Yes. But once again, that is someone with a large enough pipe. People sell DDoS mitigation but that isn't anything close to a business being able to mitigate things and caring about best practices.
A 1gig circuit is a large pipe? Also, what are you talking about? Are you claiming that NTT nor TWTC can mitigate a DDoS attack? If so, you're massively wrong.
> Also, what are you talking about? Are you claiming that NTT nor TWTC can mitigate a DDoS attack? If so, you're massively wrong.
Both are in possession of large networks which allow them to mitigate DDoS attacks.
The small business with the 1gbps pipe isn't "mitigating" the attack. Their provider is mitigating the attack in return for payment.
Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.
If you're using CloudFlare to protect your site against DDoS, you're essentially participating as part of a passive protection racket. "That's a pretty bold claim," you may reasonably contend. Here are the facts: - A very large proportion (I would conservatively estimate >50%) of DDoS-for-hire sites are hosted on CloudFlare. I couldn't find a comprehensive survey of all attack service providers, but in a recent sampl…
I don't agree at all. I think CloudFlare is almost a public utility at this point, and they should offer services to anyone and be completely blind to the content they are serving. If LEAs have a court order, then they should definitely remove them from the service but not before. This is a law enforcement problem and it should not be CloudFlare's responsibility. Banks are not generally forced to police each customer's transactions, neither should CloudFlare be forced to police their network. They are a blind intermediary and they provide an extremely valuable service.
Cloudflare is cheap, and you can easily stick Cloudflare in front of your AWS/GCS boxes.
Cloudflare is MITM. It is unacceptable for any website that respects its users' privacy.
A great deal of DDoS services are essentially MITM intermediaries. Akamai, Black Lotus and others do the same thing. Why is CloudFlare the bad guy? They have an exemplary record thus far.
By never revealing the IP address of the origin. Conceal it completely behind CF. A properly configured CF setup will mean your real server IP never gets revealed ever.
Not always possible without expensive plans. For example, if you use websockets you will need a business/enterprise level plan in order to pipe through cloudflare. Non http/https services often fail to go through cloudflare as well. For example, you're gonna have to reveal origin to use ftp/sftp.
Have a separate domain that points to your real origin IP. This is how I do it. I have company.com and companyprivate.com (obviously named so it's not so obvious they are related). Company.com points to CloudFlare and companyprivate.com points directly to the origin. Nobody knows about companyprivate.com except the people who need to.
Cloudflare is MITM. It is unacceptable for any website that respects its users' privacy.
A great deal of DDoS services are essentially MITM intermediaries. Akamai, Black Lotus and others do the same thing. Why is CloudFlare the bad guy? They have an exemplary record thus far.
The comment I replied to was about Cloudflare. But what really concerns me are the website owners who betray their users by allowing their HTTPS traffic to be MITMd, no matter if they use Cloudflare or something else. Also it is not acceptable to let one entity (be it Cloudflare or anyone else) control a significant portion of the worlds web traffic.
Dennis you left the name of the Russian DDoS site in one of your images...you may want to consider cropping this.
He explicitly states the site name in the article. No real reason to remove it imo. >ASERT keeps tabs on DDoS botnets and their attack activity with our BladeRunner botnet monitoring system and kypitest[.]ru is no exception.
Except it's not that site - https://fuc***.ru/ is where you can purchase these services.