Live data from Hacker News

Someone attacked our company

usefathom.com

81–90 of 112 posts

Re: Someone attacked our company

#81
post #50

PHP Laravel on Amazon Lambda to count pageviews? Are you sure it's not just a regular customer and not a DDOS? > privacy-first analytics solution [...] The only downside of this is that we need to keep access logs (IP & User-Agent, no browsing history) for 24 hours Keeping IPs don't make you super privacy friendly.

> Are you sure it's not just a regular customer and not a DDOS? Please be respectful of OP, he put a few weeks working on the issue, it is not fair to tell him that you think everything he tells is shit, only because you don't believe what he says

You have to consider OP might have been misled by the Amazon Sales team to buy their $3k per month DDoS protection.

Re: Someone attacked our company

#82
post #79

I feel you, it is horrendous seeing your work being torn up like that. Having anything public-facing on the internet feels like running a liqueur store in a bad neighbourhood. I am the co-founder of a SaaS in the higher-ed-tech sector (universities, 300+ of them). Going to make sure we implement support for Fathom (in addition to GA, GTM, Matomo) and reach out to our customers. Hope it helps a bit. Our users would al…

That sounds incredible. We’re used in a lot of universities right now and it would be great to see more

Re: Someone attacked our company

#83

Earlier quoted context omitted.

Well, it's your money... I'd be happy to help make this more efficient though (at no charge of course). Offhand I'd say "web server which accumulates data and uploads it to S3 every N requests or M seconds" would probably get you what you need at a tiny fraction of the cost of "lambda which posts to SQS". Create an AMI and toss it at an autoscaling group and you really won't need to worry about scaling issues either.

I bet you could set up something way cheaper. And I'm certain you know 10x more than me regarding servers, hardening, configuration, etc. And I'm certain you enjoy servers! For us, the cost works and we have appropriate margin for it. The cost savings aren't worth the extra "we have to monitor these servers" thoughts. Our approach is 100% emotional.

Hey, in the most non-antagonistic way possible -- do you know who "cperciva" (Colin "Did you win a Putnam? Yes, I did." Percival) is?

You might want to take them up on the offer, you don't get an opportunity like that everyday.

Absolute legend.

Re: Someone attacked our company

#85
post #50

Earlier quoted context omitted.

> Are you sure it's not just a regular customer and not a DDOS? Please be respectful of OP, he put a few weeks working on the issue, it is not fair to tell him that you think everything he tells is shit, only because you don't believe what he says

You have to consider OP might have been misled by the Amazon Sales team to buy their $3k per month DDoS protection.

Never expected to see someone defending me on Hacker News. I appreciate it. To clear things up:

* I found AWS Shield Advanced organically

* It was a DDoS attack

* I am incredibly happy with the personalized service. It’s like hiring someone to handle it, except you have people on call 24x7

Re: Someone attacked our company

#86
post #78

> We will not let a lonely nerd attack our business How do they even know it was "a lonely nerd"? In fact, it's much more likely that it was carried out by a well-socialized team of shady professionals, on a commission from competitors. It's 2020, people, can we drop it with the "Hack3rs" stereotypes...?

While more likely (why would a random nerd would have such a beef with them?), stating that without actual evidence is borderline conspiracy theory. I wouldn't have mentioned the hypothetical lone nerd at all, but I figure he was so angry he had to picture someone to be angry at.

Re: Someone attacked our company

#87
> I don’t know anybody who has signed up for this $3,000/month service from AWS… it’s called AWS Shield Advanced. The big value of this service to us is that we have access to some of the world’s best DDoS mitigation experts. In the event of an attack, we can page them, and they’ll help us mitigate the attack, creating firewall rules, identifying bad actors, and offering advice. So instead of just two of us responding to DDoS attacks, we have genius engineers we can speak with, and that feels good.

Just amazed at the amount of money and time that people are willing to give AWS so that they don't manage dedicated servers themselves, I mean, paying $36k/year just to have someone manage firewall rules that's plain laughable... not to mention this is happening on "hacker news".

> They're competitors of ours and it's just not a good fit.

I sincerely hope that AWS doesn't start an analytics product and become a "competitor" because that sounds like you're going to have to rewrite all your software outside of AWS, and it sure seems extremely locked in ...

Re: Someone attacked our company

#88
post #78

> We will not let a lonely nerd attack our business How do they even know it was "a lonely nerd"? In fact, it's much more likely that it was carried out by a well-socialized team of shady professionals, on a commission from competitors. It's 2020, people, can we drop it with the "Hack3rs" stereotypes...?

While more likely (why would a random nerd would have such a beef with them?), stating that without actual evidence is borderline conspiracy theory. I wouldn't have mentioned the hypothetical lone nerd at all, but I figure he was so angry he had to picture someone to be angry at.

I’d have been happy with some generic “shady characters”. It just feels lazy (and bigoted) in 2020 to use this sort of negative stereotype, particularly when coming from someone in the business. One cannot deal with a threat effectively if one mis-identifies the actual profile and capabilities of such threat.

Re: Someone attacked our company

#89

Earlier quoted context omitted.

I bet you could set up something way cheaper. And I'm certain you know 10x more than me regarding servers, hardening, configuration, etc. And I'm certain you enjoy servers! For us, the cost works and we have appropriate margin for it. The cost savings aren't worth the extra "we have to monitor these servers" thoughts. Our approach is 100% emotional.

Hey, in the most non-antagonistic way possible -- do you know who "cperciva" (Colin "Did you win a Putnam? Yes, I did." Percival) is? You might want to take them up on the offer, you don't get an opportunity like that everyday. Absolute legend.

"AWS Hero" is probably more relevant than "Putnam Fellow" here. ;-)

But seriously, it's clear making this more efficient isn't a priority for them, and I completely understand and respect that. I ignore plenty of good advice for the same reason: "Working on more important stuff in Tarsnap right now".

Re: Someone attacked our company

#90
post #78

> We will not let a lonely nerd attack our business How do they even know it was "a lonely nerd"? In fact, it's much more likely that it was carried out by a well-socialized team of shady professionals, on a commission from competitors. It's 2020, people, can we drop it with the "Hack3rs" stereotypes...?

While more likely (why would a random nerd would have such a beef with them?), stating that without actual evidence is borderline conspiracy theory. I wouldn't have mentioned the hypothetical lone nerd at all, but I figure he was so angry he had to picture someone to be angry at.

If it's more likely then why can't it be used as the starting point? What's the conspiracy theory?
Post reply on HN