Live data from Hacker News

Network Performance Issues in multiple locations

cloudflarestatus.com

61–63 of 63 posts

Re: Network Performance Issues in multiple locations

#61
post #39

Earlier quoted context omitted.

>solved "worked around" is more appropriate, and introduced huge problems with their workaround. The correct solution is to punish ISPs that permit this behavior to continue unchecked. We need offense, not defense. Any ISP that doesn't detect and kill DDoS participants needs to be severely throttled by other ISPs. Organizations like the FCC should be tackling this and levying fines against US-based ISPs for non-compl…

It's really hard to know what constitutes DDOS traffic at times. Suppose a Netflix show got really popular, do you cut it off. Let's make an exception for Netflix. What if a new competitor blahflix got popular quickly, Does its traffic get blocked? Oh wait now blahflix needs to pay $$$ to get special privileges. Shit gets hairy real quick. Suppose DDOS happens from iot devices. One of this is an important medical dev…

You punish origin address forgery. That's enough.

If you are under attack and nobody is forging their origin, it's only a matter of you talking with your ISP to block the offenders.

Re: Network Performance Issues in multiple locations

#62
post #31

Earlier quoted context omitted.

Exactly. You don't solve a DDoS problem by having less capacity than your attacker and most individual companies can never afford the amount of bandwidth that is at Cloudflare's disposal. Centralization was absolutely the best answer to that problem and will be for a long time. Almost nobody but fortune 500 companies would be able to survive a DDoS otherwise.

Akamai has had and continues to have more capacity than Cloudflare.

They do, but they are considerably more expensive to the point they aren't even competing with Cloudflare.

Re: Network Performance Issues in multiple locations

#63
post #57
post #53

Earlier quoted context omitted.

You have to realize that DDoS mitigaters are in a position to not stop attacks. They get paid more money when attacks happen; so any company whose sole purpose is mitigation, has a major conflict of interest. A small site can easily be hosted on AWS, which has their own protection which is transparent. Any other cloud provider should offer it transparently anyway. I absolutely hate people who claim Cloudflare is thei…

I feel like saying DDoS mitigators are in a position to not stop attacks is akin to saying car insurance companies are in a position to not stop car accidents. I think the value prop is the quality of the service WHEN the attacks happen, and when they aren't happening it is effectively an insurance-like business. However if I get DDoS'd and my mitigator does nothing, one would think they would eventually be overtaken…

A good DDoS mitigation service can take the brunt of the attack and so you stay online. So, it's not exactly like car insurance companies unless insurance companies actually were able to put a steel wall in front of your car to prevent accidents.

But you still get attacked, but it's like a frame around you, so you don't hurt or damaged. (Here's an example of how Incapsula mitigates DDoS attacks - https://www.incapsula.com/ddos/ddos-mitigation-services.html)

Post reply on HN