5 ms·
Isn't the ISP/carrier ultimately responsible for mitigating these types of attacks? You rent a line and some IP addresses, not the garbage coming into their net
by godgod 11y ago
Isn't the ISP/carrier ultimately responsible for mitigating these types of attacks? You rent a line and some IP addresses, not the garbage coming into their network.
I'd be interested to hear how Matthew Prince at Cloudflare would mitigate these NTP/SSDP amplification attacks.
While I agree they are a juicy target for nation states, without proof that claim rings hallow. Why would the NSA/Russians/Chinese want $6000 from Protonmail when all they'd have to do is use XKEYSCORE to filter out Protonmail users and hack computers to get the secret E-mail at layer 7. Shutting down the Protonmail doesn't help a nation state at all. They WANT to know who's sending/receiving encrypted E-mail. The second wave of the attack would be as simple as targeting the last few hops to protonmail. That's not rocket science. If extortion was the goal of a nation state, we'd all be broke.
This attack smells more of a sophisticated asshole blackhat haxor with some advanced tools and a knowledge of vulnerabilities in critical internet protocols.