• by walth on 10/4/2024, 1:00:09 AM

    Meanwhile, it’s going on two weeks that a large volumetric amplification attack has been coming from CF itself against systems I manage.

    Ironically, their abuse report does validate the domain being used to route traffic is a registered customer domain. But the abuse report and even Slack pings have yet to affect the traffic. It’s incredibly frustrating because you’d expect a company like Cloudflare, which positions itself as a defender against DDoS and similar threats, to take action much more quickly when they’re part of the problem.

  • by theideaofcoffee on 10/3/2024, 8:41:47 PM

    Enh. I try to be positive in my comments as much as I can. Whenever the subject of DDoS mitigation by cloudflare comes up, and it seems like they're always tooting their own horn, I struggle to be impressed. By their own info, they have approximately 330 global locations [0]. 3800Gbps divided roughly (remember, anycast, and if their upstreams are well mixed, they're going to see pretty consistent splitting) equally across 330 locations is 'only' ~11.5 Gbps each location. I'm guessing within each PoP is more than a handful of machines dedicated to DDoS mitigation. So sure, they're doing computation on each bit of all of that, but it still doesn't seem all that significant. Toss half a cabinet at mitigation and continue on with your day. These capabilities are available at such commodity prices nowadays it's hardly worth the effort of a full page blog post.

    And ok, I'll give some leeway in those numbers looking at the map on the linked page, 35% or so of source traffic is clustered over five countries so that distribution skews and some pops around those source countries are going to be hit harder than others. Still, maybe add an order of magnitude and I'll be a little less dismissive.

    [0] https://www.cloudflare.com/network/

  • by psd1 on 10/3/2024, 11:06:21 PM

    I worry that CF has perverse incentives

  • by cedws on 10/3/2024, 6:54:28 PM

    65 second attack? Very suspicious. This attack must have had some very specific goal.