FWIW, my guess is that attackers launching DNS reflection/amplification 
attacks against Google properties/networks are making the incorrect 
assumption that it would be more problematic for Google to block attack 
traffic sourced from recursive resolvers than from authoritatives.  
That, along with copy-catting and attacker/attack infrastructure 

Most attackers aren't very knowledgable.  The sad part is that their 
suboptimal, poorly-constructed attacks tend to succeed, anyways - not 
against organizations like Google, but against the unprepared.

