Live data from Hacker News

DDoS protection

wiki.hetzner.de

171–175 of 175 posts

Re: DDoS protection

#171
post #114
post #99

Earlier quoted context omitted.

online.net kicked us out for using too much of an unmetered network connection.

May I ask how much you used? Did they offer throttling or gave warning at least?

nope, nothing. it was something like 45 tb

Re: DDoS protection

#172
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

But whats their policy on DDoS? Since this is the topic you are posting this on just saying Hetzner "feels cheap" doesn't make that any less important.

Re: DDoS protection

#173
post #129
post #83

Earlier quoted context omitted.

Problem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.

“fundamentally flawed” is not synonymous with “not supporting the style of anonymity which I prefer”. There's no evidence supporting the assumption that those VPN exit nodes’ IP reputation is actually incorrect rather than earned by the behaviour of other customers. We went through this in the 90s where a few people were upset that they couldn't send email directly from their dialup connection, because they were stil…

I stand by my assertion — the idea that an IP address can have "reputation" is fundamentally flawed. The SMTP example that you cite is actually a good one: the whole reason why we started assigning "reputation" to IP addresses is because we could not be bothered to improve SMTP over the last 40 years or so and it still assumes we live in a world of trust.

CloudFlare (and everyone else for that matter) should stop assigning "reputation" to IP addresses. An IP address is a network location, think of it as a temporary storage box which could be occupied by anyone and anything. We should move beyond coloring boxes.

Re: DDoS protection

#174
post #23
post #18

Earlier quoted context omitted.

The internal network is a joke, it only works if you have all of your servers in one rack and you need to rent a switch to connect all of them. Online.net has a real RPN where you can add SAN storage to it etc etc. The PX line is a Fujitsu Desktop PC with a server CPU and ECC Ram. For me that's a compromise I don't really like. Also the network is a bit shitty since they don't route through DTAG (largest german carri…

If you need xx TB storage servers then you will not find any cheaper hardware + storage + network option in EU than in hetzner. I have storage servers there.

Yep, true. I use a used dedicated server for backup with FreeBSD w/ ZFS and 2 3 TB disks in mirrored ZFS. I pay 36 EUR/m for this setup. I think you must be lucky to get a similar setup for the same price from online.net.

Re: DDoS protection

#175
post #173
post #129

Earlier quoted context omitted.

“fundamentally flawed” is not synonymous with “not supporting the style of anonymity which I prefer”. There's no evidence supporting the assumption that those VPN exit nodes’ IP reputation is actually incorrect rather than earned by the behaviour of other customers. We went through this in the 90s where a few people were upset that they couldn't send email directly from their dialup connection, because they were stil…

I stand by my assertion — the idea that an IP address can have "reputation" is fundamentally flawed. The SMTP example that you cite is actually a good one: the whole reason why we started assigning "reputation" to IP addresses is because we could not be bothered to improve SMTP over the last 40 years or so and it still assumes we live in a world of trust. CloudFlare (and everyone else for that matter) should stop ass…

So what's your alternative? People use addresses because they're a strong signal with relatively low false-positives (not many people are tor/VPN users with cookie blocking). How do we do better short of deploying a login system or a unique client identifier which cannot be disabled?
Post reply on HN