Live data from Hacker News

DDoS protection

wiki.hetzner.de

71–80 of 175 posts

Re: DDoS protection

#71
post #63

Earlier quoted context omitted.

Calling this "the elephant in the room" is very insightful. It surprises me that AWS is so often recommended as the best choice for new businesses without large capital. AWS automatically scalable infrastructure changes DoS outcomes from 'your server is down due to DoS', to 'your company is out of business due to DoS' (and for small company it doesn't even need to be a large DDoS, shell script on a single machine wit…

I've seen people state, in comments here and in blog posts, about DDoS attacks and also the resulting charge from Amazon - but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'. Do you have any examples of companies or individuals being help liable by Amazon for these costs? Totally prepared to accept I'm wrong, just going on my experience so far.

Unless there is a contractual guarantee somewhere, that's not something I like to bet my company on.

Re: DDoS protection

#72
post #18

Earlier quoted context omitted.

You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc. The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like. Also the network is a bit shitty since they don't route through DTAG (largest german carri…

> Also the network is a bit shitty since they don't route through DTAG (largest german carrier)

Because DTAG is a bunch of . What they did and continue to do to site/net ops, is amounting to extortion. It's good that Hetzner stands up to Telekom, lots of other net ops simply pay the extortion fee.

Re: DDoS protection

#73
We are switching away from hetzner managed server as we had ~30 hours of downtime this sunday. They suddenly swapped our valid ssl certificate with a self signed one. They offered no immediate support (i called them three times) and open tickets were left unanswered for another ~20 hours. As i ranted about their customer service on twitter, they finally took care of it. So please stay away from them.

Re: DDoS protection

#74
post #70

Earlier quoted context omitted.

Calling a reverse proxy company "MITM" seems kind of silly to me. It's not an attack, it's a service provider doing what their customers ask them (pay them) to do.

The letters stand for "man in the middle" which seems to me a quite literal description of what's going on. The word attack isn't used.

I know what it stands for and it is the name of an attack. Try Googling "man in the middle" and see what all the results say. It is not a neutral term.

When a service provider decrypts and filters traffic for you, it's usually just called decrypting and filtering traffic.

Re: DDoS protection

#75

Earlier quoted context omitted.

Yeah, but they've also the "Wifi Captive Portal" of the internet, which frequently creates trouble (if you're using Tor for example).

As a site operator you basically must use Cloudflare and highly aggressive policies regarding Tor. I like Tor as a concept, the problem is that there is no way to stop people massively abusing Tor. Whatever you want - nazi/hate speech, swatting, trolling, DDoS (by hitting expensive render paths or by forcing cache bypasses) - operate any kind of site with user interactions and you will get messed around with by mostl…

As a site operator, I have Tor (T1) whitelisted on all of my CloudFlare websites and have no additional spam problems or anything else. CloudFlare doesn't even catch all of my malicious traffic (spammers, mostly) -- even StopForumSpam doesn't do a 100% perfect job.

Re: DDoS protection

#76
post #70

Earlier quoted context omitted.

Calling a reverse proxy company "MITM" seems kind of silly to me. It's not an attack, it's a service provider doing what their customers ask them (pay them) to do.

The letters stand for "man in the middle" which seems to me a quite literal description of what's going on. The word attack isn't used.

Except MiTM is used primarily, if not exclusively, in attack scenarios. Otherwise any third-party you use as a website owner is a MiTM.

Re: DDoS protection

#77
Free? How about mandatory? I hate blackboxes in my communication channel that decide which communication is acceptable and which isn't. Plus all the security vulnerabilities and other bugs that the complexity of such systems probably brings with it, making it harder and harder to debug network problems.

And all that is especially true in the case of Hetzner, who have repeatedly demonstrated how to build hilariously broken networks. Even ignoring that they were vulnerable to ARP spoofing for a long time and other things that have since been fixed, just some blunders of their current offerings: virtual servers behind v4 NAT (yes, you can't make that shit up ...) and IPv6 assignments of a single /64, even for dedicated machines (with an option to extend it to a /56 for money). So, if their new blackbox screws something up, what are the chances that they will care?

Re: DDoS protection

#78
post #63

Earlier quoted context omitted.

Calling this "the elephant in the room" is very insightful. It surprises me that AWS is so often recommended as the best choice for new businesses without large capital. AWS automatically scalable infrastructure changes DoS outcomes from 'your server is down due to DoS', to 'your company is out of business due to DoS' (and for small company it doesn't even need to be a large DDoS, shell script on a single machine wit…

I've seen people state, in comments here and in blog posts, about DDoS attacks and also the resulting charge from Amazon - but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'. Do you have any examples of companies or individuals being help liable by Amazon for these costs? Totally prepared to accept I'm wrong, just going on my experience so far.

> but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'.

Negotiating the bill afterwards is an experience most people want to avoid, I think. I guess many would prefer a service where they don't receive the huge bill to begin with, even with other downsides.

Re: DDoS protection

#79

Can someone from the EU or DE talk about where Hetzner sits reputation-wise for those not familiar with them. Are they a solid provider?

Hetzner mostly targets the low-end customer market, so they are pretty good if you want to optimize for cost.

Re: DDoS protection

#80

PEARLS ==> SWINE

I'm having some servers at Hetzner (beside AWS and DigitalOcean) for the last 15 years and never had 8 hours of continuous downtime, so this really astonishes and scares me. Could you point to a Hetzner post where this has happened? (so I can reevaluate if I might move to OVH).

For the record, I've had significant problems with network connectivity being constant at OVH's BHS datacenter. Even when presented with evidence that they're having downtime issues (repeated customer mentions on Twitter, New Relic reports, etc.), OVH refused to honor their SLA or even acknowledge the problem. I had a week with 96% uptime because of their network link problems.
Post reply on HN