DDoS attack protection for at-risk public interest websites
1–10 of 19 posts
Re: DDoS attack protection for at-risk public interest websites
#2Is there any progress on infrastructure improvements that could potentially improve this current state of affairs? Is our only solution for benevolent companies like Cloudflare to offer their blanket of protection? I guess I'm asking, who will guard the guards?
Re: DDoS attack protection for at-risk public interest websites
#3I'm personally shocked by how much power a DDoS has to potentially sway public opinion and influence the world at large. A few individuals have a hugely disproportionate voice in our public media by nature of the fact that they can control what other websites say through these attacks. Is there any progress on infrastructure improvements that could potentially improve this current state of affairs? Is our only soluti…
Re: DDoS attack protection for at-risk public interest websites
#4I'm personally shocked by how much power a DDoS has to potentially sway public opinion and influence the world at large. A few individuals have a hugely disproportionate voice in our public media by nature of the fact that they can control what other websites say through these attacks. Is there any progress on infrastructure improvements that could potentially improve this current state of affairs? Is our only soluti…
Services like Cloudflare, Blacklotus, etc. act like insurance companies [e.g. You have a pool of X services and only Y are getting attacked at a time]. This gives them an economy of scale others can't match on their own. I'd like to see a non-profit public internet security service tbh but I don't think it'd raise the capital it would need to get to the level Cloudflare is at.
Provisioning something like this yourself is going to probably cost you $450 per Gbps of mitigation per month. HE is selling transit for $.45/Mbps/month, for instance. Then you'd need to clean it. HE can't provision this instantly or on demand, so you'd need to have it built out and semi-permanent [e.g. long term contract for 100s of Gbps].
You can create multiple targets too but the costs are still roughly the same vs. one big target. [e.g. 10 x 10 Gbps is pretty much as effective as 1 x 100 Gbps and similar costs]
Re: DDoS attack protection for at-risk public interest websites
#5I'm personally shocked by how much power a DDoS has to potentially sway public opinion and influence the world at large. A few individuals have a hugely disproportionate voice in our public media by nature of the fact that they can control what other websites say through these attacks. Is there any progress on infrastructure improvements that could potentially improve this current state of affairs? Is our only soluti…
I think the fundamental problem is cost. Much like raising an army, protecting against things like DDoS on the scale of 10Gbps+ costs real money. Services like Cloudflare, Blacklotus, etc. act like insurance companies [e.g. You have a pool of X services and only Y are getting attacked at a time]. This gives them an economy of scale others can't match on their own. I'd like to see a non-profit public internet security…
I'm more curious why we don't start large-scale investigations in response to each DDoS attack: each one gives you a list of machines likely participating in a botnet.
Re: DDoS attack protection for at-risk public interest websites
#6Re: DDoS attack protection for at-risk public interest websites
#7Earlier quoted context omitted.
I think the fundamental problem is cost. Much like raising an army, protecting against things like DDoS on the scale of 10Gbps+ costs real money. Services like Cloudflare, Blacklotus, etc. act like insurance companies [e.g. You have a pool of X services and only Y are getting attacked at a time]. This gives them an economy of scale others can't match on their own. I'd like to see a non-profit public internet security…
Typically, you pay a fixed extra cost for a gigabit or 10Gbps link, but beyond that you only pay for traffic. So, a DDoS will cost you a fair bit, but having the spare capacity to weather one shouldn't cost you all that much. (Depending on just how much you expect to get hit by.) I'm more curious why we don't start large-scale investigations in response to each DDoS attack: each one gives you a list of machines likel…
> I'm more curious why we don't start large-scale investigations in response to each DDoS attack: each one gives you a list of machines likely participating in a botnet.
https://securityledger.com/2013/04/cyberbunker-owner-arreste...
They do. It just has to be large enough.
Re: DDoS attack protection for at-risk public interest websites
#8Earlier quoted context omitted.
I think the fundamental problem is cost. Much like raising an army, protecting against things like DDoS on the scale of 10Gbps+ costs real money. Services like Cloudflare, Blacklotus, etc. act like insurance companies [e.g. You have a pool of X services and only Y are getting attacked at a time]. This gives them an economy of scale others can't match on their own. I'd like to see a non-profit public internet security…
Typically, you pay a fixed extra cost for a gigabit or 10Gbps link, but beyond that you only pay for traffic. So, a DDoS will cost you a fair bit, but having the spare capacity to weather one shouldn't cost you all that much. (Depending on just how much you expect to get hit by.) I'm more curious why we don't start large-scale investigations in response to each DDoS attack: each one gives you a list of machines likel…
No, at this point the machines are most likely 'innocent' and are just running exploitable services (usually NTP, DNS, or chargen). Despite widespread knowledge of the vulnerabilities of these protocols ( http://openresolverproject.org/ http://openntpproject.org/ ) getting people to actually fix their systems is hard. Since the systems themselves aren't compromised, investigating each one is not really a good use of your time.
These attacks rely on the ability of the attacker to spoof IP addresses. Tracking down the sources of these spoofed packets would be more useful, but this requires the cooperation of the transit providers. It will also lead back to providers that make money by allowing spoofed traffic in the first place. Ecatel is the well known one right now, they are very popular in the 'booter' business.
Re: DDoS attack protection for at-risk public interest websites
#9I'm personally shocked by how much power a DDoS has to potentially sway public opinion and influence the world at large. A few individuals have a hugely disproportionate voice in our public media by nature of the fact that they can control what other websites say through these attacks. Is there any progress on infrastructure improvements that could potentially improve this current state of affairs? Is our only soluti…
I think the fundamental problem is cost. Much like raising an army, protecting against things like DDoS on the scale of 10Gbps+ costs real money. Services like Cloudflare, Blacklotus, etc. act like insurance companies [e.g. You have a pool of X services and only Y are getting attacked at a time]. This gives them an economy of scale others can't match on their own. I'd like to see a non-profit public internet security…