Live data from Hacker News

DDoS protection

wiki.hetzner.de

11–20 of 175 posts

Re: DDoS protection

#12
Cloudflare is a major source of centralization.

The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example.

It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

Re: DDoS protection

#13
I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

Re: DDoS protection

#14

Earlier quoted context omitted.

I'm having some servers at Hetzner (beside AWS and DigitalOcean) for the last 15 years and never had 8 hours of continuous downtime, so this really astonishes and scares me. Could you point to a Hetzner post where this has happened? (so I can reevaluate if I might move to OVH).

We all know nothing.

Novelty account making pretty outrageous claims about some large service provider but can't back it up.

I'd not put too much stock in this, Hetzner isn't perfect but almost a full day of unscheduled downtime does not match my experience.

Re: DDoS protection

#15
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.

Re: DDoS protection

#16

Earlier quoted context omitted.

We all know nothing.

Novelty account making pretty outrageous claims about some large service provider but can't back it up. I'd not put too much stock in this, Hetzner isn't perfect but almost a full day of unscheduled downtime does not match my experience.

Hail jacquesm!

Re: DDoS protection

#18
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc.

The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like.

Also the network is a bit shitty since they don't route through DTAG (largest german carrier), you have to pay a premium so that they activate it for you, and that's only one thing that feels weird about Hetzner. Of course I understand the reasoning behind it, but still, why should I choose Hetzner if I can get a way better solution from Online.net?

Re: DDoS protection

#19

Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

[disclaimer: I work for CF]

CloudFlare also regularly speaks about attacks and mitigations, therefore is helping the community to build better defences. Other providers stay shy and never disclose their magic. We believe DDoS is an internet wide problem and one of the ways to solve it is to spread the mitigation know how.

Examples:

- DNS attacks https://www.youtube.com/watch?v=UcAygzNSxlI&t=2h13m20s

- Iptables is great https://www.youtube.com/watch?v=pCVTEx1ouyk

- Our DDoS mitigation pipeline https://www.youtube.com/watch?v=XiK4643YdOk

- BPF for DNS https://blog.cloudflare.com/introducing-the-bpf-tools/

- BPF for SYN https://blog.cloudflare.com/introducing-the-p0f-bpf-compiler...

- Kernel bypass with netmap https://blog.cloudflare.com/single-rx-queue-kernel-bypass-wi...

- NTP attacks https://blog.cloudflare.com/technical-details-behind-a-400gb...

- DNS amplification https://blog.cloudflare.com/deep-inside-a-dns-amplification-...

- Recent attack trends https://blog.cloudflare.com/a-winter-of-400gbps-weekend-ddos...

- L7 attack with ad networks https://blog.cloudflare.com/mobile-ad-networks-as-ddos-vecto...

Re: DDoS protection

#20
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

I'm in the UK and have used Hetzner for servers for a few years. I've found them to be extremely responsive for support and remarkably good value. (Also, not being locked in to a 6-12 month contract is great.)

But I'll check out online.net, so thanks for that ;)

Post reply on HN