4 ms·
Doesn’t Cloudflare have every incentive to inflate the bandwidth of the attack they have successfully mitigated? And yes I know that there are Cloudflare emplo
by balanc 1y ago
Doesn’t Cloudflare have every incentive to inflate the bandwidth of the attack they have successfully mitigated?
And yes I know that there are Cloudflare employees here so spare me with your pinky swears.
- x2tyfi 1y agoCouldn’t this logic apply to basically every internal metric across every company?
- udev4096 1y ago[flagged]
- perching_aix 1y agoSpeaking of incentives, what might be the incentives of those referring to them as Clownflare? I sure have to wonder what their biases are, and how fairly they represent the company.
- eviks 1y agoHow does it counter the incentives of all other companies to make it look like they're not the only one???
- mlyle 1y agoCloudflare has the biggest scale and is arguably best positioned to soak up massive attacks. Therefore CF may have a unique incentive to make it sound like attacks are larger and there are more really big ones.
- eviks 1y ago> is arguably best positioned Lying about the scale of thwarted attacks by others is the counter argument
- mlyle 1y agoStill not sure what you're saying: A) everyone inflates-- in which case, you want to be with the entity with the biggest pipes. Also, of course, we have reasonable estimates about how much traffic everyone can exchange. B) non-CF players downplay DDoS-- this isn't going to work either.
- eviks 1y agoA) not really, you need an entity with pipes big enough. Have they repeatedly claimed to have frequent attacks bigger than anyone's capacity? (by the way, how are those reasonable estimates immune to everyone lying but not to the lies about the attacks?) B) why?
- mlyle 1y agoCapacity isn't a number, like you have 48 units of internets. You need an entity with peering, pipes, and request rates big enough in the right places.
- eviks 1y agoCapacity is a number, like you can handle 10 tbps attacks (with the peering/pipes/rates infrastructure)
- mlyle 1y agoBut it's not. How much you can soak up of clients actively trying to handshake and request resources is going to be different from how much of bulk traffic. How much traffic you can soak up in one place (e.g. saturating your peering to where 80% of your customers are). Or how much spoofed traffic you can soak up globally from a botnet. Cloudflare has a ton of infrastructure, and this just makes them intrinsically more robust to the biggest attacks. It's in their interest, therefore, to make people believe there's a lot of really big attacks.
- 1y ago
- move-on-by 1y agoA couple months ago Brain Krebs, who uses Google’s Project Shield, wrote of a very similar attack. 6.3 terabits, all UDP, less then a minute. https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/ https://krebsonsecurity.com/2025/05/krebsonsecurity-hit-with...