DDoS protection
11–20 of 175 posts
Re: DDoS protection
#12The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example.
It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"
Re: DDoS protection
#13Re: DDoS protection
#14Earlier quoted context omitted.
I'm having some servers at Hetzner (beside AWS and DigitalOcean) for the last 15 years and never had 8 hours of continuous downtime, so this really astonishes and scares me. Could you point to a Hetzner post where this has happened? (so I can reevaluate if I might move to OVH).
We all know nothing.
I'd not put too much stock in this, Hetzner isn't perfect but almost a full day of unscheduled downtime does not match my experience.
Re: DDoS protection
#15I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.
Re: DDoS protection
#16Earlier quoted context omitted.
We all know nothing.
Novelty account making pretty outrageous claims about some large service provider but can't back it up. I'd not put too much stock in this, Hetzner isn't perfect but almost a full day of unscheduled downtime does not match my experience.
Re: DDoS protection
#17Re: DDoS protection
#18I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.
You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.
The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like.
Also the network is a bit shitty since they don't route through DTAG (largest german carrier), you have to pay a premium so that they activate it for you, and that's only one thing that feels weird about Hetzner. Of course I understand the reasoning behind it, but still, why should I choose Hetzner if I can get a way better solution from Online.net?
Re: DDoS protection
#19Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"
CloudFlare also regularly speaks about attacks and mitigations, therefore is helping the community to build better defences. Other providers stay shy and never disclose their magic. We believe DDoS is an internet wide problem and one of the ways to solve it is to spread the mitigation know how.
Examples:
- DNS attacks https://www.youtube.com/watch?v=UcAygzNSxlI&t=2h13m20s
- Iptables is great https://www.youtube.com/watch?v=pCVTEx1ouyk
- Our DDoS mitigation pipeline https://www.youtube.com/watch?v=XiK4643YdOk
- BPF for DNS https://blog.cloudflare.com/introducing-the-bpf-tools/
- BPF for SYN https://blog.cloudflare.com/introducing-the-p0f-bpf-compiler...
- Kernel bypass with netmap https://blog.cloudflare.com/single-rx-queue-kernel-bypass-wi...
- NTP attacks https://blog.cloudflare.com/technical-details-behind-a-400gb...
- DNS amplification https://blog.cloudflare.com/deep-inside-a-dns-amplification-...
- Recent attack trends https://blog.cloudflare.com/a-winter-of-400gbps-weekend-ddos...
- L7 attack with ad networks https://blog.cloudflare.com/mobile-ad-networks-as-ddos-vecto...
Re: DDoS protection
#20I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.
But I'll check out online.net, so thanks for that ;)