6 ms·
At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying
by oldtownroad 3y ago
At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery.
Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?
- logdahl 3y agoThe universities in Sweden were attacked by "Turkey" after the big quran-burning scandal. They had some twitter account bragging about it. Was pretty evident it was Russia.
- codezero 3y agoI had a customer that was getting DDoSed by competitors, the competitors likely didn't know they were doing a DDoS, as they were aggressively scraping product listings but just doing so without any delay/rate limiting and it effectively DDoSed them. They weren't trying to make the target site slower, but were trying to get data at a rate that made the target's servers uneconomical to their actual paying customers. This kind of attack is nothing like the actual DDoS attacks, but it's a lot more common in my experience, but also relatively easy to mitigate with something like Cloudflare or Akamai (which is what I'd recommend to my customers).
- OsrsNeedsf2P 3y agoWe had a similar issue and assumed it was script kiddies having fun. Turns out someone (raises hand) wrote a really bad microservice who's inefficient queries sometimes triggered all our alerts.
- saltminer 3y agoReminds me of a support ticket I had to investigate recently. Performance metrics were taking a dive and triggered automated alerts - average response time jumped from 200ms to 2000, 8000, and eventually began approaching 15000, at which point requests were timing out all over the place. At first I was wondering if my recently-deployed MR was responsible, but upon further investigation, it was from one developer on another team doing two very dumb things with their application prototype: - Constantly retrying the same query with no filtering and setting the maximum allowed page size - Sending massive quantities of small queries for specific individuals (50-100 per second) which quickly hit the rate limit, and immediately resuming after the rate limit expired Some developer outreach was required...
- ilyt 3y agoWe had that except it was our own frontend developers. We also had some actual attacks so we made a system that detect anomalies (like more than 50rps per IP) and raises alert. ...which was thwarted by frontend developers again, as they loaded few hundred tiny icons at once that triggered that alert routinely, and only thru http2 multiplexing their idiotic design patents haven't bitten them before.
- jopsen 3y agoHehehe, entirely unsurprising :)
- dudeinjapan 3y agoSure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.
- mortallywounded 3y agoSounds like something those dogpile folks would do.
- falcor84 3y agoMade me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?
- kps 3y agoAltavista started turning to shit as soon as it was no longer an Alpha demo. That was a major reason Google took off so quickly.
- dudeinjapan 3y agoWas at Tokyo Disneyland today and taught my girlfriend the word “enshittification”. (i.e. making your customers pay via your stupid app to do literally anything in your park, and not even providing wi-fi.)
- seanmcdirmid 3y agoI don’t remember paying for anything at Disney Sea with the app except for a few fast passes (and used to schedule the free fast passes of course). Suica card and credit card worked for everything else.
- _23sd 3y agoThat's not enshittification, squeezing money out of you is just how theme parks operate. The term can't really apply to Disney parks at all because there's no two sided market.
- arein2 3y agoA local hosting company ddosed local bussineses that had IT infrastructure and then advertised their hosting solution with ddos protection.
- elorant 3y agoI've heard stories about attacks where the target is a subsystem but in order to avoid drawing attention to it they attack the entire network.
- xyst 3y ago[flagged]
- stepupmakeup 3y agoprotection rackets by companies you'd only find on places like lowendtalk