Live data from Hacker News

Linode is suffering on-going DDoS attacks

status.linode.com

101–110 of 186 posts

Re: Linode is suffering on-going DDoS attacks

#101
post #66

Earlier quoted context omitted.

What about DigitalOcean? Its pricing is comparable to Linode's, yet DigitalOcean is now the second largest web host in the world according to Netcraft. Do you still think that AWS, Google Cloud Platform, and Microsoft Azure offer better protection?

Here's the email I received (many times) when someone sent a smallish 1Gbit/s DDoS to my digitalocean server: > Our system has automatically detected an inbound DDoS against your droplet named xyz with the following IP Address: xx.xx.xx.xx > As a precautionary measure, we have temporarily disabled network traffic to your droplet to protect our network and other customers. Once the attack subsides, networking will be…

I've received the same type of email multiple times from DigitalOcean and its extremely frustrating.

With even the smallest of traffic spikes, DigitalOcean will detect it as a DDoS and immediately cut off your server for 3 hours.

If even a typical (I've used multiple VPS providers and dedicated-server providers and DO is absolutely the worst when it comes to DDoS policy.

Re: Linode is suffering on-going DDoS attacks

#102

Earlier quoted context omitted.

Given my ignorance of much of these issues, I probably shouldn't be commenting (take my comment with a huge grain of salt). But the idea of depeering networks on the Internet for misapplication of a voluntary protocol seems like the beginning of the end of a free Internet (if ever such a thing existed). If BCP38 is critical to the success of the Internet, I think rather than ranting about those not implementing it, e…

Your heart's in the right place, but the Internet is built on policies of individual networks because there is nobody to enforce. Your suggestion back to me is simply mine in different clothing, because you think someone can enforce such a global requirement. Enforcing policy like "filter or get depeered" is the only way to achieve a global requirement like you want with the way the Internet is structured. As akerl p…

Thanks for the kid-gloves reply :)

I hadn't considered that there isn't really a central authority for controlling who runs a peer, aside from ICANN, but they have pretty loose reins.

Funny that everyone waxes poetic about bitcoin being a revolution in anonymous and tacit network management. Meanwhile our little Internet experiment continues to be a HUGE tacit agreement to adhere to a handful of network protocols.

Re: Linode is suffering on-going DDoS attacks

#103
post #59
post #18

Earlier quoted context omitted.

If the DoS is large enough there is little they can do if their downstream is 100% saturated. They would either need more capacity or for their upstream providers to filter the attack for them.

Heard of nullroutes? (Edit: how is it that perfectly valid technical solutions get downvoted?)

I would hope it is obvious based on the extent and duration of the attacks that RTBH is not an option in this case.

Re: Linode is suffering on-going DDoS attacks

#104
post #54

I would like to correlate the comments in this thread with past comments on every single article about AWS or GCE of the form "this is so expensive / complicated I run my boxes on Linode for half the price". DDoS protection is one of the things you pay for on the big clouds.

On AWS the DDoS hits the wallet instead. What’s the difference? It’s “denial of service,” not denial of server and network resources.

AWS ELBs don't forward DNS and NTP traffic to the backends, and ingress bandwidth isn't billed to you. So there's no impact on the wallet when the most common DDoS traffic is aimed at you.

Re: Linode is suffering on-going DDoS attacks

#105
post #62

Earlier quoted context omitted.

Comments from people seem to indicate their anti DDoS was "we blackhole you if you draw an attack". Has that changed?

Yes. This hasn’t been true for a long time. OVH runs a huge network and they invested in tools to mitigate and neutralize DDoS attacks[1]. Of course an attack can still saturate your servers’ NICs but they won’t drop you anymore. At their scale they are basically forced to handle big attacks on regular basis. The fact that they offer this protection in their basic package is what makes them a great host[2]. They don’…

Good to see OVH getting some recognition here. I am a happy customer of both OVH and DigitalOcean but my usage has become strongly weighted towards OVH. The OVH web interface could be improved (I've had to open support tickets for basic things like activating auto-renewal), that's the only downside with them really. Range of products, network, disk speed and responsiveness are all consistently very good. Their new 2016 'Cloud' VPSs have markedly better disk speed than DigitalOcean's SSDs, which are already pretty fast.

For a quick side project I still like DigitalOcean's hourly billing and user interface, but any machine I plan on using for a month or more are all with OVH by default.

Re: Linode is suffering on-going DDoS attacks

#106
post #76

Oh wow. I remember a couple months ago the ATL datacenter had network issues too. Really annoying, but I guess it's not their fault 100%. I wish they offered more DDoS protection solutions. I know some VPS companies specialize in that offering for things like game servers. It'd be nice if some sort of solution could just be included. I don't know if it's more of a technical issue or legal problem. As far as I know th…

OVH does VPS's and they have their own Anti-DDoS network setup that is pretty amazing: https://www.ovh.com/us/anti-ddos/

Interesting. What is "Multi-point Mitigation"? I know it mentions a few locations. I googled it and it just brings me back to that page.

I wonder if any solution would shutdown a VM and then restart it on another host but that'd be really sucky in some situations like an app might not shutdown cleanly, or the app is in the middle of something like charging a credit card.

Re: Linode is suffering on-going DDoS attacks

#107
post #91

Earlier quoted context omitted.

I don't know, but all traffic to GCE is routed through Google's frontend, which provides in-built DDoS protections.

I'd imagine they use VRF's to quickly segment the traffic after ingress. Google.com might have DDoS protection, but I'm wary that it extends to GCE. I've read about Google Andromeda, but there's no real meat in any article about DDoS mitigation.

This document specifically claims that "All traffic is routed through custom GFE (Google Front End) servers to detect and stop malicious requests and Distributed Denial of Service (DDoS) attacks."

https://cloud.google.com/security/whitepaper

Re: Linode is suffering on-going DDoS attacks

#109

I used to run a hosting company similar to Linode back in the day, and DDOS's were the most annoying thing ever. The main reason DDOS attacks exist is poor security and lack of cooperation between ISPs. Lack of adequate security on desktops (usually Windows) makes it possible to build large bot networks. Lack of cooperation between ISPs makes it very hard to track down the source of the DOS. Very often the DDOS isn't…

>> We've actually told customers to go away because their content was too DOS-prone.

Isn't that a good way to earn yourself some nasty one-star reviews? "They shut us down because of our political/religious content." That doesn't sound like a way to attract and keep loyal customers through stellar reviews and word-of-mouth advertising.

I hope there's a better way for ISPs to solve the problem than just to get rid of the customers who are the targets.

Re: Linode is suffering on-going DDoS attacks

#110
post #16
post #11

Earlier quoted context omitted.

The best thing for reliability is to use multiple companies. AWS has proved that multiple times.

Disagree. It is hard to maintain codebase and consistent infrastructure setup for multiple providers. Amazon's m3.medium != some vendor's m3.medium. Network setup and configuration are also nightmare. Speaking from experience dealing with four cloud vendors at once. It sounds great from a textbook perspective, but unless you are ready to spend millions every year to fight fire, please don't do that. If you were to us…

I think you're looking through the wrong end of the telescope, here.

We currently have ~50 servers in 8 cities, across Linode, Digital Ocean, and Vultr. It took me two weeks to craft a ~400 line script that abstracted the server creation APIs for each. Once spun up, they're each bootstrapped with a script that builds each server from scratch identically regardless of the provider (with a couple one-offs for Vultr), because they're all running the same distro.

A whole data center can go down, and there's no reason for me to get out of bed.

Post reply on HN