Live data from Hacker News

Network Performance Issues in multiple locations

cloudflarestatus.com

41–50 of 63 posts

Re: Network Performance Issues in multiple locations

#41
post #31

Earlier quoted context omitted.

Exactly. You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal. Centralization was absolutely the best answer to that problem and will be for a long time. Almost nobody but fortune 500 companies would be able to survive a DDoS otherwise.

Akamai has had and continues to have more capacity than Cloudflare.

That doesn't matter at all. They've still got tons of capacity.

> You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal.

You can have less capacity than Akamai (many excellent providers have less) and still serve this purpose.

Re: Network Performance Issues in multiple locations

#42
post #31

Earlier quoted context omitted.

Exactly. You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal. Centralization was absolutely the best answer to that problem and will be for a long time. Almost nobody but fortune 500 companies would be able to survive a DDoS otherwise.

Akamai has had and continues to have more capacity than Cloudflare.

For CDN, yes. For DDoS mitigation, no. Before they removed the figure from their website they claimed about 1/5th the DDoS mitigation capacity as Cloudflare.

Re: Network Performance Issues in multiple locations

#43
post #31

Earlier quoted context omitted.

Exactly. You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal. Centralization was absolutely the best answer to that problem and will be for a long time. Almost nobody but fortune 500 companies would be able to survive a DDoS otherwise.

Akamai has had and continues to have more capacity than Cloudflare.

Don't know that they have more but most colos I've used are using akamai.

Re: Network Performance Issues in multiple locations

#44

Idea: let's proxy half the internet through a private, proprietary service! We can get people to give us valid SSL certificates for their sites, too, and let's fuck up Tor while we're at it. We can totally handle it, right? Oh, and we need to pay for it somehow, so let's go the venture capital approach and just pretend we won't eventually hit a growth cap and ruin our company Twitter-style when we get there. The craz…

I have a medium sized website, for 20$ a month they take 80% of the requests and bandwidth so i don't have to pay for a dedicated server and someone to run it.

I love them very much.

If they fuck up too often i can stop using them in 5 minutes, this is just perfect.

Re: Network Performance Issues in multiple locations

#45
post #31

Earlier quoted context omitted.

Exactly. You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal. Centralization was absolutely the best answer to that problem and will be for a long time. Almost nobody but fortune 500 companies would be able to survive a DDoS otherwise.

Akamai has had and continues to have more capacity than Cloudflare.

Ok but they:

1) are way more expensive than Cloudflare

2) suck at DDOS mitigation (there's a lot more to it than just bandwidth)

3) don't care much about DDOS mitigation (it is a side business from their actual business, which is edge caching)

4) drop customers who actually get hit with big DDOS attacks (see #3 above--they will always prioritize caching customers over DDOS customers)

EDIT- oh and I forgot to say that if your site is HTTPS, you will have to give Akamai your keys, just like you do with Cloudflare.

Re: Network Performance Issues in multiple locations

#46

Earlier quoted context omitted.

I love a good pitchfork and torch session as much as the next rabble-rouser, but let's remember Cloudflare got popular because they _solved*_ a hard problem: how to deal with a DDOS, as a small or medium size website. Cloudflare's essentially a for-profit insurance pool for bandwidth. No individual site has enough bandwidth to handle a DDOS, nor can afford it, but pooled together, many sites can afford a service that…

>solved "worked around" is more appropriate, and introduced huge problems with their workaround. The correct solution is to punish ISPs that permit this behavior to continue unchecked. We need offense, not defense. Any ISP that doesn't detect and kill DDoS participants needs to be severely throttled by other ISPs. Organizations like the FCC should be tackling this and levying fines against US-based ISPs for non-compl…

This is a noble ideal that will never actually fly in practice. I can protect my site against DDoS by correcting architecture issues with one small set of companies: the hosting providers that my site sits behind, and the computers and architecture that make my solution work.

You're proposing that I protect my site by rewriting the rules for internet across the entire planet and punishing every single visitor (thousands upon thousands!!) who doesn't play by some new arbitrary rules that we then have to get everyone to agree on.

No, the ISPs should not be made to correct this kind of behavior, because it will be an eternal game of cat and mouse, and we've proven that the attackers can get around said blocks quite easily. Heck, often the "attackers" are grandma and grandpa types that clicked on a bad link and didn't know any better. Instead, we're taking the right approach here: identify bad incoming traffic at the destination, and drop it before it hits the backing servers. That's a solution we can actually reasonably apply.

I don't agree with a lot of what Cloud Flare is doing, and I really wish we had more than one service like it that was as popular as they are, but they are doing good work. They're solving a huge need within the industry. I believe there should be more competition in the space, but I refuse to believe that the overall approach is inherently bad when it obviously works.

Re: Network Performance Issues in multiple locations

#47
post #3

Telia had problems hitting many service providers. Not a Cloudflare problem per se. Plenty of non-Cloudflare stuff affected like Reddit, AWS, Fastly, ... Check out the dip in requests to Reddit: http://www.redditstatus.com/

Yes, we were affected by this: https://status.fastly.com/incidents/3j0pnly3gvqb

Fastly was on top of it and routed around the issue quickly.

Re: Network Performance Issues in multiple locations

#48

Idea: let's proxy half the internet through a private, proprietary service! We can get people to give us valid SSL certificates for their sites, too, and let's fuck up Tor while we're at it. We can totally handle it, right? Oh, and we need to pay for it somehow, so let's go the venture capital approach and just pretend we won't eventually hit a growth cap and ruin our company Twitter-style when we get there. The craz…

"Make the Internet work the way it should".

Re: Network Performance Issues in multiple locations

#49
post #39

Earlier quoted context omitted.

>solved "worked around" is more appropriate, and introduced huge problems with their workaround. The correct solution is to punish ISPs that permit this behavior to continue unchecked. We need offense, not defense. Any ISP that doesn't detect and kill DDoS participants needs to be severely throttled by other ISPs. Organizations like the FCC should be tackling this and levying fines against US-based ISPs for non-compl…

It's really hard to know what constitutes DDOS traffic at times. Suppose a Netflix show got really popular, do you cut it off. Let's make an exception for Netflix. What if a new competitor blahflix got popular quickly, Does its traffic get blocked? Oh wait now blahflix needs to pay $$$ to get special privileges. Shit gets hairy real quick. Suppose DDOS happens from iot devices. One of this is an important medical dev…

"One of this is an important medical device that got hacked"

If someone puts "an important medical device" on a network directly accessible from the internet, or on the same network as other IOT crap devices, they should be banned from ever working with computers.

Re: Network Performance Issues in multiple locations

#50
post #28

More general question, as similar situation has happened multiple times where we are not sure: 1) did we break our client server 2) did our internet provider die 3) did the service die What are recommended ways of finding out fast and reliably in these cases where the fault is.

External monitoring from AWS or a colo. Simple icmp checks and tcp connects + possible up to app layer checks allowed from these failsafes. Obfuscate as needed.
Post reply on HN