So in other words, anybody can carry out a DDOS for basically no cost. So trying to analyze the purpose, let alone suspects, is probably not going to be fruitful.
This is a sampling of currently available services and who they use for DDoS protection:
stresslab.app - Cloudflare
maxstresser.com - Cloudflare
sunnystress.com - Cloudflare
tresser.io - Cloudflare
ip-stresser.net - Cloudflare
hardstresser.com - DDoSGuard
zdstresser.net - Cloudflare
starkstresser.net - Cloudflare
stresserhub.org - Cloudflare
nightmarestresser.net - DDoSGuard
Just for fun head over to Cloudflare's abuse reporting site and try to figure out how to get one of these taken down. https://abuse.cloudflare.com/Now they hide behind Cloudflare who will refuse to turn over any information so that security folks can get them taken down. Unfortunately Cloudflare has grown too large that we can't just block all of it or depeer them like we would any other network that provided services to bad actors.
Most of the listed domain names are under US jurisdiction. That means the authorities should be able to take them down. If Cloudflare is found to have been knowingly enabling crime, it could face fines, and the CEO and other key people could end up in prison. The Cloudflare services have probably been paid using means that are under US jurisdiction. Those payment accounts can be closed and the people behind them tracked down and potentially charged with crimes.
Or at least that's how things work in the real world. The internet is still apparently too new for the authorities to understand how to deal with it.
Zero ingress puts the upfront bandwidth cost onto the attacker. Because... you actually may succeed to defend and stay up. Their success is not guaranteed, they might be shouting into the void.
Attack success (as in, "impact on you") is guaranteed if your ingress is chargeable.
https://robindev.substack.com/p/cloudflare-took-down-our-web...
So in other words, Cloudflare noticed the author was running a gambling site, they decided that this was negatively impacting the shared IPs and the author would therefore need to upgrade to a plan that included BYOIP because they would need to use that feature to continue using Cloudflare and they likely insisted on prepayment for the annual plan because gambling sites have a reputation for being flaky and prepaying would have demonstrated the liquidity necessary to continue operating the site at that plan.
Again, Cloudflare could have communicated this better (and maybe they did in parts of the correspondence the author didn't share) but this all seems perfectly understandable, especially given how the sales team kept referencing Trust and Safety (implying the alternative is ending the contract for violating the ToS).
The issue of tainting shared IPs would indeed have suddenly gone away had the author brought their own IP (which would have required an Enterprise plan to do while staying on Cloudflare). Instead the author feigns ignorance arguing they don't even need the features of the Enterprise plan and doesn't acknowledge the issue with sharing IPs while sheepishly mentioning that maybe they're accidentally invading bans of their domain in certain countries by having alternative domains which they of course don't actually need because most traffic comes from their main domain yet somehow having these alternative domains is critical to running their business.
What are you even trying to argue here? The author is being deliberately dishonest in how they frame the incident and Cloudflare's motivation is perfectly understandable. The only thing to take offense with is the communication style which we can only judge based on a select few messages the author shows us. We have to rely on their word after they have already demonstrated dishonesty.
“We tried saying that we don't need any number of the 14 features that are included”
Which, to me, is the crux of the issue. Is it fair for Cloudflare to say “You are breaking the terms of service if you do not change your set up in this specific way, and also the way you need to chance your setup is locked behind a significantly more expensive pricing.” Being able to bring your own IP does not, to me, seem like something that should require a plan that is orders of magnitude more expensive than the standard. It seems much more to me like something that is more fundamental, and should be included as an option in a lesser version of the product Maybe I’m wrong, and there is actually significant overhead to Cloudflare for letting customers bring an IP. But as is, it feels very much to me like a situation where something vital was locked at the most expensive tier to force certain kinds of customer to pay more.
Yes, BYOIP as a feature does not seem complex enough to warrant paying for an Entperise license. But the kind of customers who need BYOIP (especially if they need it to avoid harming your IP reputation) are likely to be at a higher risk of being flaky or otherwise painful so this is very much a tax on running that kind of business (just as porn sites often find it hard to find payment processors because of the high risk of credit card fraud).
As a freelancer I have absolutely made offers at 10x my going rate for client I did not want. The idea is that if they really want me to work for them, at least I get reimbursed for the suffering that will entail. This kind of pricing structure is no different.
For the sake of argument (maybe not true), let's say that all techies are aware of archive.org, and consider it beneficial, probably using it themselves.
Why don't they instead demo against a target that will be proof of capability, and one that someone won't pay them to do (no freebies), yet one that they perceive as bad or deserving in some way?
Probably improper to suggest "better" targets here, but I really wonder what's going on when some relative do-gooder gets attacked.
Similarly, ransomware attack on a children's hospital, of all places? Doesn't that get you uninvited to criminal mastermind dinner parties?
As Omar of "The Wire" told us, a man's gotta have a code.
LockBit was so successful partly because they didn’t have to hack anyone themselves. It was basically something advertised “Got SSH or RDP access? Let’s make a bunch of money.”
This attracted hackers who might not trust themselves to do the extortion part safely, as well as people who didn’t actually hack anything but hated their boss, wanted a payday.
Perhaps they intentionally attack targets that are generally seen in a positive light, to prove to potential customers that morale is not an issue.
Oh, you want me to DDOS a children's hospital? No problem.
(Googling "Jason Scott TIA" gives me "Dr Jason Scott is a Senior Research Fellow in the Tasmanian Institute of Agriculture" which doesn't explain much to me)
TIA = The Internet Archive (i.e. the victim of the DDoS).
>The user you're responding to is Jason Scott of The Internet Archive
I am shocked that any HN reader could be ignorant of this fact. Their director is a (controversial) Turing Award winner.
This could even be as simple as "Some aspect of the attack pattern is inconsistent with such a motive", or "We spotted the perpetrator credibly gloating about it". But just from IA's public statements, the pattern ("launching tens of thousands of fake information requests per second") is quite consistent with simple denial.
And not taking on the job of police when you don't know as much as you think you do, such as the speakers whose speech you presume to police.
You might not know the significance of "textfiles says no", but you do know that in general it's a thing that on HN, sometimes the rando is no rando, and you do know that you're not dang.
That's all it takes to avoid looking like a douche. And soon enough some comment or other would fill in the significance, from someone else looking like a douche and having it explained to them.
Jason could have added "Internet Archive here, it's not that." But he would have to say that in front of every comment he ever writes, which I think would get old for him and probably no small number of other people would criticize that too "yesss we know you work for IA FFS get over yourself..."
I think it's fine for him to just speak and let everyone else take care of themselves.
Sometimes. More often than many other places we could mention. But in the majority of cases, even here, a rando is a rando. And if the randos see the accepted conventions being ignored without comment it might encourage them to do it more.
> Jason could have added
I'd argue should have.
> But he would have to say that in front of every comment he ever writes
Only comments where it is significantly relevant, or in this case where his experience and proximity to the issue at have might be considered enough to ignore the standard commenting conventions.
Npm has been under pretty severe attack for ~6 weeks now. I forget who else.
The scariest thing to me is what we might do in the face of persistent online attacks. If this stuff gets rolled up into western nations rolling back privacy & liberty? That's an theonion.com "bin laden plan to sit back and enjoy collapse" situation. Freak out & let cyber security paranoia reign & destroy free communication & connection.