frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

DDoS Botnet Aisuru Blankets US ISPs in Record DDoS

https://krebsonsecurity.com/2025/10/ddos-botnet-aisuru-blankets-us-isps-in-record-ddos/
44•JumpCrisscross•2h ago

Comments

Groxx•1h ago
I'm honestly kinda curious why nobody's blocking these IPs from sending data near the source.

Like, I can come up with plenty of possible reasons, and reasons why it could potentially be very bad if ISPs started cracking down on this, but I don't actually know any reasons.

Are any talking about why / why not? It seems like this whole insecure-IoT-device thing would probably dry up pretty quickly if people's internet was cut off when one was detected. They can then turn around and lambast / sue / etc the company that sold it, putting pressure on the source of the problem. Right now there's no reason for sellers to do anything at all to ensure security, afaict.

So... not actually arguing in favor of it, but definitely curious about any stated ISP / core networking system's stated reasons.

bombcar•1h ago
There's no economic incentive for YOU (as the proximate ISP) to do anything about it, it would cost money, and cost you customers.

Any idea why they don't fix it?

martinald•1h ago
Of course there is. If you've got all your internet egress tied up with DDoS attacks from your network it is a big problem.
Groxx•1h ago
Yes, you generally see this kind of thing start from the pain-feelers and move up the chain to the pain-causers.

So why hasn't that happened? These are clearly damaging to many, and ISPs are apparently doing next to nothing to prevent it, and it has been extremely clear for a while now that it's going to just become a bigger and bigger problem.

Mindless2112•1h ago
> “The outbound and cross-bound DDoS attacks can be just as disruptive as the inbound stuff,” Dobbin said. “We’re now in a situation where ISPs are routinely seeing terabit-per-second plus outbound attacks from their networks that can cause operational problems.”

ISPs are starting to feel the pain, so perhaps in the near future they will do something about it.

dloy•1h ago
Perhaps, or perhaps not. Maybe if we held them accountable they would?
kibbel•1h ago
A large part of the article is dedicated to this, noting how disruptive it is to other services and customers, and listing a few countermeasures (detection and blocking at the ISP level, detection and blocking at the router level, and educating customers on not buying vulnerable IoT trash).
Groxx•1h ago
Not really? At best it's "DDOS prevention sellers are having trouble" and "ISPs say they're doing fine". The vast majority of the article is talking about the various kinds of malware causing this, and how some have been "fixed" by stopping the individuals running it (which clearly doesn't work very well, new ones just fill the void).

Or this:

>“The crying need for effective and universal outbound DDoS attack suppression is something that is really being highlighted by these recent attacks,” Dobbins continued. “A lot of network operators are learning that lesson now, and there’s going to be a period ahead where there’s some scrambling and potential disruption going on.”

Uh. No. That's gross negligence if they are only starting to think about it now - the trend has been clear for over a decade, and the IoT threat has been obvious since day 1 and even blasted over public news for the past few years. Their status is pretty much only one of: incompetent, malicious, or they have had plans but haven't acted on them fast enough or strongly enough for [some reason], and that reason isn't something I've seen. Surprises happen, prevention costs money and time, and there are plenty of reasons why everyone isn't already prepared for everything, so I think "incompetent or malicious" is pretty rare.... but what are those reasons?

MartijnBraam•57m ago
This does happen, but it seems to depend on the ISP. In the Netherlands I've seen ISPs block the internet connectivity when they've detected infected devices, sometimes they send a letter before blocking and some ISPs seem to dump your internet connection in a captive portal. In all these cases it's been enough to call the ISP after finding the problem and you're connected again minutes later.
TZubiri•32m ago
> They can then turn around and lambast / sue / etc the company that sold it, putting pressure on the source of the problem

Or just unplug the culprit. But the key seems to be that the device continues working. Ideally you would just shutdown or disconnect the device. If fridge is infected, the fridge can still fridge, but it no longer has internet privileges.

quantummagic•24m ago
Any device that participates in a DDOS needs to be recalled by the manufacturer, mandated by law. Make it potentially economically crippling to sell a vulnerable device, and security will be taken very seriously. Frivolous uses of tech, won't be worth the risk.
DaSHacka•18m ago
This just in: every computer manufacturer forced to recall every single computer model they've ever sold because some users use weak passwords.

I can't wait for all of them to switch to IOS-ified devices incapable of installing alternative operating systems or programs, as that would be the inevitable end solution for all these manufacturers if this was implemented.

martinald•59m ago
This really is a function of two things:

1) (Mainly) the huge increase in upstream capacity of residential broadband connections with FTTH. It's not uncommon for homes to have 2gbit/sec up now and certainly 1gbit/sec is fairly commonplace, which is an enormous amount of bandwidth compared to many interconnects. 10, 40 and 100gbit/sec are the most common and a handful of users can totally saturate these.

2) Many more powerful IoT devices that can handle this level of attack outbound. A $1 SoC can easily handle this these days.

3) Less importantly, CGNAT is a growing problem. If you have 10k (say) users on CGNAT that are compromised, it's likely that there's at least 1 on each CGNAT IP. This means you can't just null route compromised IPs as you are effectively null routing the entire ISP.

I think we probably need more government regulation of these IoT devices. For example, having a "hardware" limit of (say) 10mbit/sec or less for all networking unless otherwise required. 99% all of them don't need more than this.

nick32661123•28m ago
Seems more likely that residential modems will be required to use ISP-provided equipment that has government mandated chips, firmware, etc to filter outbound traffic for DDoS prevention.
DaSHacka•22m ago
Why should they be required to have hardware in their own network to filter that out when the ISP is obviously receiving all of their traffic anyway?
spatley•40m ago
Seems pretty clear that the US needs strict regulation on any device connecting to the internet.

* no default password * * no login if not on the local wifi or wired ethernet *

dehrmann•23m ago
I'd rather the industry standardizes on some sort of guest network and proxy/hub. It could even ship with hardware from ISPs. Separating the network buys you a lot of security, and running everything through a proxy makes it easier to inspect data and creates a standard hook for using abandonware.
DaSHacka•21m ago
Many manufacturers are already moving there of their own accord. I really don't think we'd need some legislation to fix this problem.

Zawinski's Law was Never About Email

https://danverbraganza.com/writings/reinterpreting-zawinskis-law
1•nvader•53s ago•0 comments

In depth analysis of database workloads and benchmarks

https://database-doctor.com/analysis/
1•b-man•1m ago•0 comments

Locate.name: AI makes your URLs unmemorable to unforgettable

https://www.locate.name/
1•singmj•3m ago•1 comments

AutoPR: Let's Automate Your Academic Promotion [pdf]

https://arxiv.org/abs/2510.09558
1•SerCe•5m ago•0 comments

South Africa's one million invisible children without birth certificates

https://www.france24.com/en/africa/20250705-south-africa-s-one-million-invisible-children-without...
3•mooreds•11m ago•0 comments

Figuring out round, floor and ceil with integer division

https://blog.pkh.me/p/36-figuring-out-round%2C-floor-and-ceil-with-integer-division.html
1•mooreds•12m ago•0 comments

The Life and Legend of Bruce Lee

https://halfcastewoman.substack.com/p/the-life-and-legend-of-bruce-lee
1•mooreds•13m ago•0 comments

Deep gashes are slicing up cities, swallowing houses and displacing people

https://www.nature.com/articles/d41586-025-02745-x
2•rguiscard•15m ago•0 comments

NVIDIA DGX Spark In-Depth Review: A New Standard for Local AI Inference

https://lmsys.org/blog/2025-10-13-nvidia-dgx-spark/
1•yvbbrjdr•17m ago•0 comments

Abstracted Social Media

https://lab.shinadayu.com/SNS/
2•nogajun•18m ago•1 comments

China port fees on U.S. ships set to kick in Tuesday

https://www.cnbc.com/2025/10/14/asia-pacific-markets-set-to-open-lower-as-new-china-port-fees-on-...
1•zerosizedweasle•18m ago•0 comments

Free online MKV to MP4 converter

https://mkvamp4.com
1•zgm13827•19m ago•1 comments

Dredging Up Fun – A Board Game Design Primer [video]

https://www.youtube.com/watch?v=Z0Vu_GeoSJo
1•yomismoaqui•20m ago•0 comments

Nanochat

https://simonwillison.net/2025/Oct/13/nanochat/
2•bilsbie•26m ago•0 comments

Hacktoberfest 2025

https://hacktoberfest.com
1•yomacatchy•31m ago•0 comments

GPU Glossary

https://modal.com/gpu-glossary
1•airstrike•32m ago•0 comments

Traffic lights with four colors and a new white light are coming

https://unionrayo.com/en/traffic-lights-color-white-autonomous-cars/
3•fcpguru•36m ago•1 comments

SpaceX Starship flight 11 successful

https://twitter.com/SpaceX/status/1977895039318864296
54•sfjailbird•45m ago•1 comments

China Stands Firm on Trade War Fronts, Targeting Minerals and U.S. Tech

https://www.caixinglobal.com/2025-10-14/trade-war-monitor-oct-13-china-stands-firm-on-trade-war-f...
2•zerosizedweasle•50m ago•0 comments

Japanese in Anime and Manga

https://anime-manga.jp/en/about_anime-manga/
1•rawgabbit•50m ago•1 comments

War on Slop

https://www.jasonthorsness.com/32
1•jasonthorsness•52m ago•0 comments

SpaceX launches Starship megarocket on 11th test flight

https://www.cnn.com/science/live-news/spacex-starship-flight-11-launch-10-13-25
41•JumpCrisscross•53m ago•29 comments

IKEA's Pencil Is the World's Most Stolen Object

https://thisthat3.substack.com/p/why-ikeas-pencil-is-the-worlds-most
1•bookofjoe•54m ago•0 comments

Requiem for a Startup (2011)

https://marksoper.me/Requiem-For-A-Startup-April-30-2011.html
1•gist•59m ago•0 comments

Troubling: AI's self-investment spree sets off bubble alarms on Wall Street

https://finance.yahoo.com/news/very-troubling-ais-self-investment-spree-sets-off-bubble-alarms-on...
2•zerosizedweasle•1h ago•1 comments

Amit Kapila: Parallel Apply of Large Transactions

http://amitkapila16.blogspot.com/2025/09/parallel-apply-of-large-transactions.html
1•PaulHoule•1h ago•0 comments

Show HN: Cinematic pep talks to help you overcome any obstacle

https://apps.apple.com/us/app/dialed-ai-motivated-in-60s/id6478706376
1•marlongrandy•1h ago•0 comments

How to Build a Solar Powered Electric Oven

https://solar.lowtechmagazine.com/2025/10/how-to-build-a-solar-powered-electric-oven/
1•louwrentius•1h ago•1 comments

'Like losing a friend': farewell to Marc Maron's pioneering podcast WTF

https://www.theguardian.com/tv-and-radio/2025/oct/13/like-losing-a-friend-farewell-to-marc-marons...
2•n1b0m•1h ago•0 comments

The Reason So Many Restaurants Taste the Same

https://www.youtube.com/watch?v=rXXQTzQXRFc
2•indigodaddy•1h ago•0 comments