Slashdot Mirror


Akamai Kicked Journalist Brian Krebs' Site Off Its Servers After He Was Hit By a Record Cyberattack (businessinsider.com)

An anonymous reader writes:Cloud hosting giant Akamai Technologies has dumped journalist Brian Krebs from its servers after his website came under a "record" cyberattack. "It's looking likely that KrebsOnSecurity will be offline for a while," Krebs tweeted Thursday. "Akamai's kicking me off their network tonight." Since Tuesday, Krebs' site has been under sustained distributed denial-of-service (DDoS), a crude method of flooding a website with traffic in order to deny legitimate users from being able to access it. The assault has flooded Krebs' site with more than 620 Gbps per second of traffic -- nearly double what Akamai has seen in the past.

212 comments

  1. So basically ... the attack wins? by DavidRawling · · Score: 5, Informative

    Seems to me the attackers win, at least in the short term, because the caching and CDN provider (who I expect was probably contracted and paid, although it's entirely up to Brian how he handles his business affairs, it does seem likely) takes the site off the air anyway. That being the case ... what's the point of having that contracted relationship, if they dump you anyway?

    1. Re:So basically ... the attack wins? by sinij · · Score: 3, Insightful

      Yes, but not for technical reasons (DDoS succeeding in overwhelming ISP). Akami shamefully decided to dump Kerbs.

    2. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 5, Informative

      Akamai were providing him service for free up to that point:

      https://twitter.com/briankrebs/status/779111614226239488

      So up to this point they had been eating the cost of hosting him and defending against attacks. This one just got too big for too long.

    3. Re:So basically ... the attack wins? by mwvdlee · · Score: 4, Insightful

      I might be a conspiracy theorist here, but what might Akamai gain by blocking the guy who's taking down one of the largest criminal organizations providing the type of attacks that Akamai is being paid for to prevent?

      --
      Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    4. Re:So basically ... the attack wins? by DougOtto · · Score: 4, Insightful

      I read somewhere that there was no contract but rather Akamai was providing the service pro-bono.

      If that's the case, and it was starting to impact paying customers, it's an understandable move.

      --
      Solving Unix problems since 1989...
    5. Re:So basically ... the attack wins? by Opportunist · · Score: 5, Insightful

      The reason is irrelevant. The message is clear: You want to silence your opposition? Conduct a DDoS until your enemy's hoster decides that you're more hassle than he is worth.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    6. Re:So basically ... the attack wins? by Opportunist · · Score: 2

      Umm... NIMBY. As in "yes, we like what he does, but he should be hosted somewhere else".

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    7. Re:So basically ... the attack wins? by Opportunist · · Score: 2, Interesting

      It's not that we don't understand it (frankly, people, who would act differently?), what is troublesome is the signal this broadcasts.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    8. Re:So basically ... the attack wins? by koreanbabykilla · · Score: 1

      They hosted him pro bono

    9. Re:So basically ... the attack wins? by Horus1664 · · Score: 2

      ...so if he'd paid $20 a month he'd be ok ? (Or you'd be outraged?)

    10. Re:So basically ... the attack wins? by Xest · · Score: 0, Redundant

      So basically don't trust Akamai because apparently they're incapable of dealing with DDOS attacks.

      Seriously, if they can take a blog offline, then who the fuck would trust anything of actual commercial value on Akamai's network ever again?

    11. Re:So basically ... the attack wins? by ole_timer · · Score: 1

      who said thy were blocking him?

      --
      nothing to see here - move along
    12. Re: So basically ... the attack wins? by Xest · · Score: 5, Insightful

      They weren't hosting him for free, there's no such thing as free.

      They were hosting him because it was good PR for them to be able to say "Yeah, we're capable of holding up this high value target's website just fine regardless of all the attacks he regularly comes under".

      This is a tacit admittance that Akamai's business model has changed from high end bulletproof host to just another host that will not keep your site up in the face of a DDOS. This is rather unfortunate for them, because such low end hosts are widely available, and at a far lower price point.

      I wish them luck with their new model as just another host chasing the low hanging fruit. They've sacrificed an incredibly important unique selling point for them - their reputation as a host that will keep you going no matter what.

    13. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      Also, it's funny because of: https://www.akamai.com/uk/en/a...

      Good PR: providing free hosting to a high profile and well liked journalist/commentator
      Bad PR: apparently one of your most vaunted product offerings isn't good enough to keep one blog online

      CAPTCHA: buffer (!)

    14. Re:So basically ... the attack wins? by Mal-2 · · Score: 2

      Unfortunately, this has always been the case. The whole point of a DDoS is the ability of the attacker to multiply its efforts enormously. The only possible defense against any and all DDoS attacks would be to own more than half the bandwidth of the network, which hopefully nobody ever will -- or at least more than any adversary or group of adversaries can ever point your way. Since the attackers are not paying for the bandwidth, and Akamai is, the attackers win by economic siege.

      Either Akamai can bow and take down Krebs, or they can let the whole ship go down in a symbolic gesture. Which one would you do, if you had a business to run?

      --
      How is the Riemann zeta function like Trump rallies? Both have an endless number of trivial zeros.
    15. Re:So basically ... the attack wins? by Impy+the+Impiuos+Imp · · Score: 4, Funny

      * Largest DDoS attack mitigated to date: 321 Gbps, 71.5 Mpps

      Lol. Looks like we're gonna need a bigger boat.

      --
      (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
    16. Re:So basically ... the attack wins? by MitchDev · · Score: 1

      Hopefully all their current and any future customers will tell Akamai to go fuck themselves and drive them out of business in a REAL "Denial of Service" attack...

    17. Re: So basically ... the attack wins? by DigitalSorceress · · Score: 1

      This sums up my thoughts so much better than I could... and I totally agree... this is really a big black mark on Akamai.

      --

      The Digital Sorceress
    18. Re:So basically ... the attack wins? by jofas · · Score: 1, Insightful

      Oh, HEEEERE we go.

      Akamai is NOT a public service. Akamai is the 800lb gorilla in the room. To a large extent, the can charge what they want and do what they want.

    19. Re:So basically ... the attack wins? by koreanbabykilla · · Score: 2

      I would imagine if he paid them what it costs to mitigate that kind of onslaught for days and days he would be online. I am certain that his blog being offline for a few days or weeks till this stops isn't worth it to ANYONE to use the resources to keep it up.

    20. Re:So basically ... the attack wins? by jofas · · Score: 3, Interesting

      You've obviously never seen an Akamai invoice...

    21. Re:So basically ... the attack wins? by Mal-2 · · Score: 1

      What would that accomplish other than to make sure there are no players left in the market except for the really, really big ones? You know that if this topples Akamai, the attackers will take on another target and bring them down the same way, and so on, and so on...

      --
      How is the Riemann zeta function like Trump rallies? Both have an endless number of trivial zeros.
    22. Re: So basically ... the attack wins? by chfriley · · Score: 1

      Excellent summary of my thoughts Akamai's actions.

      He should consider using a .bit address with Zeronet.

    23. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      Shamefully? It's normal for hosting providers to have agreements that states they can terminate you if hosting you is detrimental to their network, even if this is due to an outside attack targeting you. I would say a 620gbit DDoS is detrimental to their network.

    24. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 3, Interesting

      He should consider using a .bit address with Zeronet.

      He should publish his site on Freenet. There's no such thing as a DDoS there, quite the opposite: the more requests there are for a specific URL, the more widely that content is propagated across the network, making it easier and faster for everyone to load. I say again, you cannot DDoS a Freenet site, there is no server to DDoS, as the content is distributed and hosted across the entire network. The only thing he'd lose is the comment section (Freenet's design is not conducive to interactive/dynamic stuff like commenting).

    25. Re: So basically ... the attack wins? by Aristos+Mazer · · Score: 4, Insightful

      They are incapable of dealing with the largest DDoS they've ever seen, double the previous record. There is no defense against a DDoS except bandwidth, so there's an upper bound that will take down *any* provider. Akamai is a high-end defender, but in this space, attackers have the clear upper hand.

    26. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 5, Informative

      Before using terms like "shamefully", you really should know all the facts...

      Before everyone beats up on Akamai/Prolexic too much, they were providing me service pro bono. So, as I said, I don't fault them at all.

      — briankrebs (@briankrebs) September 23, 2016

    27. Re:So basically ... the attack wins? by mysidia · · Score: 1

      It would be better if Akamai survives, but is HURT by this choice of theirs, such that they revisit their policy.

    28. Re:So basically ... the attack wins? by MitchDev · · Score: 1

      So basically anyone someone decides to DDoS should be automatically dropped from the internet is your plan?

      NO

    29. Re: So basically ... the attack wins? by ArmoredDragon · · Score: 2

      I think the best thing would be to treat internet access much like we do electromagnetic spectrum, and require those using it to have some kind of accountability in that if they participate in a ddos, willingly or not, then they have to have their access throttled to something like 128kbit, even if they switch ISPs, and they can only have it unthrottled once they decide to secure their devices or otherwise stop participating in ddos.

    30. Re:So basically ... the attack wins? by poofmeisterp · · Score: 1

      The reason is irrelevant. The message is clear: You want to silence your opposition? Conduct a DDoS until your enemy's hoster decides that you're more hassle than he is worth.

      Talk about encouragement for future activities...

      Butthead impression, if I may, from the 90's MTV series Beavis and Butthead:

      "WHOOOAAH. It really DOES work. Uuhuhuhuh huhuhuhuhuh."

    31. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 1

      Speaking as a current Akamai customer. Not bloody likely to happen for this reason.

      First off, not a lot of players out there that compete with Akamai. More to the point, when you integrate with them in all the ways we have, that takes a lot of work. We have often considered dumping Akamai, because the customer service is absolute shit. However, as long as they keep working and doing all the custom BS that we need them to do, they will probably retain our business.

      Second, a business like Akamai isn't there to make a point for someone. Yes, generally they will try and be idealistic, they are actually humans here, but there are limits. They have shareholders who probably don't like that they had to give in, but that can't be sustained if it impacts your bottom line strongly.

    32. Re:So basically ... the attack wins? by poofmeisterp · · Score: 2

      Unfortunately, this has always been the case. The whole point of a DDoS is the ability of the attacker to multiply its efforts enormously. The only possible defense against any and all DDoS attacks would be to own more than half the bandwidth of the network, which hopefully nobody ever will -- or at least more than any adversary or group of adversaries can ever point your way. Since the attackers are not paying for the bandwidth, and Akamai is, the attackers win by economic siege.

      Either Akamai can bow and take down Krebs, or they can let the whole ship go down in a symbolic gesture. Which one would you do, if you had a business to run?

      Has it been discussed before to modify either layer 1 or TCP standards to include a DDoS ICMP/other response upstream that indicates that there is a stream of unwanted, high-bandwidth data coming from a source IP of xxx.xxx.xxx.xxx, going all the way back to the source's downstream node in each case. If the traffic is confirmed, block traffic to the reporting IP. If not, don't. Simple standard (yes, many issues that can be exploited or abused, but those can be worked around simply).

      Not understanding why DDoS is still such a problem if it's stoppable.

    33. Re:So basically ... the attack wins? by gweihir · · Score: 1

      Akamai was hosting him for free. Of couse, a smarter move would have been to say "We are Akamai, sites hosted by us do not go down" and exploit this for all its PR value. Of course, that takes management with a vision, MBA bean-counters do not need to apply.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    34. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      He should consider using a .bit address with Zeronet.

      He should publish his site on Freenet. There's no such thing as a DDoS there, quite the opposite: the more requests there are for a specific URL, the more widely that content is propagated across the network, making it easier and faster for everyone to load. I say again, you cannot DDoS a Freenet site, there is no server to DDoS, as the content is distributed and hosted across the entire network. The only thing he'd lose is the comment section (Freenet's design is not conducive to interactive/dynamic stuff like commenting).

      He'd lose his comment section, and his site's visibility to anyone who isn't running Freenet on their machine. Mentioning a fix isn't going to change peoples' ignorance of best-method and workaround solutions. Good idea, just not doable.

    35. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      He'd lose his comment section, and his site's visibility to anyone who isn't running Freenet on their machine

      So a lot of security researchers, cribbing journalists, secret admirer skids, and other interested parties might install Freenet. That sounds like a win-win.

    36. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      Or do what Cox already does if you are served a DMCA notice. They shut off your Internet and redirect your web requests to a page with contact information to remedy the problem. Once you've met their checklist your Internet access is turned back on. Maybe people are victims of DDoS attacks knowingly or not. The only solution is to give them a mechanism to know so they can do something about it.

    37. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      It is not easily stoppable. Different methods have different mitigate techniques. If several million users are simultaneously performing a single wget against your web servers you're going experience the slashdotting effect. Slashdot has taken down many a site in its history. Wget is a standard command that all web browsers run to get the content that is displayed. This is hard to sort out if you actually still want to do business because you have to sort out legitimate requests and none legitimate requests. When you're talking about hundreds of millions of requests it becomes very difficult to manage.

      The days of syn floods causing an outage are pretty much over, that form of DDOS went out of a style a while ago.

      DNS amplification is still pretty common but there are well known mitigations methods for that as well.

      It is a pickle for ISPs as net neutrality forces them to not take certain measures but I think it would pass the reasonable test should it ever result in a lawsuit. There should be a DDOS authority that notifies ISPs that IP that belong to them are participating in a DDOS attack and that they should do something about it. Different ISPs will take different approaches and some won't care so you have to start making it a legal requirement which of course only works country by country. Without Russian, China, and India going along with it, it would probably fail. That could be a condition of handing over ICANN though.

    38. Re:So basically ... the attack wins? by sjames · · Score: 4, Insightful

      Alas, no. That would have been possible in the before time when a T1 was a lot of bandwidth and the threat was a DOS rather than a DDOS.

      In a DDOS, no one host is a big contributor, but there are a lot of hosts. Consider, you have 10,000 hosts (a SMALL attack) fetching valid URLs from your web server and sending them to /dev/null. Now, which of the 10100 hosts fetching pages from you do you want shot down? Keep in mind, your objective includes not letting the attacker win. To add to the "fun", those 10,000 hosts will rotate out and be replaced by others in a much larger pool fairly frequently.

    39. Re:So basically ... the attack wins? by Sun · · Score: 1

      I believe that the reason Akamai kicked him out was because they didn't want to risk their entire network for one client, at least not without him paying considerably more than he does. At the end of the day, there is a limit to what even Akamai's network can take.

      Which is another way of saying that the attackers won.

      Shachar

      Disclaimer: I've worked for Akamai for a year and a half, up until two years ago, in a technical role. I do not speak for Akamai.

    40. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      That being the case ... what's the point of having that contracted relationship, if they dump you anyway?

      It depends on the terms of the contract. If he was paying for their service (and it wasn't donated by Akami), then he could have exceeded the traffic load he had paid for. Perhaps if he wants a higher threshold before being cut-off he could purchase a different service level.

    41. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 1

      if they participate in a ddos, willingly or not, then they have to have their access throttled to something like 128kbit

      That is just stupid. The DDOS is coming from millions of computers across hundreds of ISPs in dozens of countries. There is no way that anyone can determine that the minimal amount of traffic coming from each of those computers is part of a DDOS attack let alone inform the ISPs or force them to enforce this ridiculous rule.

    42. Re:So basically ... the attack wins? by amorsen · · Score: 1

      The source IP of the traffic is spoofed. This would not be possible if all ISP's implemented BCP38, but some don't, so it is.

      --
      Finally! A year of moderation! Ready for 2019?
    43. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      Seems to me the attackers win, at least in the short term, because the caching and CDN provider (who I expect was probably contracted and paid, although it's entirely up to Brian how he handles his business affairs, it does seem likely) takes the site off the air anyway. That being the case ... what's the point of having that contracted relationship, if they dump you anyway?

      fedjfo;ljsjs;lj;oj;odjo;dddjo;xj

    44. Re:So basically ... the attack wins? by klubar · · Score: 2

      It's always a problem with pro-bono clients or favors for friends client. If it was a top-paying client, they might have pulled out all the stops to prevent the attack.Every pro-bono and service provider (whether lawyer, ad agency, programmer, etc.) understands the dynamics. Full-freight clients come first and the top two or three clients come even before them. Discounted, best-efforts, pro-bono and clients of friends come below.

      Hopefully, the relationship is described and understood in advance.

    45. Re: So basically ... the attack wins? by Cederic · · Score: 1

      There is no defense against a DDoS except bandwidth

      Sure there are.
      - intelligent routing of the inbound traffic
      - intelligent handling and dropping of the inbound traffic
      - controlled service degradation
      - legal action
      - the criminal justice system
      - a B2 bomber improving its fuel efficiency by discarding excess baggage on the Cypriot dacha of the cunt behind it

      I'm not even a security or network expert so I'm sure I've missed a few.

    46. Re: So basically ... the attack wins? by Aristos+Mazer · · Score: 1

      Those all mitigate, yes, but at the end of the day, the network can always generate a DDoS bigger than that can handle unless you control more bandwidth than the rest of the network.

    47. Re:So basically ... the attack wins? by david_thornley · · Score: 1

      Why would you need to spoof IPs when you're using a botnet for a DDoS?

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    48. Re:So basically ... the attack wins? by rsmith-mac · · Score: 1

      To make it even harder to stop.

    49. Re:So basically ... the attack wins? by robi5 · · Score: 1

      > Without Russian, China, and India going along with it, it would probably fail.

      Why, any non-participating countries can just be throttled as the source country is known and participation in the DDoS is known (if it isn't, the agreement is useless anyway).

    50. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      ISPs tried to do this sort of thing for a while - quarantine customers who were infected or had problems and make them get their stuff cleaned/patched/repaired. Guess what the fed up customers did? They went to other ISPs. ISPs stopped doing this, because they cannot afford to lose even bad customers who are paying for service.

    51. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      But the Akamai Prolexic service is meant to protect against DDoS and what they had offered Krebs for free. If their service can't handle it, that sure sounds like bad PR to me. Or, perhaps the secret sauce of how their service handles this is that it needs to churn through many netblocks and keep moving the target, but they ran out of netblocks to move it to. In other words, their service is a scam and not able to handle what it takes.

    52. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 1

      I suspect Akamai Prolexic has just been exposed as unable to protect against the biggest DDoS. If I was a top-paying client, I'd want to have multiple "DDoS" protection services, and I'd tell them if they want to have my business, they have to host Krebs and prove their product will actually do what it claims to do.

    53. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      "Good idea, just not doable." Imagination roll fail, in DnD fashion, hehe.

      A) You can make a whitelisted Freenet page on the WWW. You literally just make a very restrictive web server that only understands requests with specific ranges of URI's. Of course this can be hacked or DoS'd but nothing's perfect. Making it available through many servers would duplicate a lot of what Akamai offered.

      B) You can do comments on Freenet using said mirrors/gateways. Freesites can use other many methods to add comments even with a "static" page (you update it every so often for example). The problem then is Sybil/spammer attack. Requiring everyone to do FMS or WoT is not practical, but maybe a smart person can work around this.

    54. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      You ask a very good and intelligent question there. I don't know what other people's thoughts are, but my method would have to be non-public, as that easily presents workarounds. Having said that, that isn't going to happen so I'll have to answer your question. I got a way into it before I deleted everything and typed this response. You'll see a response later this weekend. Drawing board time, literally.

    55. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      Agreed completely. I'm still thinking but your idea is one of the base must-dos. I have to think this through to make sure that I'm not saying it incorrectly, but my initial thought is that if the protocol is not being used, you're automatically rejected. This puts a big limit upfront and encourages companies and individuals to upgrade firmware/OS on all routers to be compliant. If not, fingers can be pointed at the individual devices and companies running those devices that refuse to comply. Consumer demand will prevail in the end. It's not like you have to pay for it, it's just a firmware upgrade, or OS upgrade. If the manufacturer or provider of the firmware flash OS upgrade wants to charge money for it, nasty fingers could get pointed in their direction for breaking standards. What is being requested and set as a standard is not something that makes any company or entity lose anything, it only helps gain control over a problem. There is no reason not to do it. Therefore, after, oh, many months availability, those who refuse to upgrade will become primary targets in initial blocking. You don't implement BCP38 and any new DDoS prevention and mitigation standards, you become the first to be blocked upstream (if traffic is coming from that path in an attack). Customers will win in the end. Those who refuse to comply just become first-ignored (like emails coming from Nigerian people who want you to hold on to their dead relative's riches for them - lololol).
      I'm just starting on this. More to come. I always assumed that companies like Cisco would find ways to make sure that this kind of thing could immediately implement and set a fix as a base standard. Seeing that it's not required as a base standard, I'm coming up with something. I'm not saying I'm smarter than them or anyone else. Just doing something that they / others don't feel the need to do. :)

    56. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      They were providing the service 'pro-bono' according to Brian (via Twitter).

      They felt the free service they were providing to him was no longer worth risking paying customers service. I know this isn't the first time his site has been attacked, but this does seem to be the largest.

    57. Re:So basically ... the attack wins? by Sun · · Score: 1

      Akamai cached sites don't move between IPs. They are hosted on all of them. Anycast is used to direct your request to the DNS server nearest you, which then goes on to direct your actual HTTP request to the server nearest you. If the attacking computers are geographically located in a certain area, that area will suffer gravely, but other areas won't be affected at all.

      As such, ANY Akamai hosted site is DDoS protected by nature. A few years ago, an iOS update was slugish to arrive. Afterwards, we were told that there were considerable slowdowns to web sites not hosted by Akamai. In other words, it was not that the Akamai network couldn't handle the load of many people downloading the update at once. The Internet couldn't handle that load.

      There might be something technical I'm not aware of, but as far as I know, the DDoS protection product is a marketing thing, not a technical thing. You are, essentially, buying insurance against having to pay Akamai a whole lot of money for the DDoS traffic it served on your behalf. I am not 100% certain, but I do not think Akamai serve DDoS protected sites and regular CDN hosted sites differently.

      Whether it is bad PR or not is not for me to say. I do think that a host provider that gives a pro-bono service has a legitimate claim to say that non-paying customers should not be costing it more than it is willing to give. On the other hand, I also agree that, in this case, the DDoSers won.

      Shachar

      P.S.
      Akamai used to publish real time information on how much traffic the entire network was carrying. The page is still there, but it no longer carries that information. I don't know why.

    58. Re:So basically ... the attack wins? by Anonymous Coward · · Score: 0

      If I'm running that business or another one like it, I just got a BIG wakeup call, because I now know what I need to be able to defend myself against.

    59. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      The bandwidth issue is bullshit. It can be dropped at peering points where bandwidth is unlimited. Yes, I said unlimited... If you disagree you're an idiot. They have 1000s of 100GbE ports that are idle

    60. Re: So basically ... the attack wins? by Anonymous Coward · · Score: 0

      Can you share Akamai's true ability to mitigate a large volumetric DDoS attack? Akamai posted an outage notice at about the same time as the Krebs attack. Prevailing theory is that their actual capacity or capabilities are far inferior to what they advertise in bandwidth.

    61. Re: So basically ... the attack wins? by amorsen · · Score: 1

      You don't implement BCP38 and any new DDoS prevention and mitigation standards, you become the first to be blocked upstream

      The only ones who can do that are the large backhaul providers. Why would they annoy their customers by enforcing a policy that means they have to move less data? That would be a daft business move.

      --
      Finally! A year of moderation! Ready for 2019?
    62. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      The more I've thought about this, there is always a dead end. You just mentioned one - customer satisfaction.
      Unless DDoS attacks start ruining the online video viewing & Facebook addiction satisfaction of consumers, I don't see a solution in sight.
      I came up with about 5 different solutions that could work, but every one of them involved the average consumer understanding its purpose and accepting it. That, as the intelligent know, means that it ain't gonna happen. In each of the solutions I came up with, the consumer might feel like they are being targeted as an enemy, or someone who has done something wrong, when they don't even know that they have done anything. That's not to mention if they truly haven't done anything at all. What I'm saying is that if a consumer feels like they are unfairly treated 1 time out of 100, it's going to lead to a bunch of them grouping together in order to start some sort of movement BS (or people trying to be compensated for their suffering [not able to watch social media for 10 minutes one day]). People have a real problem understanding that sometimes you have to suffer for a short time in order to have a long-term solution with less suffering in the long term. Also, the length of each the âsufferingâ shortens as the total solution starts to work and be improved upon. People can't miss what they want for even 15 minutes to improve the total quality and inherent robustness of the internet's damage control protocol. I'm not even going to get started with how the same needed happiness of people results in an operating system that makes it very easy for people to seize control of it and execute these DDoS attacks. Even if that operating system is completely destroyed or another one becomes the primary, they're (abusers) going to find ways around it in order to take advantage of people, because you know, people are stupid. It's all about the "now now now, what I want now". I copyright this as the Veruca Effect. I don't understand why taking one minute to think about the potential problem is so painful to people. I guess that's why I'm not in the common category.

      Apologies for bad paragraph formatting. Posting this from phone.

    63. Re: So basically ... the attack wins? by Xest · · Score: 1

      Even this DDoS attack is still drastically smaller than Akamai's purported bandwidth. The whole point in their network is that they're supposed to be so distributed, with so much bandwidth that withstanding even this should be trivial - they claim to serve upto 30% of the world's daily requests, their network has a capacity of 30 Tbps and they're bottling it in the face of a 0.6 Tbps DDoS attack.

      This was really always Akamai's selling point - precisely that they do have far more bandwidth than any DDoS will ever muster. DDoS protection is in fact one of Akamai's single largest selling points - it's plastered all over their site, so if they're now saying they can't be bothered to deal with them then again, what's the point in Akamai?

      So sure you're argument makes sense for a provider that doesn't own a colossal amount of bandwidth, but you obviously don't know Akamai else you'd realise your entire argument is moot in relation to them because they're not short on bandwidth. You argued that you can't ever win against DDoS attacks unless you have more bandwidth, and, er, well, they do - by a massive margin and the chance of anyone building a bot net with the bandwidth to rival Akamai's capacity is basically zero.

      Taking the DDoS on the chin, which they could trivially do even with existing customer commitments whilst working with ISPs to deal with infected machines would've been a massive benefit for InfoSec (and been great for their profits as it would let them boost their reputation further and reduce future impact on their network). Instead they've decided to act with the attackers and tell the world they can no longer be trusted on their main selling point.

    64. Re: So basically ... the attack wins? by Aristos+Mazer · · Score: 1

      My understanding is that they have massive bandwidth for all their normal traffic, but their *spare* bandwidth for surprise DDoS traffic was more limited, and this exceeded their spare unused capacity and it exceeded their $$$ for negotiating additional. If I'm misunderstanding something, please explain what I've missed.

    65. Re:So basically ... the attack wins? by poofmeisterp · · Score: 1
    66. Re:So basically ... the attack wins? by poofmeisterp · · Score: 1

      There has to be something different in the TCP headers, the ordering of the packets, SOMETHING, that differentiates a browser and a standardized DDoS attack drones' packets.

      If that is researched and is NOT the case, I see the only way around it being a Human verification system, like CAPTCHA. Fail CAPTCHA > 3 times, block IP. But this IP blocking has to be done upstream and has to have a punishment system for sites that abuse it.

      Basically, there has to be a head controller of Internet comms (an organization without government involvement [yeah, right]), see above, or fail.

    67. Re:So basically ... the attack wins? by sjames · · Score: 1

      Sorry, there's really no difference. An attacker can easily appear to be the browser of their choice.

      Going to CAPTCHAs that would actually work would be as bad as shutting the routers off and going home. Are you really willing to solve a captcha every time a daemon on your system wants to do a DNS lookup of check in with a time server? Besides, they can actually be solved by putting up a porn site (solve the captcha, see the next image).

    68. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      Sorry, I didn't say that the CAPTCHA would cover a session, not an individual request. But, that would mean the whole concept of IP blocking after failure and all of the fallout would have to be tolerated or simplified. We know that's not going to happen. :(

    69. Re: So basically ... the attack wins? by sjames · · Score: 1

      Even a session wouldn't help. Many communications over the net are machine to machine. Also there's the whole solve the CAPTCHA by mechanical Turk (paid for with copied porn).

      I wouldn't be surprised if within a year of setting up such a scheme, CAPTCHAs for certain websites would develop a very high failure rate.

      How would a search engine spider the web?

    70. Re: So basically ... the attack wins? by poofmeisterp · · Score: 1

      Even a session wouldn't help. Many communications over the net are machine to machine. Also there's the whole solve the CAPTCHA by mechanical Turk (paid for with copied porn).

      I wouldn't be surprised if within a year of setting up such a scheme, CAPTCHAs for certain websites would develop a very high failure rate.

      How would a search engine spider the web?

      I get it. It's beyond my scope of presentable knowledge.

      Just one thing still bothers me - there has to be something that malware written to act as a DDoS attacker is lacking in its TCP transactions... Something. I give up in discussing it publicly, but there has to be something.

    71. Re: So basically ... the attack wins? by sjames · · Score: 1

      There honestly isn't. Especially if they use the system's TCP library. I say that as someone who has implemented a few network stacks.

    72. Re: So basically ... the attack wins? by Xest · · Score: 1

      They have a lot of spare capacity atm because they scaled up to support companies like Microsoft but Microsoft has now built it's own cloud and so no longer needs them, and they never really scaled down again afterwards.

      As such they could more than withstand this attack without customers being affected. The problem is that because they have lost big customers their ability to maintain year on year growth has of course suffered and become far harder. As such I'd wager this is more about cost cutting in not having to pay the staffing costs of dealing with this type of attack as there should be no bandwidth limitation that would prevent them handling this.

      To be clear, if this was a bandwidth issue, then that means that they also couldn't handle similar surges caused by things such as Netflix releasing the latest series of House of Cards. Yes, 655Gbps is a lot, but it's something a company like Akamai should have no problem dealing with, and if it now is, then they have bigger problems - like not being able to fulfil existing customer SLAs during times of extreme load even without a DDoS.

    73. Re: So basically ... the attack wins? by Aristos+Mazer · · Score: 1

      Useful information. I'd give you a +1 if I could.

    74. Re: So basically ... the attack wins? by Xest · · Score: 1

      Thinking about it (and I should've probably included this in my previous post!), you can actually put some numbers on it quite easily. Netflix recommend 5Mbps for 1080p streaming, and so 655Gbps = 670720Mbps.

      670720Mbps / 5Mbps = 134,144 simultaneous 1080p streams.

      That's quite a lot of users, but when you consider that Netflix has 83 million users it's fairly easy to see how that's the sort of typical surge they may get for their most popular releases (especially as 70% of Netflix subscribes apparently binge watch, meaning their consumption of data could easily go on for 10hrs+ on release day of a new series). Of course you may be able to drop the 5Mbps down a bit as well as that's no doubt an estimate and hence increase the number of concurrent viewers, but the point is that traffic is still within reasonable surge bounds for some of the bigger services, or some of the surge periods on the net like Black Friday even if you do so.

    75. Re: So basically ... the attack wins? by HappyPsycho · · Score: 1

      Uh, no.

      Spoofing filters are best setup at the last mile to customers. It can possibly be setup on the interconnections between / to small ISPs where there is no BGP transit going on (hence your BGP filters say what networks are expected, screw anything else).

      For the last mile there are the smallest number of variations at that point and limited number of variations for routes. By the time you hit the tier 1/2s who are backhauling hundreds of teras / petas of traffic you will hit not only the limitations of attempting to firewall that much traffic but lots of legitimate reasons for asynchronous traffic flows (most commonly traffic management).

    76. Re: So basically ... the attack wins? by amorsen · · Score: 1

      Yes, you didn't read the thread. The argument was that the last mile providers who don't implement BCP38 should be blocked from the Internet. Last mile providers can only be blocked by the large backhaul providers, and they are never going to do that.

      --
      Finally! A year of moderation! Ready for 2019?
    77. Re: So basically ... the attack wins? by Coren22 · · Score: 1

      No router could handle just dropping the packets. In order to put a rule in place like that, every packet needs to be inspected. When you are dealing with 600 Gb of DDoS traffic, the routers don't even have time to inspect the packets.

      I'm not even a security or network expert so I'm sure I've missed a few.

      I suppose that shows?

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
    78. Re: So basically ... the attack wins? by Coren22 · · Score: 1

      Um, router processing power isn't unlimited though.

      --
      APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  2. Akami folded, Kerbs is down by sinij · · Score: 4, Interesting

    From Kerbs on Security site:"The attack began around 8 p.m. ET on Sept. 20, and initial reports put it at approximately 665 Gigabits of traffic per second." .

    Akami were handling it as of yesterday, but it seems that they decided it was too expensive to stand by their client while he is under attack.

    Maybe a coincidence, but this started to happen after Kerbs exposed anti-DDoS 'protection' firm BackConnect use of BGP hijacking.

    1. Re: Akami folded, Kerbs is down by Anonymous Coward · · Score: 4, Interesting

      It's more than likely that BackConnect has DDoS'ers on staff...a quick look at their employees and their past guarantees it.

      The ultimate business model! DDoS a site, then come to them saying you'll help.

    2. Re:Akami folded, Kerbs is down by Sarten-X · · Score: 4, Informative

      too expensive to stand by their client

      He wasn't their (paying) client. He is a benefit to the infosec society, and was provided pro bono service in appreciation of and to assist his work.

      This attack probably cost Akamai a significant amount of money, so it's reasonable that they'd cut it off for a while.

      --
      You do not have a moral or legal right to do absolutely anything you want.
    3. Re: Akami folded, Kerbs is down by toonces33 · · Score: 2

      Indeed that seems to be the case, but the information is out there. If they want to shut Krebs up, they will need to take down faceplant and twaddle as well.

    4. Re:Akami folded, Kerbs is down by lastman71 · · Score: 1

      For the lazy web, a link on google cache:

      http://webcache.googleusercont...

    5. Re: Akami folded, Kerbs is down by Anonymous Coward · · Score: 1

      That's a nice website you have.

      Would be a shame if it came under attack, now wouldn't it?

  3. Chock one up by Anonymous Coward · · Score: 0

    for the boyz!

  4. Not a surprise by Anonymous Coward · · Score: 4, Insightful

    Akamai has a fiduciary responsibility to others on their network to ensure that they are not impacted by a single user. They were providing the service for free to Brian Krebs, he stated this. I do not work for Akamai(one of their competitors actually) but this is very, very common in this space.

    1. Re:Not a surprise by Anonymous Coward · · Score: 0

      Does this mean that they would dump him even if he was a paying customer? How about the company where you work? Would it?

    2. Re:Not a surprise by Anonymous Coward · · Score: 0

      Responsibility, fiduciary or otherwise, means nothing without the corresponding accountability. Accountability, in just about every form, just doesn't exist any more.

  5. So long... by Daetrin · · Score: 4, Insightful

    So they booted him off because he was costing them a ton of money and wasn't paying anything. (I guess they were providing him service as a charity?)

    But does that mean that they'll kick their paying customers off as well if the costs of defending them against attacks exceed the revenue they're getting from that specific customer? If so that would mean you could put Akamai out of business just by targeting one customer at a time, moving on to a new one as each one was evicted from the service.

    --
    This Space Intentionally Left Blank
    1. Re:So long... by Anonymous Coward · · Score: 1

      How did this actually cost Akamai "a ton of money"? Do you think Akamai pays for that traffic? They're what's known as a "peering slut". Akamai is present at practically every internet exchange, and peers with basically anyone. Everybody gladly enters into peering agreements with Akamai, because that unloads a lot of traffic that you'd otherwise have to route through expensive transit connections. Sure, they had and have people working to defeat that attack, but it's not like those people get paid extra for that. Don't get me wrong. I'm not saying "fire away, they can take it". DDoSers deserve to be hung by their balls. I'm just a bit skeptical about that "ton of money" argument that gets thrown around a lot in discussions about this attack.

    2. Re:So long... by SecurityGuy · · Score: 2

      Akamai is present at practically every internet exchange, and peers with basically anyone.

      I'd speculate that's exactly what they're talking about. Building and maintaining that infrastructure isn't free. If you have one guy using up X% of it, it's pretty reasonable to start thinking that the cost of serving that one guy is X% of your ongoing infrastructure costs.

      So, did Krebs personally cost them a ton of money? Probably not. Would he if they committed to keep serving him AND that sort of traffic load continued? Yes.

    3. Re:So long... by poofmeisterp · · Score: 1

      So they booted him off because he was costing them a ton of money and wasn't paying anything. (I guess they were providing him service as a charity?)

      But does that mean that they'll kick their paying customers off as well if the costs of defending them against attacks exceed the revenue they're getting from that specific customer? If so that would mean you could put Akamai out of business just by targeting one customer at a time, moving on to a new one as each one was evicted from the service.

      Interesting question. Let's find out. Who wants to volunteer? ;)

    4. Re:So long... by Anonymous Coward · · Score: 0

      That infrastructure isn't used up by these attacks. The only damage the DDoS can do is to the reputation, if and only if Akamai succumbs to the attack. Let's say Akamai had not given up. The attack would have continued, but certainly not forever. Every second of it would have given Akamai more information about the attacker. As long as this didn't impact other clients, there would have been no actual damage. It would have given Akamai a big PR boost, honestly. Who else could withstand a 600+ Gbps attack? But what's the situation now? Akamai has signaled its limit for defending against DDoS attacks. You might argue that they wouldn't drop a paying customer as easily, but a line has been crossed nevertheless: The threat was too big for Akamai. The attackers know that Akamai is vulnerable. Worse, Akamai's clients know that Akamai is vulnerable. Unless Akamai was actually about to get steamrolled by the attack, in which case they legitimately lost their reputation for DDoS secure hosting, their decision to kick Krebs off its servers was the actually damaging thing, not the attack.

  6. Pro Bono by hodagacz · · Score: 5, Insightful

    I don't blame Akamai at all and it sounds like Krebs doesn't either. There were a ridiculous amount of resources used on the attack and that shit gets expensive to block.

    1. Re: Pro Bono by Anonymous Coward · · Score: 0

      How, exactly, does it get expensive to block?

    2. Re: Pro Bono by Anonymous Coward · · Score: 2, Interesting

      If blacklisting IPs used in DDOSs could be reliably automated, it wouldn't be a problem.

    3. Re: Pro Bono by khallow · · Score: 1

      By reducing the quality of service of paying customers.

    4. Re: Pro Bono by I4ko · · Score: 4, Insightful

      Are you serious? Blocking traffic at high packet rate is expensive - CPU cycles, even with null routing even with FPGAs. It gets expensive as electrical cost at this level - extra heating, extra cooling, extra power. Even if your upstream has provided you with a blacklist community in their BGP announce policy, that traffic is blocked by something. Spend too many CPU cycles on blocking traffic, you miss on a few routing table updates, the tables expire and all that is there behind that router is gone. Your upstream may not like that. This is 650Gbps, think about that for a second - if this is TCP handshake you are looking at something like 20Gpps. Let that sink for a second, actually no, let it sink for a minute.

      If I was in Akamai's shoes that is what I would have done - get it off the network for a while, let anger, hot waves, hormones, or whatever other human emotion is fueling it cool off for a while. (And btw, never get a connected car because of this, especially one you need to start with your cellphone)

      Short of dropping the network completely off the BGP table in order to stop this at the source or the closest network to the source that speaks BGP cost will always be accrued. And it doesn't help that these days most network aggregate announces to /17 or /16 and don't accept/transmit to peers smaller ones. If I was Akamai I would ask that he moves his DNS to one special /16 that I keep unannounced, but that is a whole lot of IP space wasted. Even if Akamai has agreements to be able to keep /24 granularity of announces to all their peers, and have Krebs's site in some of their big pops where there are larger blocks, it takes time to move other customers out of that block and into other blocks, so they can drop the block off the network for a while without affecting others, even though most of the traffic will reach Akamai's upstreams (from the traffic point of view).

      Been there, done that 12-14 years ago. Much hasn't changed, only the numbers - 65 to 650 Mbps back then, 650Gbps now.
      Oh, I miss the days when someone on a 19.9Kbps modem could generate a 2+Mbps flood due to ppp compression.

    5. Re: Pro Bono by klui · · Score: 1

      It's already happening with IP cameras and IoT. https://twitter.com/olesovhcom...

    6. Re: Pro Bono by david_thornley · · Score: 1

      This appears to have been an action by a very, very large botnet. Blacklisting the IPs would mean identifying them, separating Joe who just wants to read what Krebs has to say from Jim who's part of a botnet.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  7. 620 Gbps per second by Anonymous Coward · · Score: 0

    Wow, really?

    1. Re: 620 Gbps per second by Sneeka2 · · Score: 5, Funny

      Yup. Twice the redundancy per second per second.

      --
      Bitten Apples are still better than dirty Windows...
    2. Re: 620 Gbps per second by Anonymous Coward · · Score: 1

      Yow! the traffic was accelerating at a tremendous clip!

    3. Re: 620 Gbps per second by Anonymous Coward · · Score: 0

      That is more than 63g acceleration, lethal in both cases it seems, physical and virtual worlds.

    4. Re: 620 Gbps per second by Anonymous Coward · · Score: 0

      It's not a clip, it's a magazine! ;-)

    5. Re: 620 Gbps per second by Anonymous Coward · · Score: 0

      This is another Manish Singh piece. He isn't being paid to be an Editor, he is being paid to be a...
      Actually, I haven't a clue.
      (That's twice so far today Manish...)

  8. If software publishers were held liable by Anonymous Coward · · Score: 0

    Hold all commercial software creators/publishers legally liable for security issues that enable these groups to create the botnets used in these attacks.

  9. Idiots by edibobb · · Score: 5, Informative

    Akamai is throwing away a great marketing opportunity and turning it into a huge negative. Why would I move to Akamai, knowing that they'll kick me off their network if I ever have trouble? They're throwing away their primary competitive advantage with one stupid decision.

    1. Re:Idiots by HBI · · Score: 1

      I agree entirely. Can you say bad publicity? I knew you could.

      --
      HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    2. Re:Idiots by Anonymous Coward · · Score: 0

      Kreb hosting was being provided for free. I bet the situation would be different were he a paying customer.

      Still would have been a good marketing opportunity to defend him but in this case it is understandable when paying customers are being impacted by a pro bono account.

    3. Re:Idiots by Opportunist · · Score: 2

      Bad publicity is one thing. Being the target of the BY FAR biggest DDoS in history is another thing. They can have the best publicity on earth if they have to fold tomorrow because all their customers bail due to not being reachable because of the DDoS.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    4. Re:Idiots by Anonymous Coward · · Score: 0

      Because they were providing it for free to Brian, they had no obligation to keep him on their network and suffer that kind of DDoS attack for free.

    5. Re:Idiots by ole_timer · · Score: 1

      a) we don't know what krebs paid akamai to do beyond content accelraiton at the edge b) we don;t know why akamai kicked off krebs (he did'nt pay for ddos protection? the akamai firewall?) c) there's no such thing as bad publicity

      --
      nothing to see here - move along
    6. Re:Idiots by ole_timer · · Score: 1

      acceleration

      --
      nothing to see here - move along
    7. Re:Idiots by Anonymous Coward · · Score: 1

      According to TFA, They were hosting it pro bono for him.

    8. Re:Idiots by Anonymous Coward · · Score: 0

      When you're providing protection it's pretty safe to assume the no publicity is bad publicity rule doesn't apply when your protection fails. I'd never heard of Akamai but I know if I was ever looking for hosting and resilience to attack was a priority I wouldn't go them them.

  10. Re:SOS by Anonymous Coward · · Score: 0

    Good, infants should be trafficked.

  11. Re:SOS by Opportunist · · Score: 1

    Are you here to provide a sample of what kind of spam the DDoS traffic consisted of or what's that got to do with the story?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  12. Didn't help that Krebs was really drunk at the tim by Anonymous Coward · · Score: 0

    e.

  13. Exactly by Anonymous Coward · · Score: 2, Insightful

    Blocking DDos is bread and butter basics to a content delivery network, so why are they delivering 620Gbps of data on a DDOS attack?

    I would consider it to be good practice, for when a more important customer gets attacked. At the very least I would consider it BAD practice to show that DDos can work easily against an Akamai site.

    Akamai need to do an about turn, politely tackle the DDos and sack the idiot that decided they'd fold to a simple distributed denial of service attack.

  14. 620 Gigabits per second per second?!?! by Anonymous Coward · · Score: 0

    620 Gbps per second?!?! So every second, the traffic increases by *another* 620 Gbps? Next thing you know, we'll have Automatic Teller Machine machines, Personal Identification Number numbers, and Liquid Crystal Display displays running amok.

    1. Re: 620 Gigabits per second per second?!?! by Anonymous Coward · · Score: 0

      I for one welcome our new Overlord overlords, why don't you?

  15. Units by Anonymous Coward · · Score: 0

    more than 620 Gbps per second of traffic

    So that's what, like 4.17 cubic hogsheads?

  16. This is a very real threat to free speech. by Anonymous Coward · · Score: 0

    Say something, get blown off the web.

    1. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 4, Insightful

      The reason that this DDos is able to generate so much force is they aren't just using malware-infected PCs. They are also using security cameras and other devices that connect to the internet. Thanks to all the companies who don't give two shits about securing their devices.

    2. Re:This is a very real threat to free speech. by Luthair · · Score: 2

      Recently botnets haven't really been the issue, they've mostly been reflection attacks which use DNS, NTP, etc. to amplify the size of the requests. If networks started to drop UDP packets with spoofed addresses that would reduce the problem significantly (so would convincing a huge number of people to fix their DNS or NTP servers, but that is harder).

    3. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      Say something, get blown off the web.

      Wow. Sounds just like "progressive" "free speech is great as long as you agree with my arrogant, limited views" college twerps.

    4. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      You completely misconstrue what Brian Krebs does. There is nothing political in his activities. He purely reports on numerous bad actors in the information arena.

    5. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      Apparently this attack was performed directly by the botnet using TCP. There was no amplification going on.

    6. Re:This is a very real threat to free speech. by ADRA · · Score: 1

      Or, you know - blame ISP's for not shutting down DDOS nodes. I assume the biggest problem is that we don't have a DDOS early-warning system for flagging and cutting abusers from the upstream pro-actively.

      --
      Bye!
    7. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      The Internet of Things has arrived. Fantastic!

    8. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      They are also using security cameras and other devices that connect to the internet. Thanks to all the companies who don't give two shits about securing their devices.

      What an awesome TOR network they could run if they cared.

    9. Re:This is a very real threat to free speech. by Anonymous Coward · · Score: 0

      They WOULD give a shit if USA and other countries punished crap hardware purveyors with import duties reflecting security practices.
      The second thing to do is confiscate or wipe broken devices.

      If USA Inc won't - the malevolent lot will continue to cost USA .

  17. Re:Haha Akamai is Kapakai by toonces33 · · Score: 1

    I wouldn;t say that - the size of the attack is beyond anything seen before. They are reporting 665 Gbps. Let the sheer size of that number sink in for a while.

  18. So much for Akamai... by moorley · · Score: 1

    If they can't handle a DDOS, any DDOS competently then they just made it clear they are a minor player....

    Wonder if AWS, Azure or Google will pick him up as a PR move.

    --
    "Don't fear death... fear not living..." -me :)
    1. Re:So much for Akamai... by david_thornley · · Score: 1

      Any service can be taken down with a DDoS attack from a sufficiently large botnet. Are you contending there are no major players?

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  19. This is what happens. . . by smooth+wombat · · Score: 4, Interesting

    when you're honest. Krebs doesn't pull his punches and the whiners of the world (i.e. those he lambasted for having low quality products or game play) don't like it and now they're being petulant two year olds.

    Just goes to show the mentality of supposed adults. Especially the cowards who sit behind a keyboard and try to destroy the work of others because they didn't get their lollipop.

    --
    We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    1. Re:This is what happens. . . by Anonymous Coward · · Score: 0

      What it really shows is the internet as designed is not useful for real business and professionals. A better system with higher security and identification standards is needed. With harsh criminal penalties for attempting to work around those standards, or at minimum you get cut off from access permanently for abusing it.

  20. Conspiracy Theory! by Kludge · · Score: 1, Interesting

    Akamai does not like Krebs exposing out the DDoS attackers, because fear of DDoS is what brings Akamai business. This is a good excuse to try to get rid of Krebs.

    I have said it before, and I will say it again: Brian Krebs rocks.

    1. Re: Conspiracy Theory! by Anonymous Coward · · Score: 2, Interesting

      On the gripping hand, this is great publicity for the DDOS service behind the attack

    2. Re:Conspiracy Theory! by q4Fry · · Score: 1

      Akamai does not like Krebs exposing out the DDoS attackers, because fear of DDoS is what brings Akamai business. This is a good excuse to try to get rid of Krebs.

      That doesn't make sense. Akamai can't convincingly say "We can help [you businesses] with this scary problem of DDoS attacks" when Akamai demonstrably couldn't protect Krebs from a DDoS attack. From a financial perspective (i.e. "This is costing us too much money"), their actions make sense. From a conspiratorial one? Not at all.

    3. Re:Conspiracy Theory! by ole_timer · · Score: 2

      i would pay akamai to kick off freeloaders so i'm protected. win-win for me. not so much for krebs.

      --
      nothing to see here - move along
    4. Re: Conspiracy Theory! by Anonymous Coward · · Score: 0

      Counterargument: They hosted him for free up to now, and weathered other smaller attacks.

  21. Iot devices blamed by Anonymous Coward · · Score: 0

    Much of the traffic comes from iot connected crap with poor security.
    Real headline should be
    Krebsonsecurity put on ice by freezer

  22. Re:Haha Akamai is Kapakai by Zocalo · · Score: 2

    Actually, that's not the case, despite a lot of the coverage claiming it is. It's the largest seen by by Akamai, but OVH reported a DDoS peaking at 800Gb/s earlier the same day - although there are no indications of a connection (yet?). What's perhaps more interesting about the DDoS on Krebs isn't the size of it so much that it apparently wasn't a UDP amplification attack, which is the norm for DDoS these days, but TCP/GRE - the botnet used was generating all that traffic on its own Both attacks are far larger than any one group was thought capable of doing (until now) and might be an indication that the number of botnet operators might not be as large as suspected, but instead consists of a smaller number of operators with multiple botnets under their control.

    --
    UNIX? They're not even circumcised! Savages!
  23. Re:Haha Akamai is Kapakai by hsthompson69 · · Score: 2

    It's "kapakahi".

    http://wehewehe.org/gsdl2.85/c...

    vs. One-sided, crooked, lopsided, sideways; bent, askew; biased, partial to one side; to show favoritism. Lit., one side. Cf. lawe kapakahi. K kapakahi ka l ma Wai-anae (saying), the sun appears lopsided at Wai-anae [said by the goddess Hiiaka while her lover was dallying with someone else, hence said of any unlawful dallying].

    "kapakai" is very different:

    http://wehewehe.org/gsdl2.85/c...

    vs. To wait for. Rare.

  24. So the lesson is: by MitchDev · · Score: 1

    Cyber-terrorism gets you what you want apparently.

    Akamai Technologies should be dumped by everyone who uses them and should not get any new customers.

  25. archive.is link. by Mal-2 · · Score: 2

    Here's an archive.is link for those not wanting to deal with BI's paywall.

    --
    How is the Riemann zeta function like Trump rallies? Both have an endless number of trivial zeros.
  26. Where's that guy from the thread a few days ago! by bad-badtz-maru · · Score: 3, Funny

    Where's that Slashdotter from the thread last week who posted 5 easy steps to stopping a DDoS! Akamai needs your "expertise"!

  27. This was one hell of an attack by Anonymous Coward · · Score: 4, Interesting

    From the right up on it, it was peaking at 665 gigabits/sec and was leveraging a massive botnet trying to make direct connections instead of using DNS reflection. They kept his site up during this and numerous other large scale attacks. Claiming that Akamai isn't a "bullet proof" host because they decided their support cost and impact to their customers outweighed the free-marketing/goodwill is just asinine. You're the same entitled person that uses free web services and then b*tches when they start charging or go under aren't you?

    1. Re:This was one hell of an attack by MightyYar · · Score: 2

      You're the same entitled person that uses free web services and then b*tches when they start charging or go under aren't you?

      I'm not a business person. If someone tells me that they have some "free" business plan that they claim will work, I can be skeptical, but it's not really on me when they are exposed as wrong. If you advertise a service as one thing and then pull a switcharoo, you should be called out. You call that "entitlement", I call it broken promises - though I'll also go along with "naive", since by now we should probably just ignore the promises of "free". Though here I am using gmail for going on a decade and a half...

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    2. Re:This was one hell of an attack by Anonymous Coward · · Score: 0

      From the right up on it, it was peaking at 665 gigabits/sec and was leveraging a massive botnet trying to make direct connections instead of using DNS reflection.

      Rather intense, yes.

      They kept his site up during this and numerous other large scale attacks.

      That was a good thing, and they should be commended for it.

      Claiming that Akamai isn't a "bullet proof" host because they decided their support cost and impact to their customers outweighed the free-marketing/goodwill is just asinine.

      No, it actually isn't asinine. It doesn't really matter why they dropped his site. The fact remains that they did, and thus the impression has been made that they are not as impervious as most would have thought before they made this decision. Again, it doesn't matter why they did it. In the end, what matters is that they did do it, and apparently felt they had to.

      It has nothing to do with entitlement. It has everything to do with their reputation which is now a bit worse than it was before, regardless of their reasoning.

      You're the same entitled person that uses free web services and then b*tches when they start charging or go under aren't you?

      I am not the person you responded to, but I doubt it. Also, I suggest you leave the personal attacks out of the discussion. You gain nothing from them. Quite the opposite.

    3. Re:This was one hell of an attack by itwerx · · Score: 2

      Though here I am using gmail for going on a decade and a half...

      Gmail has never been free, it is paid for by advertising.

    4. Re:This was one hell of an attack by MightyYar · · Score: 1

      When I came to Slashdot, they promised a pedant-free experience.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
  28. It's a lost opportunity by Anonymous Coward · · Score: 0

    He's high profile, they hosted him for a PR gain.

    So Akamai had the chance to show how their content delivery is hardened against distributed denial of service attacks and would have benefitted from the PR. Instead they cut him loose and got 10x the bad PR from that.

    At best we can say its a lost PR opportunity, but at worst they'd screwed up and someone should be fired.

    When your business is delivering content, then folding for a DDos attack shows you're not fit for purpose to higher paying customers. As it is each customer is thinking... at what level of attack will Akamai let us down?

  29. Google Sites by Danathar · · Score: 1

    I wonder how much more successful Krebs would be moving his site to a sites.google.com? Sure, he'd have to deal with the awful feature set there, but I'd like to see anybody DDOS google successfully. I don't think it's actually been done has it?

  30. Re:Null route automation is possible... apk by Anonymous Coward · · Score: 0

    Sshh, Peter, this is big boys' stuff. Go play in your corner with your hosts files and ARP command.

  31. Re:Null route automation is possible... apk by Anonymous Coward · · Score: 0

    We tried some automation of this sort of thing about 10 years ago. We very quickly ran into limitations of the operating system when we tried to block very large numbers of ip addresses. At the time some OS's were better than others, and blocking blocks instead of individual ips helped, but it's important to test this kind of thing before you need it. Of course it may all be better these days.

  32. Brian's tweet re Akami by Anonymous Coward · · Score: 0

    "
    briankrebs @briankrebs
    Before everyone beats up on Akamai/Prolexic too much, they were providing me service pro bono. So, as I said, I don't fault them at all.
    "

    So, can someone downvote the Akami witch hunt please?

  33. Google should step up for this one. by Anonymous Coward · · Score: 0

    Google should step up for this one.
    Help a security reporter/researcher out dudes.

    Akamai is awesome for protecting him this long. Obviously, we now now the limitations of that service.

    Krebs could help too, but switching to static content and external feedback locations.

    I was a dedicated reader of Krebs stuff for years. He has proven to be an excellent, accurate, trustworthy reporter. His deep stories are the best in the business with insights not usually available outside the cracker community.

    So - hey - google. You gonna help? Do no evil, right?

  34. So why wouldn't they not just attack Akamai now? by jtara · · Score: 0

    It was a risky move, IMO, on the part of Akamai, and sends a horrible message about their service.

    Were it not that the perpetrators have now apparently been arrested, why would they not then go back and go after Akami in general, just to prove a point? In fact, why wouldn't others now go after Akamai, just to prove a point?

    Perhaps it was not really a severe impact to Akamai (other than cost), and they could have withstood the attack. If somebody wants to prove that they are the King of DDOS, now what an opportunity to prove that they have the capability!

    Akamai risked bringing on a bigger attack. And they risked their reputation. A smart move on the part of a competitor would be to welcome Krebs. I fully expect some smart company will do that in the coming days.

  35. Re:Haha Akamai is Kapakai by I4ko · · Score: 2

    At that size I am sending employees on planes with jackhammers and bobcats to start cutting fibre near the source.

  36. Should work, e.g. in hosts? apk by Anonymous Coward · · Score: 0

    See subject: Via hosts files I block 3,993,505++ & growing host-domain names - I can't see modern OS failing doing it @ routing table (or firewall) levels nowadays.

    * "Play it again Sam" & try it again I say (yes, it really works & using what you ALREADY HAVE AVAILABLE NATIVELY in your OS' IP stack & tools for it...)

    APK

    P.S.=> That is, unless you ENJOY being "DDoS'd/DoS'd" that is OR spending monies on things you really don't NEED to be spending on (of course, it helps "burn budget" @ year end too, now doesn't it? Yes, or you don't get the SAME or MORE next year - I consult @ year end every year for 10 yrs. now making monies on that basis in fact (very sad considering their own IT staff could do it but that budget needs BURNING, lol, for the reasons I noted as the REAL REASON it's done))... apk

  37. Re:Null route automation is possible... apk by TroII · · Score: 2

    Proper egress filtering by consumer ISPs would stop most of the DNS/NTP/etc amplification attacks overnight. There's absolutely no reason any packets should be leaving, say, Comcast's network with an Akamai source IP on them. But this isn't an amplification attack, at least according to the previous article. This is apparently the old style DDoS, think LOIC, many thousands of hosts making "legitimate" (as far as the TCP transaction is concerned) connections, exhausting resources, sending giant requests, etc.

  38. Re:Where's that guy from the thread a few days ago by Anonymous Coward · · Score: 0

    Maybe they should try Google's Project Shield. https://projectshield.withgoogle.com/public/

  39. Re:Where's that guy from the thread a few days ago by bad-badtz-maru · · Score: 1

    Great idea!

  40. Re:Null route automation is possible... apk by Anonymous Coward · · Score: 0

    Border routers accept Windows batch and Powershell scripts? Who knew...

  41. Here's some I posted here years ago... apk by Anonymous Coward · · Score: 0

    See subject & (for Windows) http://yro.slashdot.org/comments.pl?sid=4755487&cid=46161879/ & DDoS appliances e.g.-> https://www.google.com/search?q=DDoS+Appliance&btnG=Search&client=opera&hs=Mhq&channel=suggest&gbv=1/

    * Enjoy!

    APK

    P.S.=> There's also NULL ROUTING (that your own techs/admins can program arp & route commands for easily enough)-> https://it.slashdot.org/comments.pl?sid=9692843&cid=52947119/ ... apk

    1. Re:Here's some I posted here years ago... apk by bad-badtz-maru · · Score: 1

      The first link looks like the solution, send it to Akamai, they just need to enable SYN cookies on their Windows machine!

  42. Amazon should come forward by Anonymous Coward · · Score: 0

    Amazon should come forward to host Kreb's site. This provides a good opportunity to prove the world how robust they can be with their cloud infrastructure against DDOS attacks.

  43. Re:Where's that guy from the thread a few days ago by Anonymous Coward · · Score: 0

    Oh, he's further up the thread claiming they just need to write a Powershell script to automatically manage their hosts file.

  44. Structured Sting Operation to Track DDoSers by Anonymous Coward · · Score: 0

    Anyone participating is a fool.. this will be big news soon.

  45. Dear "Freddie 'dunning' Krueger" (lol)... apk by Anonymous Coward · · Score: 0

    I came up w/ something YOU /. menials should've? Yes https://it.slashdot.org/comments.pl?sid=9692843&cid=52947119/

    HOWEVER:

    Yes, I forget actually THINKING & WORKING is beyond your ken (lol, since that's NO HUGE TASK considering the tools ARE THERE ALREADY for you to do this w/ in null routing).

    (Move the goalposts ALL YOU LIKE - after all - I saw nothing of border routers in the person I replied to ... BUT those routers DO HAVE FIREWALL RULES that could block this as well - guess what? YOU FAIL, lol, as always vs. myself)

    APK

    P.S.=> There's also a LOT MORE you can do vs. various forms of DDoS https://yro.slashdot.org/comments.pl?sid=4755487&cid=46161879/ (even DDoS appliances if coding is "too much" for you even in PUNY scripting others' tools (that coders like myself create for you to merely 'use', you user with a better password (nothing more))... apk

    1. Re:Dear "Freddie 'dunning' Krueger" (lol)... apk by Anonymous Coward · · Score: 0

      If you can't imagine a modern OS choking on 620 Gbps you are truly way out of your league here. These are distributed denial of service attacks were are talking about here, note the distributed part. These packets are indistinguishable from normal traffic, it's not just a few computers sending a massive amount of traffic. Like you say, that could easily be dealt with. This is basically a massive slashdotting botnet, each components sending normal requests, but distributed of a vast number of machines. I just can't wrap my head around how you think you can filter that with a couple scripts, it's just laughable. I don't even know why I'm replying to this, it's like hearing a rough carpenter say, "I don't see how hard it could be to keep one of those skyscrapers standing! It's just a couple bricks and stuff, I've never had a house fall down!".

      And yes, I'm replying anonymously because I'd like to enjoy my time on Slashdot rather than have some moron stalk me with autism drenched posts about host files.

  46. Re: Haha Akamai is Kapakai by Anonymous Coward · · Score: 0

    Shut up

  47. Seems to me this is a design flaw of the web by Solandri · · Score: 1

    The web is asymmetric. A single host (or hosts in the case of a CDN like Akamai) sends files to thousands or millions of clients (web browsers).

    This seems like something a distributed symmetric system like bittorrent could fix. Each browser already caches files for the web sites it's visited. If they could also be made to serve those cached pages to other web browsers (with a checksum to allow the new recipient to detect and discard corrupted caches), that would solve server overloading. The more popular a site/page is, the more computers it's cached on, and the more "load" it can take - it's self-scaling.

    Making it SSL-only would prevent manipulation of the content (cache the page pre-decryption) since you'd need the original site's private key to alter the content in any meaningful way. A bad actor could still turn their cache into gibberish, but you should be able to counter that with automated blacklists of computers with corrupted caches, and using multiple parity copies for redundancy - sort of a distributed RAID. Basically the same problems bittorrent has to deal with.

    1. Re:Seems to me this is a design flaw of the web by Anonymous Coward · · Score: 0

      It's called freenet

    2. Re:Seems to me this is a design flaw of the web by Anonymous Coward · · Score: 0

      Well, like that comment on Freenet, you can't DDoS a specific site on Freenet, but you sure as heck can DDoS the entire network. I wonder if the SSL itself could be abused to trigger CPU-intensive tasks that would take down the proxy.

  48. WayBack link to his site, with lead of recent post by lamber45 · · Score: 1

    Since it'll be offline for a while, perhaps... Israeli Online Attack Service ‘vDOS’ Earned $600,000 in Two Years.

    vDOS — a “booter” service that has earned in excess of $600,000 over the past two years helping customers coordinate more than 150,000 so-called distributed denial-of-service (DDoS) attacks designed to knock Web sites offline — has been massively hacked, spilling secrets about tens of thousands of paying customers and their targets.

    The vDOS database, obtained by KrebsOnSecurity.com at the end of July 2016, points to two young men in Israel as the principal owners and masterminds of the attack service, with support services coming from several young hackers in the United States. [...]

  49. Re:Where's that guy from the thread a few days ago by bad-badtz-maru · · Score: 1

    I see him up there now - can't believe the crap he posts, he really believes he has the solution...

  50. Maybe Krebs should talk to Google by swillden · · Score: 1

    Maybe Krebs should talk to Google about getting on their Project Shield

    --
    Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  51. Re: Where's that guy from the thread a few days ag by Anonymous Coward · · Score: 0

    Hehe. Yes. Doing something at the end of the pipe will stop it before it gets there. Hmm. Fucking script kiddies at 40 years old.

  52. Depends on type of DoS/DDoS attack by Anonymous Coward · · Score: 0

    See subject: I'm not certain this IS a "SYN-ACK" type of DDoS/DoS though (that only works on that type iirc).

    * There's plenty more I illustrated too (DDoS appliances, Null-Routing (using tools you ALREADY NATIVELY HAVE, & even border/network perimeter filtering @ router firewall levels too)).

    APK

    P.S.=> Upstream bandwidth's necessary for some of these too (a constraint in & of itself)... apk

    1. Re:Depends on type of DoS/DDoS attack by bad-badtz-maru · · Score: 1

      It seems like you don't understand the scale and scope of these attacks. You're approaching it the way you'd approach someone pointing a few circuits at you. These are millions upon millions of requests all coming from different addresses in an insanely short period of time. Nothing outside of a few highly-specialized tools can meaningfully inspect traffic at those rates. The reason Amazon, eBay, Microsoft, etc can handle it is just sheer size... there's no special technology, they're just already scaled out to handle everyone shopping on Black Friday, which is inherently a larger set of requests than any DDoS.

    2. Re:Depends on type of DoS/DDoS attack by Anonymous Coward · · Score: 0

      See subject: I'm not certain this IS a "SYN-ACK" type of DDoS/DoS though (that only works on that type iirc).

      It's not. All significant web hosting services and service providers defend against that, including Akamai.

      There's plenty more I illustrated too (DDoS appliances, Null-Routing (using tools you ALREADY NATIVELY HAVE, & even border/network perimeter filtering @ router firewall levels too)).

      Null routing is fine if all you care about is getting the load off your systems, but it means completely disabling all legitimate traffic as well. Which is fine if it's your only option, but it's a last resort.

      Here's a better solution for Krebs: Use Google's Project Shield. It's free for journalists, and it will keep legitimate traffic mostly flowing while stopping DDoS attacks. It uses lots of nifty anti-DDoS tricks, but its primary weapon is simply size. The system of reverse proxies at the edge of Google's network is so large, powerful and well-connected that DDoS attacks simply cannot swamp it or its network links. It has to be, to handle Google's normal traffic. And, of course, it's good at recognizing DDoS attacks and filtering them out, while passing regular traffic through.

  53. LIES "Freddie 'dunning' Krueger"? by Anonymous Coward · · Score: 0

    See subject (it's you, lol): I didn't note hosts vs. DDoS but rather arp/route NULL ROUTING liar https://it.slashdot.org/comments.pl?sid=9692843&cid=52947119/

    * You're pitiful... or illiterate - take your pick but you FAIL as always worm - NULL ROUTING WORKS vs. DoS/DDoS & it's SO SAD I had to show you MENIAL network techs/admins tools that already NATIVELY do the job & you couldn't on YOUR OWN BALLCOURT, networking (took a coder, you know - guys like me who create tools MERE MENIALS with LOW skills merely use, the lot of you merely USERS WITH A BETTER PASSWORD, lol...!)

    APK

    P.S.=> It has, however, been a REAL PLEASURE exposing you as a liar trying to "put words in my mouth" I never ONCE stated (hosts isn't a solution here & I didn't note it was vs. DDoS either liar)... apk

  54. Re:Haha Akamai is Kapakai by Noah+Haders · · Score: 1

    Actually, the summary says 620gbpsps. Even worse!

  55. Re: Haha Akamai is Kapakai by hsthompson69 · · Score: 1

    Just trying to help the haole :)

    I'll bet you think it's called "Harry Karry" too :) Or "Karry okie" :)

  56. Re:SOS by D00MSlayer · · Score: 1

    Take your racist bullshit somewhere else

  57. What have YOU offered? Zero afaik by Anonymous Coward · · Score: 0

    See subject: My posts cover many methods vs. types of DDoS or DoS - what have YOU offered that's better as a potential solution here?

    * N O T H I N G!

    (Between arp/route null routing + DDoS appliances and CDN distribution of site parts plus OS settings &t router or software firewalls I've covered a LOT MORE GROUND vs. DDoS than any SINGLE person has on this page, hands-down & unquestionably...)

    APK

    P.S.=> "I don't understand the scale & scope"? Question is, do YOU?? I don't see it in potential solutions as I have offered QUITE comprehensively - & IF I was an asshole, trust me, I could code the tools that GENERATE these types of attacks (distributed too, easily) - I've been coding custom networking tools for decades (since 1995 in fact professionally)... apk

  58. Akamai Technologies can't protect you against DDoS by khz6955 · · Score: 1
  59. Again: What did YOU offer? ZERO! by Anonymous Coward · · Score: 0

    See subject & this blabbermouth blowhard bullshitter that you are https://it.slashdot.org/comments.pl?sid=9692843&cid=52947553/

    * :)

    (Lots of bullshit from you, no potential solutions, & yet I offer damn near the full gamut possible vs. DDoS by comparison in that link alone above earlier by myself (not you))

    APK

    P.S.=> Why I waste MY time on fake name using CHUMP TROLL BLOWHARDS (with nothing of value to offer here unlike myself in my posts) like you online is sometimes beyond me... apk

    1. Re:Again: What did YOU offer? ZERO! by bad-badtz-maru · · Score: 1

      This DDoS is 600+ Gbps but the DDoS devices you link to handle 40 Gbps. How does that work? In another post, you suggest using a CDN. Did you read the original article? Akamai IS a CDN! It's very clear you have no concept of the traffic levels involved. It's hundreds and hundreds of servers involved, it's traffic levels where expensive routers start to fall over due to load. It's not something you manage with $200 appliances or shell scripts.

      Part of being intelligent is realizing that some things are above your current understanding. That's why I have no solutions. However, I do understand enough to know that your solutions are amateur, given the sheer size of the data flow under discussion. You don't even recognize the scale and present solutions that are completely unworkable in that scale.

  60. Answer the question: What did YOU offer? Zero by Anonymous Coward · · Score: 0

    See subject: It's all I have to ask you (you evade it) & I offer more than ANY 1 person in this article did here https://it.slashdot.org/comments.pl?sid=9692843&cid=52947553/

    * You lose just on my subject alone...

    APK

    P.S.=> Part of being intelligent is offering (even potential) solutions to problems - you don't offer ANY, lol... apk

    1. Re:Answer the question: What did YOU offer? Zero by bad-badtz-maru · · Score: 1

      I offered no viable solution. Neither did you.

  61. Re:Haha Akamai is Kapakai by Anonymous Coward · · Score: 0

    You are confusing hawaiian and pidgin.
    I grew up in hawaii. I learned my pidgin in the school yard.
    And kapakai is definitely "all fucked up" in pidgin.

    More proof: http://www.mauiinformationguide.com/speaking-pidgin.php

  62. Re:Little BOYS using programmer's tools? by Anonymous Coward · · Score: 0

    Oh dear, dickless is off his meds again, having the I crushed you delusion, sad really poor fellow, always making such a fool of himself.

  63. Akamai cannot handle a DDoS - who can? by Anonymous Coward · · Score: 0

    So apparently Akamai cannot handle a DDoS, or not without some extreme costs or collateral damage. Seems this would be a great time for one of those places that claim to be able to provide protection from this sort of thing to step up and say, "We can handle anything, including hosting Krebs with all his haters trying to take him offline."

  64. Re:Little BOYS using programmer's tools? by Anonymous Coward · · Score: 0

    Weak off topic unidentifiable ac troll he states a fact techs depend on coders for tools to use. Minus them they're zero. You must be one and the truth of his words cut you right to the bone. Truth is like that.

  65. WRONG: Learn to read... apk by Anonymous Coward · · Score: 0

    See BOTTOM of this post & what both MS + Amazon do (they have cash to do it) http://yro.slashdot.org/comments.pl?sid=4755487&cid=46161879/

    BOTH COMPANIES HANDLE "rushes" BIGGER THAN WHAT THIS IS, especially on holidays for Amazon (which is WHY they contructed their network thus).

    * Yes - it's got POTENTIAL here even vs. 600++ g/mbps attacks & to warn them @ 2-6g/mbps to do null routing (which yes, can BE AUTOMATED AS I outlined for you networker menials who obviously need coders like myself to SHOW YOU HOW TO TO DO IT YOURSELVES easily, even in scripts).

    APK

    P.S.=> That's one hell of a LOT MORE than you offered:

    "I offered no viable solution. Neither did you" - by bad-badtz-maru ( 119524 ) on Friday September 23, 2016 @05:20PM (#52949445)

    Oh, really? I offer EVERY POSSIBLE DoS/DDoS defensive measure known there IS afaik @ least (where you admittedly offer SQUAT) - from least costly to MOST costly (see subject & Amazon + MS measures)... apk

  66. Null routing doesn't mean that! by Anonymous Coward · · Score: 0

    "Null routing is fine if all you care about is getting the load off your systems, but it means completely disabling all legitimate traffic as well. Which is fine if it's your only option, but it's a last resort" - by Anonymous Coward on Friday September 23, 2016 @05:38PM (#52949567)M

    You don't disable LEGIT stuff doing null routes. I went from cheapest methods to MOST expensive (Amazon/MS) http://yro.slashdot.org/comments.pl?sid=4755487&cid=46161879/ & that tail end of it SHOWS that HUGE attacks can be detected + blocked (IF a company has the cash as MS/AMAZON DO for a "DDoS proof" network architecture) - once you have that, you can null route (or firewall) attacks based on IP addresses as I noted also in other posts on this page.

    * Lastly - I know it's not (which is WHY I said what I did as far as SYN/ACK protection in my reply which someone oddly said before that reply of mine "that's the answer" etc., via TCP/IP parameterization) - I merely offered every possible defense I knew of vs. DDoS (more than anyone on this page has).

    APK

    P.S.=> That MS/AMAZON setup's got the BEST OVERALL POTENTIAL for protection for guys like Krebs (who obviously pissed off some online scumbags exposing them & their heinous little machinations obviously) - but that's more cash than guys like Mr. Krebs has available I wager (maybe this "project shield" is a way, but I'd wager it's based on things like MS & AMAZON are already long been doing) & others mentioned it LONG before you did (probably more GOOGLE SHILLS as usual, lol - this site's LOADED with them considering it's GOOGLE SPONSORED SLASHDOT bigtime in ads)... apk

  67. Was the DDoS why Akamai discontinued service? by jetole · · Score: 1

    Has Akamai come right out and said that the DDoS is the cause of why they are discontinuing service? If that is the reason, well, it's a business decision, but it doesn't look good in their capability to stop DDoS. Another possibility is, did Krebs disclose confidential information that violated his contact with Akamai when he disclosed details? I don't know but that may be another viable reason why Akamai has discontinued services to him or it could be a viable excuse of how he violated his contract allowing them to choose to discontinue services for whatever reason they wish due to the contract being nullified by breech from the customer. Again, I don't know, but it's worth considering that as a possibility.

  68. Re:Null route automation is possible... apk by Anonymous Coward · · Score: 0

    Trying to minus mod apk hide putting you in your place menial https://it.slashdot.org/comments.pl?sid=9692843&cid=52947339alongwithhttps://it.slashdot.org/commen...> too? That's how we all know what the good posts are like when APK outsmarts the Google shills trying to champion their project shield mere imitation of what both Amazon and Microsoft do for a long time now

  69. Re:Haha Akamai is Kapakai by hsthompson69 · · Score: 1

    Um, it's "kapakahi" in pidgin too. Not sure what school yard you were in when you heard "kapakahi", but if you missed the "h", it's your hearing that's off, or they had a speech impediment.

    Your cite is from a haole :)

    Try Peppo's: http://www.aloha-hawaii.com/cu...

    "CHOP SUEY
    Kapakahi; all mixed up."

    But go ahead, tell me more about what a local boy you were, and how haoles taught you how to speak pidgin :)

  70. Learn to read chicken dick... apk by Anonymous Coward · · Score: 0

    Microsoft & Amazon have setups that could handle it (dropping connections @ the 6gbps onward mark) https://yro.slashdot.org/comments.pl?sid=4755487&cid=46161879/ you ignorant little illiterate cowardly fuck!

    APK

    P.S.=> You're replying anonymously because I've CRUSHED YOU BEFORE under your "registered 'luser'" name here (fake names for FAKE FUCKS LIKE YOU) before & you know it - you just don't want me tossing your previous fails back @ you to laugh @ you MORE over them (@ your expense, weasel)... apk

  71. Re:Haha Akamai is Kapakai by Coren22 · · Score: 1

    Is that the acceleration of the attack?

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?