Live data from Hacker News

DDoS protection

wiki.hetzner.de

61–70 of 175 posts

Re: DDoS protection

#61

Earlier quoted context omitted.

Cloudflare gets so much undeserved hate on HN. You guys do amazing work, provide an incredible service and your writeups are awesome. Thank you.

I think their work is fantastic, but I really don't like that every site I visit meets me with CF's captcha page. It's not only annoying per se, but the privacy implications are unsettling. I welcome the competition.

This was never the intention. Part of the problem is inertion - cf operates large and complex application that was designed back when we had only a handful of customers. Part of the problem is technical - the privacy-centric anti-abuse technologies don't exist yet.

Please do help us fix this. Report issues, help us understand when we have incorrect IP reputation. Help us find captcha accessibility problems. And maybe - join the team to actually code the fix.

Re: DDoS protection

#62

Can someone from the EU or DE talk about where Hetzner sits reputation-wise for those not familiar with them. Are they a solid provider?

In 4 years we had network issues Edit: be aware this is a bare metal server. You have to do everything yourself.(monitoring, raid integrity, smartd). And do not forget to request a remote KVM console(LARA), if you plan to reboot and you are not sure the kernel will boot.

Re: DDoS protection

#63

Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

Calling this "the elephant in the room" is very insightful. It surprises me that AWS is so often recommended as the best choice for new businesses without large capital. AWS automatically scalable infrastructure changes DoS outcomes from 'your server is down due to DoS', to 'your company is out of business due to DoS' (and for small company it doesn't even need to be a large DDoS, shell script on a single machine wit…

I've seen people state, in comments here and in blog posts, about DDoS attacks and also the resulting charge from Amazon - but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'. Do you have any examples of companies or individuals being help liable by Amazon for these costs? Totally prepared to accept I'm wrong, just going on my experience so far.

Re: DDoS protection

#64
post #59
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

I'd not seen the Scaleway hosting/VPS range before, so thanks for pointing to Online.net. How does OVH compare to the above two?

In some cases cheaper. Often lower setup fees. You can choose to have your setup fee split over your first 6 months.

On the other hand their support is not great. I've heard it's all PC-grade hardware rather than server-grade. They complain Canonical tried to charge them out the backside for Ubuntu licensing when in reality it'd be nothing if they'd stop using a modified, unsupported and un-maintained Ubuntu derivative.

Hit or miss really, depends what you're after and what you're personally ok with.

Re: DDoS protection

#65
post #21
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

Have you been using online.net for long? Their offer looks interesting except for availability rate 99.5%. That's almost 4 hours of downtime every month. within availability range.

Checking billing I've had my longest server there since 2014-06-02 so just over 2 years.

In that time I've had* one network issue * That I've noticed in my elsewhere-hosted monitoring.

My only complaint if I can even call it that is that the price of the server doesn't keep up with the specs they're selling - i.e. if you can get a server with resources for cheaper than my server with resources my price should come down to avoid me churning it). Having said that I don't know anywhere that actually does that and for reliability reasons it's probably better to cycle machines out when they get old enough for it to be worth the savings.

Re: DDoS protection

#66

Earlier quoted context omitted.

Cloudflare gets so much undeserved hate on HN. You guys do amazing work, provide an incredible service and your writeups are awesome. Thank you.

Yeah, but they've also the "Wifi Captive Portal" of the internet, which frequently creates trouble (if you're using Tor for example).

Tor is used for abuse. If you want the privacy* you get with Tor the price you pay is that sites and services will check that you're not one of the abusers. At least it's not a flat-out ban. Any other large network on such a small IP space (as an example maybe a NAT-using mobile ISP) would be checked just as harshly.

* Or any other reason you're using it.

Edit: If I'm wrong can you please reply explaining why? I'm having an emotional rollercoaster of up and downvotes here! Please do feel free to correct me if I'm wrong, we all need learnin'

Re: DDoS protection

#67
I always liked Hetzner and I have a few dedicated servers there. Their service was always fast and very competent. However they are not soo cheap compared to other hosters anymore.

Re: DDoS protection

#68

Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

Calling a reverse proxy company "MITM" seems kind of silly to me. It's not an attack, it's a service provider doing what their customers ask them (pay them) to do.

Re: DDoS protection

#69

Earlier quoted context omitted.

Cloudflare gets so much undeserved hate on HN. You guys do amazing work, provide an incredible service and your writeups are awesome. Thank you.

Yeah, but they've also the "Wifi Captive Portal" of the internet, which frequently creates trouble (if you're using Tor for example).

As a site operator you basically must use Cloudflare and highly aggressive policies regarding Tor.

I like Tor as a concept, the problem is that there is no way to stop people massively abusing Tor.

Whatever you want - nazi/hate speech, swatting, trolling, DDoS (by hitting expensive render paths or by forcing cache bypasses) - operate any kind of site with user interactions and you will get messed around with by mostly Tor-using scum, since trolls have understood by now that exposing their real IP will lead to them being v&d.

I don't like Cloudflare as a SPOF for half the internet, but for now they seem to be the only one able to reduce the impact of crap you have to deal with as a site op to a manageable level.

Trolls are destroying the Internet.

Re: DDoS protection

#70

Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example. It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"

Calling a reverse proxy company "MITM" seems kind of silly to me. It's not an attack, it's a service provider doing what their customers ask them (pay them) to do.

The letters stand for "man in the middle" which seems to me a quite literal description of what's going on. The word attack isn't used.
Post reply on HN