Live data from Hacker News

Understanding the recent DDoS attack against Read the Docs

about.readthedocs.com

51–60 of 74 posts

Re: Understanding the recent DDoS attack against Read the Docs

#51
post #48
post #46

Earlier quoted context omitted.

AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.

What do they do that you think is prohibited by a residential ISP contract?

Running a proxy server and running a botnet, at least.

Re: Understanding the recent DDoS attack against Read the Docs

#52
this might be a AI driven attack and readthedocs was just a test target.

What surprised me is how easy it was to evade the cloudflare defenses. I know it was easy to evade CF, but I would expected CF to do a better job at blocking L7 DDOS.

CF is really good in defending against the L4 DDOS, but not L7.

this means that cloudflare is really not useful much in the era of Agentic DDOS driven by thousands agents across the globe

Re: Understanding the recent DDoS attack against Read the Docs

#53
post #39

I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…

The problem is most of the botnet zombies are in places with very little rule of law like eastern europe/russia/south america/china. It is an exercise in futility and the richest customers just opt to just spend money on more protection than shutting down the zombies.

If the zombie is in the US, hosts like Google or Amazon will take 1+ month to respond.

Re: Understanding the recent DDoS attack against Read the Docs

#54
post #49
post #46

Earlier quoted context omitted.

AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.

Doesn't matter from the point of view of a lawsuit from an outside attacked party.

IANAL, but a harmed party outside of the 'binding arbitration' nonsense might be a way work around arbitration and drag the company into a court.

Re: Understanding the recent DDoS attack against Read the Docs

#55
post #26

My naive take on a Cloudflare perspective wants to combine "three times is enemy action" with toddler-speed block dropping and manual clearance. What's the money reason this problem isn't handled at the ISP level?

I don't quite understand your post, but is your question why don't the ISPs of the sources of the abusive traffic sort it out? The distributed nature of DDoS means each participating host isn't sending that much traffic, and there are often tens or hundreds of thousands of participating hosts. An ISP should verify claims of abuse before cutting off customers, and since most of the customers are presumably unaware of…

> most attacks were 90 seconds long ... there's no way I'm convincing an ISP to drop a pwned customer over that.

Every victim (such as readthedocs), or even people sharing blocklists to avoid becoming a victim, blocking that ISP's ranges until they do clean up their network could be a convincing argument?

As you say, even at 90 seconds, it's clear to all involved parties that the customer is pwned or malicious. Such a reoccurring source of abuse needs to either clean up or find themselves a different ISP to spread harm onto the net

I get what you're saying about that this won't solve an ongoing attack right this minute, or even by next week. But if we just let it all happen then the solution is going to be either (1) we all buy equipment that can handle something like a terabit per second and arm our infrastructure to the teeth or (2) centralize all traffic through a vetting entity who decides which client gets to visit the internet today. So far we're headed towards the latter and nobody really wants that. Abuse messages will have to slowly trickle down from victims to originating ISPs to users, and if users didn't willingly sign up, then to wherever users are getting this malware (Google's app store will be a big component). Stopping this at the source seems to me a much more desirable long-term solution

Re: Understanding the recent DDoS attack against Read the Docs

#56
post #13

A more interesting question is, what exactly do the attackers gain from hitting read the docs? Most of their docs hosting is static/easily CDN cached. Unlike database bound sites, you would need a lot more traffic to overload pure/mostly static hosting. Maybe it's a malicious AI lab looking to deny their competitors training data? As far as infosec profiling goes, this is probably the oddest case I have heard of. I a…

Nothing to do with AI, but just the general storm of trying to force the Internet into a proprietary, tightly-controlled walled garden with strong identity verification.

Re: Understanding the recent DDoS attack against Read the Docs

#57
post #55
post #26

Earlier quoted context omitted.

I don't quite understand your post, but is your question why don't the ISPs of the sources of the abusive traffic sort it out? The distributed nature of DDoS means each participating host isn't sending that much traffic, and there are often tens or hundreds of thousands of participating hosts. An ISP should verify claims of abuse before cutting off customers, and since most of the customers are presumably unaware of…

> most attacks were 90 seconds long ... there's no way I'm convincing an ISP to drop a pwned customer over that. Every victim (such as readthedocs), or even people sharing blocklists to avoid becoming a victim, blocking that ISP's ranges until they do clean up their network could be a convincing argument? As you say, even at 90 seconds, it's clear to all involved parties that the customer is pwned or malicious. Such…

> Every victim (such as readthedocs), or even people sharing blocklists

The report makes it pretty clear that the attack was distributed enough that profiling for blocklists was ineffective.

Re: Understanding the recent DDoS attack against Read the Docs

#58
post #45
post #39

I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…

I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort. Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I t…

That's why GP mentioned "Smart TV".

A random Internet-connected smart plug made by KOCKJAKD and sold on Aliexpress? Almost impossible to catch.

A major brand like LG, with US presence and sold in brick-and-mortar stores? Much more possible. It also makes a much juicier target for lawyers, thus making it much more likely to get sued. And once there is a precedent, other manufactures would be in danger too. Hopefully after losing a whole bunch of money, the manufacturers will start cracking down on those residential proxies.

(Except that discovery is going to be painful. "Use discovery to find out what's on the other end" is easy to write, but in practice it means regular people dealing with bailiffs just because they happen to buy wrong brand of smart TV)

Re: Understanding the recent DDoS attack against Read the Docs

#59
post #45
post #39

I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…

I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort. Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I t…

  > I agree they they should, but that would be hard before, ... seems like a herculean effort.

  | We choose to go to the Moon in this decade and do the other things, not because they are easy, but because they are hard; because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one we intend to win, and the others, too.
So what, they are hard. So are so many of humanity's greatest achievements.

Honestly, these companies win when we buy into the belief that these things are too hard. They're lazy and are just like any of us that make excuses to not do chores or other things that we should. But the reality is that for pursing our civilization forward we should pursue the toughest problems. It is just about will. It'll be tiring. Some will kick and scream, throwing tantrums. But we aren't just any animal, we're humans. We can do literally anything if we decide it's worthwhile.

Importantly, we shouldn't just jump onto the next hype train, we should be passionate, nuanced, and pursue for the sake of pursuit. We don't have to put all our eggs in one basket. We shouldn't. We have enough time, resources, and energy to pursue so much. But as soon as at pretend we live in a finite world we tend to self destruct and fight over constraints we've made up. The universe is limitless, as are our minds.

Post reply on HN