Live data from Hacker News

DDoS protection

wiki.hetzner.de

121–130 of 175 posts

Re: DDoS protection

#121

Earlier quoted context omitted.

that's a pretty poor excuse. why is privacy only available by submitting to a poor experience? privacy should be default, not a punishment

You're looking at it purely from the user side. Look at it from the admin side. Tor is basically a massive open proxy, and by blocking it or throwing up human checks like captchas, you eliminate a significant source of spam and abuse. There's not much to be done about this otherwise - a Tor user is sharing a network with a significantly higher than usual amount of the bad elements of the internet.

You can put captchas where they belong—on comments etc. Instead, Cloudflare punishes people simply browsing; they nuke the 99.99999% of visitors that have zero intention of interacting with the page beyond doing few GETs.

Oh and don’t forget they’ll even put the captchas on subdomains, like img.domain.tld. Go visit stackoverflow via VPN/TOR and watch how the site has no styling/images even if you do their stupid captcha on stackoverflow.com. They’ll still serve you another one on static{1-50}.stackoverflow.com. Fun.

Re: DDoS protection

#122
post #83

Earlier quoted context omitted.

Problem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.

Keep in mind, unless you're using your own personal VPN off a self-hosted machine, you're likely to be sharing your IP address with other (potentially) malicious actors trying to hide their tracks

Same as if being on an ISP though.

Re: DDoS protection

#123
That's a great move by Hetzner. Glad to see that OVH is not the only main player doing it anymore.

The only issue with both is that they don't handle l7 DDoS, which seems to be getting more common. I also don't like that they leverage TCP rst's for syn floods, but I guess thats better than going down.

But so far, for l7 attacks you still need ddos mitigation strategies or something like CloudFlare.com or https://sucuri.net in front of your site.

thanks,

Re: DDoS protection

#124
I'd have to say that webtropia.com or even myloc.de great service great value myloc has some real nice bells and whistles. webtropia has great vps and the dedi servers too. I'm at 2 locations east side USA and Deutschland. Check it out, I'm happy.

Re: DDoS protection

#125
post #123

That's a great move by Hetzner. Glad to see that OVH is not the only main player doing it anymore. The only issue with both is that they don't handle l7 DDoS, which seems to be getting more common. I also don't like that they leverage TCP rst's for syn floods, but I guess thats better than going down. But so far, for l7 attacks you still need ddos mitigation strategies or something like CloudFlare.com or https://sucu…

It seems you’re affiliated with Sucuri, I wonder why you don’t include that in your profile?

Re: DDoS protection

#126
post #91

What always strikes me is the amount of free traffic Hetzner includes in their plans, always 20TB and upwards. AWS charges a whooping 90$ per TB, it keeps me wondering why their traffic is SO much more expensive than Hetzner's...

Simple, Hetzner directly buys at transit wholesale prices.

Re: DDoS protection

#127
post #123

That's a great move by Hetzner. Glad to see that OVH is not the only main player doing it anymore. The only issue with both is that they don't handle l7 DDoS, which seems to be getting more common. I also don't like that they leverage TCP rst's for syn floods, but I guess thats better than going down. But so far, for l7 attacks you still need ddos mitigation strategies or something like CloudFlare.com or https://sucu…

It seems you’re affiliated with Sucuri, I wonder why you don’t include that in your profile?

Just giving credit to the little ones who work hard. I'm affiliated with them as a happy customer, but online.net and ovh are also good.

Re: DDoS protection

#128
post #121

Earlier quoted context omitted.

You're looking at it purely from the user side. Look at it from the admin side. Tor is basically a massive open proxy, and by blocking it or throwing up human checks like captchas, you eliminate a significant source of spam and abuse. There's not much to be done about this otherwise - a Tor user is sharing a network with a significantly higher than usual amount of the bad elements of the internet.

You can put captchas where they belong—on comments etc. Instead, Cloudflare punishes people simply browsing; they nuke the 99.99999% of visitors that have zero intention of interacting with the page beyond doing few GETs. Oh and don’t forget they’ll even put the captchas on subdomains, like img.domain.tld. Go visit stackoverflow via VPN/TOR and watch how the site has no styling/images even if you do their stupid capt…

A few GETs spread out the right way and repeated often enough is a DDOS.

There's a very good reason why Cloudflare does this. Cloudflare isn't "punishing" anybody, their job is to protect the people that use their service. Tor (or any other open proxy) is a massive source of bogus and/or abusive traffic.

Re: DDoS protection

#129
post #83
post #61

Earlier quoted context omitted.

This was never the intention. Part of the problem is inertion - cf operates large and complex application that was designed back when we had only a handful of customers. Part of the problem is technical - the privacy-centric anti-abuse technologies don't exist yet. Please do help us fix this. Report issues, help us understand when we have incorrect IP reputation. Help us find captcha accessibility problems. And maybe…

Problem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.

“fundamentally flawed” is not synonymous with “not supporting the style of anonymity which I prefer”. There's no evidence supporting the assumption that those VPN exit nodes’ IP reputation is actually incorrect rather than earned by the behaviour of other customers.

We went through this in the 90s where a few people were upset that they couldn't send email directly from their dialup connection, because they were still thinking of the world as it was in 1993 before spam became so prevalent and anyone who ran a mail server was constantly trying to deal with thousands of dialup IPs trying to deliver spam. What actually worked was that people changed the way they worked to use things like authenticated SMTP relays so you could simply block entire dialup ranges rather than try to come up with a spam-blocking AI.

The browsing system could be improved by something like a CloudFlare login system or long-term persistent authentication storage so you'd only see a CAPTCHA once a week. Unfortunately, most of the complaints come from very pro-anonymity users – which is a legitimate position but also means that it's a community which is going to be significantly more likely than average to have things like cookie & JavaScript blocking, so the complaints would simply shift to “I shouldn't have to create an account!” or “Why can't I disable JavaScript and cookies for your site!?!”

Re: DDoS protection

#130
post #123

That's a great move by Hetzner. Glad to see that OVH is not the only main player doing it anymore. The only issue with both is that they don't handle l7 DDoS, which seems to be getting more common. I also don't like that they leverage TCP rst's for syn floods, but I guess thats better than going down. But so far, for l7 attacks you still need ddos mitigation strategies or something like CloudFlare.com or https://sucu…

It seems you’re affiliated with Sucuri, I wonder why you don’t include that in your profile?

Because I am not. Just like their service and use it along with CloudFlare (which I always recommend).
Post reply on HN