NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: The massive internet attack that hardly anyone noticed

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
16 Oct, 2023 04:00 PM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

A malicious actor can do lots of damage. Photo / 123RF

A malicious actor can do lots of damage. Photo / 123RF

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

OPINION

In late August and early September this year, someone unleashed enormous distributed denial of service (DDoS) attacks which hit customers of Amazon Web Services, Microsoft and Google.

The completely new attacks are called HTTP/2 Rapid Reset and were the largest ever recorded, but we didn’t hear about them at the time, only now when the internet companies above have published details on them. What happened?

First, some background. In simple terms, a denial of service attack means making a networked server stop responding to requests. It can be a small number of malformed requests or absolutely heaps and by accident or deliberately. Add a d for distributed, and that’s attack traffic coming from lots of different places.

Imagine then if attackers find a new flaw that can be exploited more or less anonymously and safely thousands of kilometres away, and cheaply too. Interrupt government websites, take out e-commerce, prevent internet banking transactions and more.

Advertisement
Advertise with NZME.

A malicious actor can do lots of damage, like in 2020 when NZX got hit by a DDoS and went into a trading halt.

The technical explanation behind the HTTP/2 DDoS attack is very deep geek indeed. Long story short, attackers have figured out how to abuse a feature in the protocol or the language your web browser uses to communicate with internet web servers, and vice versa.

That language is the hypertext transfer protocol, major version 2, which popped up in 2015. A huge amount of web servers around the world support it.

Advertisement
Advertise with NZME.

This is a worry as everything’s on the web now.

Now, the general idea behind HTTP/2 was to make HTTP, as invented by British computer scientist Tim Berners-Lee, work harder, faster and better for streaming, applications and all the day-to-day stuff we use the web for.

Discover more

Business

Auckland Transport hit by another DDoS cyberattack: AT Mobile app and website impacted

29 Sep 05:20 AM
Business

AT restores Hop cards, responds to ransomware gang’s US$1m demand

19 Sep 12:05 AM
Business

Controversial cybersecurity shakeup will go ahead from August, Little says

25 Jul 09:15 PM
Business

‘Real chance’ Hamas-aligned groups will launch cyberattacks on NZ over next month - security firm

11 Oct 05:19 PM

HTTP/2 is based on work originally done by Google. Ironically, when the new protocol was being worked on, network geeks complained that it was unnecessarily complex which is never a good thing, and developed too quickly.

Turns out that said network geeks likely had a point, as Netflix and Google found eight denial-of-service attacks in 2019 that were a variation of the same bug, and which had to be sorted out or mitigated against.

And now there’s a novel, incredibly powerful attack that’s easy for attackers to abuse.

Who were the attackers then and why did they do it? That’s not public knowledge yet but, clearly, they know the HTTP/2 DDoS was powerful enough to level at AWS, Google and Cloudflare which all have huge network capacity.

It is also a strongly asymmetric attack that requires few resources to launch, which is a worry.

You may have heard the term botnet before: it refers to a network of compromised computers controlled by attackers.

Advertisement
Advertise with NZME.

People click on the wrong link or run software with hidden, malicious functionality and they might not even know that their computers are now hijacked and part of a botnet.

The thing is, for the HTTP/2 attacks, Cloudflare believes that a small botnet of just 20,000 machines was used. Botnets are usually several hundreds of thousands or even millions of machines strong.

The NZX was hit by a DDoS attack in 2020.
The NZX was hit by a DDoS attack in 2020.

Here we have a relatively small number of machines being able to generate an attack that was almost three times the size of the next biggest one on record. Cloudflare’s post-mortem of the attack said the flood of traffic reached 201 million requests per second.

Google said it fended off an even bigger attack that peaked above 398 million requests per second.

This compares to the entire web, which Cloudflare says comprises one to three billion requests per second.

How did we escape widespread service outages then? This time the big tech companies that host most of the web these days were correctly prepared, detected the attacks in time and neutralised the malicious traffic.

They’re now having a circle pat on the back about it, and the usual unsubtle sales spiel to businesses about buying products and services for their protection.

However, as Cloudflare noted:

“ ... it’s not inconceivable that using this method could focus an entire web’s worth of requests on a small number of targets.”

That alone guarantees more attacks in the future.

Already, Google has detected modified versions of the HTTP/2 attacks. They’re less effective than the initial one, but someone out there is adapting the technique in the hope of getting around mitigations and defences.

Meanwhile, as evidenced by HTTP/2 Rapid Reset, the tech industry is chronically unable to create secure software no matter how important its intended use is, and despite past disasters to learn from.

The vulnerability will also have to be fixed everywhere on the web, a slow and patchy process at best.

There is probably only one possible outcome from that scenario, and it’s not a good one.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Shares

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM
Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
New Zealand

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

Market close: Geopolitical tensions keep NZ market flat, US Fed decision looms

18 Jun 06:09 AM

The S&P/NZX 50 Index closed down 0.10%, falling to 12,627.32.

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
'Life-changing': International flights return to Hamilton Airport

'Life-changing': International flights return to Hamilton Airport

18 Jun 05:23 AM
Premium
Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

Liam Dann: 'Brick wall' – why tomorrow’s GDP data won’t tell the real story

18 Jun 05:17 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP