Hacker News new | ask | show | jobs
by rast-a 3820 days ago
Out of curiosity: why is it so hard to track the real origin of DDoS attack, who's behind them and what they are after?
2 comments

Imagine the scenario: person A sends a malformed DNS request to a bunch of DNS resolvers, asking them to send the response to person B. Now imagine that person A is actually part of a large botnet, being controlled by person C, via some smoke-and-mirrors.

If you're person B (under attack) it's pretty difficult to track through all of that to person C. You'd need a lot of cooperation from people (likely in many different countries) who really just want to go back to their normal business. They're likely also charging for the traffic, so they're not really that bothered, and they're each only seeing a small proportion of what person B is seeing so they don't see it as much of a problem (so aren't likely to be inclined to get involved).

I'm willing to bet it's someone with money who has an interest in making Linode look bad or unreliable. I can't imagine someone would sustain an attack like this for shits and giggles.