4 ms·
Statements like this don't help either "However, this is not an ordinary DDoS attack; the attacker posesses considerable resources and is operating at a scale
by kramerger 3y ago
Statements like this don't help either
"However, this is not an ordinary DDoS attack; the attacker posesses considerable resources and is operating at a scale beyond that which we have the means to mitigate ourselves."
:(
- b4ke 3y agoWe did just (Americans and allies) Iranian proxies…non-news really when run through the lens of current political environment. The things under attack are the message, not the attack itself. XD
- fmajid 3y agoThe Chinese government routinely runs DDoS against GitHub because it hosts VPN software that can be used to circumvent the Great Firewall of China. They use the Great Cannon of China, which is the offensive side of the Great Firewall, effectively turning ordinary Chinese Internet users into an unwitting army of DDoS-ers. Of course, GitHub and Microsoft have significantly higher resources than SourceHut to endure the DDoS.
- mschuster91 3y ago> Of course, GitHub and Microsoft have significantly higher resources than SourceHut to endure the DDoS. At that point I wonder why peering partners of Chinese ISPs used in these attacks don't go and drop connectivity unless the abusive traffic gets stopped.
- beretguy 3y agoPardon my lack of knowledge, is it possible to block all requests that originate from a particular country?
- jszymborski 3y agoWhile the attack might be sponsored by one country, the servers often come from a wide number of places.
- dns_snek 3y agoNot really, because your neighbor's security camera is likely participating in the attack. See "Mirai botnet" for example.
- treve 3y agoAlso why it's called DDoS and not DoS.
- oooyay 3y agoI work in reliability and I've sat at the intersection of this question before. Kind of, but not really. A lot of times you'll see UDP blocked from EMEA, which stops a good amount of attacks but doesn't solve the problem. It also creates problems for services that rely on UDP like VOIP. These days, even if the command originates from EMEA many of the participants are IOT devices that've been compromised - and those may live in the host country! Blocking an entire country can do something, sometimes, but it also opens up a wormhole of optics when users who are not knowingly part of malicious activity complain they can't access a service that the rest of the world can. Of course, the host country that operates with a decent degree of CYA acts like they have no idea why someone would do such a thing. Mitigating this stuff long term is often a game of 4D chess on a rotating board.