Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

91–100 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#91
post #47

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

The US' foreign policy is to disrupt and steal as well, even to allies (the NSA engaged in industrial espionage on the Germany company Siemens). Moreover, DDoS attacks orginating from the US are sometimes greater than Chinese originated attacks -- as recently as a year ago [1] Also don't forget that some of the sketchiest providers on the internet are American, who routinely ignore abuse reports. NameCheap's abuse re…

There’s also something beautifully awful about blocking entire countries due to the reputation their IP addresses have, while making strange, sweeping xenophobic statements about the people that live there, meanwhile a non-insignificant percentage of some of those attacks originate from the United States (e.g., the Mirai botnet that compromised hundreds of thousands of IoT devices and also held the CloudFlare record at one point was created by an American and operated from the U.S. despite many of the infected devices being located in some of these countries).

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#92

Earlier quoted context omitted.

I agree that cloud providers are a blessing to attackers, but blocking russian, chinese and even generally SEA ip space is still a very effective way of stopping the bottom 70% of all attacks. Sure, they're trying such outdated methods that there is very little chance of them suceeding, but honestly when just banning china reduces sshd logs by 50% you wonder why you didn't do it sooner.

Are you sure you're blocking 70% of attacks? Or are attackers just starting there, and when they realise their attacks aren't working they go via AWS instead? I can't imagine many people sufficiently motivated to launch a DDoS attack against you, yet not sufficiently motivated to switch to an attack method that will actually work.

Most attacks are using a shotgun approach. DDOS generally are targeted but even then just badly behaved scrapers or vulnerability scanners can add up to be like a DDOS.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#93

Earlier quoted context omitted.

Doesn’t deserve the downvotes. All of it is truth. So much garbage connections originate from the mentioned countries. Worst yet, these countries have poor connections in some cases and generate so many retires that also waste resources.

[flagged]

[deleted]

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#94

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

> Letting russia and china on the internet was a massive security mistake we should rectify. Internet is decentralized in nature. Even if you tried to undo that, what's stopping anyone from bridging a non-CN/RU Intranet to CN/RU-Intranet. More importantly: who is to decide that? Should now a US-based organization dictate who EU/JP/Africa can communicate with? Applying such decisions at such a low level will only resu…

> what's stopping anyone from bridging a non-CN/RU Intranet to CN/RU-Intranet.

If someone were considering this, here's a means to do it with 402s: https://github.com/lightninglabs/aperture

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#95
post #66

Earlier quoted context omitted.

>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished. Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as…

> After blocking certain countries IP ranges Alright, can we just put this one to bed ? When RIPE/APNIC/ARIN allocate a range of IPs, there is NOTHING in the terms and conditions that says "you can only use this in this geography". The legal range holder must be in the geography, but where they announce it is nobody's business. The range is held by a range holder who are listed on the relevant database. But there is…

Probably a better way to block IP ranges by geography is to block by address space announced/originating from an ASN.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#96
Me and millions of users of "obsolete" software and hardware wish CloudFlare slow and painful death. I mean, require solving 65535 useless captchas to die. And "sorry, you are not allowed to die now. Try some other time. Meanwhile why don't you learn how we protect the heavens and hell from freeloaders like you!" after that. And repeat. 71M times.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#97
post #69
post #48

Earlier quoted context omitted.

Fun fact: how many digits get lumped together in a digit grouping is not universal and varies between different languages and cultures globally: https://en.wikipedia.org/wiki/Decimal_separator#Digit_groupi...

I used to work on bizdev with a German group and it took me a long time to catch on: "The character used as the thousands separator In the United States, this character is a comma (,). In Germany, it is a period (.). Thus one thousand and twenty-five is displayed as 1,025 in the United States and 1.025 in Germany. In Sweden, the thousands separator is a space. The character used as the decimal separator In the United…

Switzerland, where I'm from uses 1'023.7, often 1'023,7 in handwriting and at least in my region when spoken you also say comma. So it took my a while to parse as I become more and more exposed to number formats from surrounding countries and the US.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#98
I took off all my properties from Cloudflare many years ago because I got increasingly more uncomfortable with a single US company who I know nothing about to sniffing the entire internet's traffic through their servers and ironically my properties had much less issues overall. Whatever value Cloudflare was supposedly adding to us, it couldn't be noticed or quantified in any measurable metric that we could see. The only thing we noticed is that we cut out one extra single point of failure. When Cloudflare had some outages we were unaffected by it, overall increasing our overall availability.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#99

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

>Letting russia and china on the internet was a massive security mistake Harm vs good assessment, anyone?

The world assessed that business with those countries would be good, and now they want to bring the world down to their level (dictatorship + censorship).

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#100
post #53

Earlier quoted context omitted.

Lots of garbage traffic comes from countries such as Russia, China, India, Brazil, etc and if you don't intend to sell anything to them it makes sense to just block them. If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

> If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries. At that point, might as well rethink the engineering happening at your company well before considering blocking countries' IP spaces, no?

You can do both.

As a cold business decision, just as it makes sense to fire customers who are more hassle than they are worth, it's also makes sense to block prospective customers who are more hassle than they are worth.

Of course, if you engineering is better, you can pick a different false-positive vs false negative trade-off.

Post reply on HN