Live data from Hacker News

Network Performance Issues in multiple locations

cloudflarestatus.com

51–60 of 63 posts

Re: Network Performance Issues in multiple locations

#51
I like to think of Cloudflare like insurance. Any single website may need it rarely if ever, but if it happens to you, you have little to no recourse that doesn't involve large sums of money.

Instead, you pay Cloudflare a regular, small amount of money† to reduce the risk of having to pay a large sum of money in case you're targeted. This sounds almost exactly like insurance to me.

† Sometimes the marginal cost is actually $0!

Re: Network Performance Issues in multiple locations

#52

Obligatory comment that I (and others) make every single time: can we please for 's sake stop centralizing everything? We are literally throwing away all the benefits of a mostly-decentralized internet for the sake convenience.

Do you have a viable alternative to protecting small websites from DDOS attacks?

Freenet style distributed cache and name resolution. But that would require an Internet v3.

Re: Network Performance Issues in multiple locations

#53

Obligatory comment that I (and others) make every single time: can we please for 's sake stop centralizing everything? We are literally throwing away all the benefits of a mostly-decentralized internet for the sake convenience.

Do you have a viable alternative to protecting small websites from DDOS attacks?

You have to realize that DDoS mitigaters are in a position to not stop attacks. They get paid more money when attacks happen; so any company whose sole purpose is mitigation, has a major conflict of interest. A small site can easily be hosted on AWS, which has their own protection which is transparent. Any other cloud provider should offer it transparently anyway.

I absolutely hate people who claim Cloudflare is their only solution for mitigation/protection, because it simply isn't true, and Cloudfare does some rather shady stuff.

Re: Network Performance Issues in multiple locations

#54
post #39

Earlier quoted context omitted.

>solved "worked around" is more appropriate, and introduced huge problems with their workaround. The correct solution is to punish ISPs that permit this behavior to continue unchecked. We need offense, not defense. Any ISP that doesn't detect and kill DDoS participants needs to be severely throttled by other ISPs. Organizations like the FCC should be tackling this and levying fines against US-based ISPs for non-compl…

It's really hard to know what constitutes DDOS traffic at times. Suppose a Netflix show got really popular, do you cut it off. Let's make an exception for Netflix. What if a new competitor blahflix got popular quickly, Does its traffic get blocked? Oh wait now blahflix needs to pay $$$ to get special privileges. Shit gets hairy real quick. Suppose DDOS happens from iot devices. One of this is an important medical dev…

>It's really hard to know what constitutes DDOS traffic at times. Suppose a Netflix show got really popular, do you cut it off. Let's make an exception for Netflix. What if a new competitor blahflix got popular quickly, Does its traffic get blocked?

Well, presumably companies have arrangements with their ISPs for expected usage and such. There can be a grace period as well, when you hit up the user and say "hey, you're using a lot of bw, is all well?" You also combine this with abuse reports from the victims if a DDoS is in fact underway. I don't think it's bad for an ISP to establish trust with a customer, either, this already happens with things like DMCA requests.

>Suppose DDOS happens from iot devices. One of this is an important medical device that got hacked. Do you auto shut it down and block it's traffic. What about the life critical device under same IP through NAT that is secure also getting blocked?

Life critical devices aren't exposed to the internet. IoT users should get throttled and receive a comminication from their ISP telling them they have a malicious device on their network with advice on how to fix the problem.

Re: Network Performance Issues in multiple locations

#55
post #49
post #39

Earlier quoted context omitted.

It's really hard to know what constitutes DDOS traffic at times. Suppose a Netflix show got really popular, do you cut it off. Let's make an exception for Netflix. What if a new competitor blahflix got popular quickly, Does its traffic get blocked? Oh wait now blahflix needs to pay $$$ to get special privileges. Shit gets hairy real quick. Suppose DDOS happens from iot devices. One of this is an important medical dev…

"One of this is an important medical device that got hacked" If someone puts "an important medical device" on a network directly accessible from the internet, or on the same network as other IOT crap devices, they should be banned from ever working with computers.

Elon Musk is working on direct brain interfaces with computers. Soon, they'll be able to hack your brain!

Re: Network Performance Issues in multiple locations

#56
post #28

More general question, as similar situation has happened multiple times where we are not sure: 1) did we break our client server 2) did our internet provider die 3) did the service die What are recommended ways of finding out fast and reliably in these cases where the fault is.

Some of my experience and solution to those issues

1) UptimeRobot [0] - use to monitor various client websites. The free plan checks every 5 minutes, which should be enough. Notifications can be sent to email, slack, sms and many others. If you think there may be a problem only from some locations make a fast check with [1]. If you suspect DNS issues [2] or [3].

2) Again use UptimeRobot for monitoring device publicly accessible from your network. Moreover, if you are in control of your office network, using pfSense [4] notifications when a network gateway goes down works well (still, that works only if you have 2 or more ISPs). Or use a dedicated monitoring device/service like Zabbix.

3) Using to Twitter to Slack notification, subscribe for updates from both services that you use and major services responsible for Internet backbone. An example is, that using GitLab, comes with multiple time when the service dies (even that they are improving) - seeing the message in Slack that something is WIP currently by all team members (in a dedicated channel), helps to skip unnecessary debugging [5] :)

Not affiliate with any of the service. Still - met the UptimeRobot guys some ago - they are a small startup based in Malta, are very cool and have very stable service :)

[0] https://uptimerobot.com/

[1] http://www.super-ping.com/

[2] https://www.whatsmydns.net/

[3] https://dnschecker.org/

[4] https://doc.pfsense.org/index.php/Gateway_Settings#Gateway_S...

[5] https://twitter.com/gitlabstatus

Re: Network Performance Issues in multiple locations

#57
post #53

Earlier quoted context omitted.

Do you have a viable alternative to protecting small websites from DDOS attacks?

You have to realize that DDoS mitigaters are in a position to not stop attacks. They get paid more money when attacks happen; so any company whose sole purpose is mitigation, has a major conflict of interest. A small site can easily be hosted on AWS, which has their own protection which is transparent. Any other cloud provider should offer it transparently anyway. I absolutely hate people who claim Cloudflare is thei…

I feel like saying DDoS mitigators are in a position to not stop attacks is akin to saying car insurance companies are in a position to not stop car accidents. I think the value prop is the quality of the service WHEN the attacks happen, and when they aren't happening it is effectively an insurance-like business. However if I get DDoS'd and my mitigator does nothing, one would think they would eventually be overtaken by a more competent competitor.

Re: Network Performance Issues in multiple locations

#58

Earlier quoted context omitted.

Cloudflare has a freemium model, so maybe you should find a better comparison than Twitter.

They both have revenue, just from different sources. The comparison isn't that bad. All VC-backed approaches (and public companies) eventually hit a growth cap, when their investors are going to expect unsustainable growth.

Companies with unclear or ad-based business models, like Twitter, are more likely to end up doing sketchy things to stay in business. Of course you can find exceptions either way but I think it generally applies.

That being said, I agree that centralization sucks, and I'm thinking about symbolically moving my tiny blog off Cloudflare for this reason. The ridiculous thing is that the origin is on GitHub Pages, so I'll have to move off there as well to be coherent.

Re: Network Performance Issues in multiple locations

#59
post #57
post #53

Earlier quoted context omitted.

You have to realize that DDoS mitigaters are in a position to not stop attacks. They get paid more money when attacks happen; so any company whose sole purpose is mitigation, has a major conflict of interest. A small site can easily be hosted on AWS, which has their own protection which is transparent. Any other cloud provider should offer it transparently anyway. I absolutely hate people who claim Cloudflare is thei…

I feel like saying DDoS mitigators are in a position to not stop attacks is akin to saying car insurance companies are in a position to not stop car accidents. I think the value prop is the quality of the service WHEN the attacks happen, and when they aren't happening it is effectively an insurance-like business. However if I get DDoS'd and my mitigator does nothing, one would think they would eventually be overtaken…

Your analogy is accurate, but... If you don't have a mitigator, they have incentive to force you on one; if you are already on it, their incentive is throttling, or otherwise 'attacking' (loosely defined) your source.

With car insurance, the insurance company has incentive to mitigate their risk, (they don't want to shell out more than they need to,) charging more if you are higher risk. They don't want to take more risk than they have to. Key point, they evaluate risk on a case by case basis.

DDoS mitigators however, they already have invested in the risk by getting the hardware to handle the bandwidth. They don't care if you are attacked or not. Nothing then stops them from playing dirty. This kind of stuff frequently happened with Minecraft servers (what feels like) ages ago. Mitigating services would go out and attack servers, and competitors to get customers to switch to them.

Re: Network Performance Issues in multiple locations

#60
post #57
post #53

Earlier quoted context omitted.

You have to realize that DDoS mitigaters are in a position to not stop attacks. They get paid more money when attacks happen; so any company whose sole purpose is mitigation, has a major conflict of interest. A small site can easily be hosted on AWS, which has their own protection which is transparent. Any other cloud provider should offer it transparently anyway. I absolutely hate people who claim Cloudflare is thei…

I feel like saying DDoS mitigators are in a position to not stop attacks is akin to saying car insurance companies are in a position to not stop car accidents. I think the value prop is the quality of the service WHEN the attacks happen, and when they aren't happening it is effectively an insurance-like business. However if I get DDoS'd and my mitigator does nothing, one would think they would eventually be overtaken…

> I feel like saying DDoS mitigators are in a position to not stop attacks is akin to saying car insurance companies are in a position to not stop car accidents.

Only if there's no overcharge when an attack happens. If there is, you are in the conflict of interest situation the GP was talking about.

I don't know what is CloudFare billion policy.

Post reply on HN