Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

51–60 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#51
post #37

Cui bono? There is a big (opportunity) cost to this kind of thing, How is this worthwhile for anyone? I assume that its's not just a competitor. Is it really worth 's time to temporarily upset one of of three big cloud providers? Is there a ransom behind the scenes?

nope, there's really no cost to it - they've been hitting with attacks double or even triple the size towards random minecraft hosts for months now.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#52
post #33

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

The international organisation for stopping wars, human trafficking, money laundering, drug distribution etc. however capable they might be, haven't managed to stamp out any of those things. I'd say a putative UN NetWatch would suffer from the same issues of funding and corruption and politics, but still we might have something better than this wild west lawlessness.

> have something better than this wild west lawlessness.

Careful what you wish for. Before you know it you can't have an IP without your ID.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#53
post #31

I feel like posting the traffic output of the network might not be a great idea because they might do these attacks on purpose to market their network's capability.

it's an open secret at that point and the attacks are far larger than that are causing congestion world-wide from the time they wake up to the time they go to sleep.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#54

Earlier quoted context omitted.

This is exactly why OpenWRT has no unattended updates by default )

You are dismissing the seriousness of this. Their package manager is widely used. One would only need to compromise their build servers to wreak havoc. Didn't they have a vulnerability in their firmware download tool like a minute ago? The difference between OpenWRT and Linux distros is the amount of testing and visibility. OpenWRT is loaded on to residential devices and forgotten about, it doesn't have professional…

I'm confused why you're so honed in on OpenWRT as a third-party open-source project here when the vulnerability you quoted (TotoLink) was the official firmware update server of a brand of devices.

Is it "scary" to think about OpenWRT potentially getting hacked? If you get scared by theoretical possibilities in software, sure. Is it relevant? Not exactly. Are companies' official servers more secure than an open-source project's servers? In this case, apparently not.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#55
post #33

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

The international organisation for stopping wars, human trafficking, money laundering, drug distribution etc. however capable they might be, haven't managed to stamp out any of those things. I'd say a putative UN NetWatch would suffer from the same issues of funding and corruption and politics, but still we might have something better than this wild west lawlessness.

> putative UN NetWatch

But who will suppress attempts to go beyond the blackwall then?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#56

IoT is just wave after wave of unsecure devices. There's gotta be a better way.

fun fact, part of the reason this botnet exists is because europe required the ability to install security updates unattended that you cannot disable and they compromised one of the servers that had the capability to push these updates compromising hundreds of thousands of routers.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#57

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

As always, hundreds watch the open repositories, maybe one watches a company's build servers, if they're lucky. :-)

Hundreds watch, but how closely?

Plenty of stories of fairly major projects having evil commits snuck in that remain for months.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#58
post #30

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

Because it's not technicaly possible, I mean we're on HN, we all know how internet works.

I heard it's a series of tubes.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#59

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

International DDoS busts and arrests do happen all the time.

Law enforcement takes time. The perpetrators of these attacks aren't hanging out in the open with their full names shielded only by the hope that their country won't extradite for political favor.

By the time the perpetrators are identified and a case is built, getting them charged isn't bottlenecked on the lack of an international agency. Any international law enforcement agency would be beholden to each country's own political wills and ideals, meaning any "teeth" they had would be no more effective than what we currenly have for extraditing people or cooperating with foreign police organizations.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#60

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

Digital signing wouldn't defend you from a compromised build server.
Post reply on HN