Live data from Hacker News

Someone attacked our company

usefathom.com

91–100 of 112 posts

Re: Someone attacked our company

#91

Earlier quoted context omitted.

I bet you could set up something way cheaper. And I'm certain you know 10x more than me regarding servers, hardening, configuration, etc. And I'm certain you enjoy servers! For us, the cost works and we have appropriate margin for it. The cost savings aren't worth the extra "we have to monitor these servers" thoughts. Our approach is 100% emotional.

Hey, in the most non-antagonistic way possible -- do you know who "cperciva" (Colin "Did you win a Putnam? Yes, I did." Percival) is? You might want to take them up on the offer, you don't get an opportunity like that everyday. Absolute legend.

Haha I didn't know who he was. But the fact Alex Debrie follows him is certification enough for me. And I was wrong. Looking at his Twitter, it looks like he knows 2000x more than me about servers.

Re: Someone attacked our company

#92

Earlier quoted context omitted.

Well, it's your money... I'd be happy to help make this more efficient though (at no charge of course). Offhand I'd say "web server which accumulates data and uploads it to S3 every N requests or M seconds" would probably get you what you need at a tiny fraction of the cost of "lambda which posts to SQS". Create an AMI and toss it at an autoscaling group and you really won't need to worry about scaling issues either.

If you were charging, how much would you charge to set up a server that you literally never have to bounce to get it back up?

That's the wrong approach -- you're going to want to be able to reboot (or replace) servers for security patches if nothing else.

But if you're regularly rebooting servers because they stop responding, something has gone very wrong.

Re: Someone attacked our company

#93

> I don’t know anybody who has signed up for this $3,000/month service from AWS… it’s called AWS Shield Advanced. The big value of this service to us is that we have access to some of the world’s best DDoS mitigation experts. In the event of an attack, we can page them, and they’ll help us mitigate the attack, creating firewall rules, identifying bad actors, and offering advice. So instead of just two of us respondin…

You're trivializing the value they provide. If mitigating large scale DDoS attacks was as simple as adding a few iptables rules they would have solved this weeks before paying AWS $3,000 a month for what is effectively an insurance policy.

The reality is that AWS has terabits of bandwidth and can mitigate these attacks upstream from your servers, which have bandwidth measured in gbps, not tbps.

So, unless you have a global network the size and scale of Amazon or Cloudfront, no, you can't just mitigate these attacks with a few firewall rules.

Re: Someone attacked our company

#94
post #26

Earlier quoted context omitted.

I would probably start by looking for third-parties to help manage to problems, at least unless they all end up at the application layer. Throw it beyond Cloudflare and talk to them, and if they're not the right fit, try someone else.

They're still going to need to process IP addresses or some kind of PII though, that's the thing :(

I see, I had misunderstood the extent to which they wanted to remain privacy-focused. Definitely can be a lot more work then when you can't outsource that stuff.

Re: Someone attacked our company

#95

Interesting that they won’t use Cloudflare due to competition in the analytics space. It makes me realize that there actually isn’t a legitimate competitor to Cloudflare and they are dominating right now.

There isn't any competition in the free-ish space, no. But there are some big-boy options: Incapsula/Imperva, DOSarrest, Akamai, SiteLock, Radware, and a few other smaller players. These are complex setups where you at minimum need to be running an AS and own your IP space and infrastructure -- you get all sorts of cool solutions like sending (router) flows to them to monitor your traffic, and when an attack is detected they'll automatically advertise your IP space for you, scrub traffic via witchcraft and GRE-tunnel your clean traffic back to you. But don't bother contacting them if you have less than four figures to spend monthly -- if you don't have at least a few cabinets of gear (if not your own DC) you're not the target market.

Cloudflare is dominating the "consumer-grade" market, but not really past that.

Re: Someone attacked our company

#96
post #78

> We will not let a lonely nerd attack our business How do they even know it was "a lonely nerd"? In fact, it's much more likely that it was carried out by a well-socialized team of shady professionals, on a commission from competitors. It's 2020, people, can we drop it with the "Hack3rs" stereotypes...?

> It's 2020, people, can we drop it with the "Hack3rs" stereotypes...?

Well, stereotype accuracy is one of the most robust and replicable findings from psychology research...

Re: Someone attacked our company

#97

Earlier quoted context omitted.

Hey, in the most non-antagonistic way possible -- do you know who "cperciva" (Colin "Did you win a Putnam? Yes, I did." Percival) is? You might want to take them up on the offer, you don't get an opportunity like that everyday. Absolute legend.

Haha I didn't know who he was. But the fact Alex Debrie follows him is certification enough for me. And I was wrong. Looking at his Twitter, it looks like he knows 2000x more than me about servers.

If you want more blog posts for Hacker News, take him up on the offer and then blog about it: "Cperciva replaced our millions of Lambda invocations with one m6g.medium and now I'm stuck as a FreeBSD admin!"

Re: Someone attacked our company

#98

Earlier quoted context omitted.

While more likely (why would a random nerd would have such a beef with them?), stating that without actual evidence is borderline conspiracy theory. I wouldn't have mentioned the hypothetical lone nerd at all, but I figure he was so angry he had to picture someone to be angry at.

If it's more likely then why can't it be used as the starting point? What's the conspiracy theory?

Evil competitor hired shady cybercriminals to put him out of business. It's the most likely explanation, but it looks weird if stated without actual evidence.

Re: Someone attacked our company

#99
post #61

One simple way to stop a lot of shenanigans such as this is to block Tor exit nodes from connecting to your services. https://blog.torproject.org/changes-tor-exit-list-service While some attackers have access to compromised home routers and IoT devices, most script kiddies do not, so they use Tor (because they don't want to get caught).

This is rubbish advice when talking about attacks as large as this.

Re: Someone attacked our company

#100

> I don’t know anybody who has signed up for this $3,000/month service from AWS… it’s called AWS Shield Advanced. The big value of this service to us is that we have access to some of the world’s best DDoS mitigation experts. In the event of an attack, we can page them, and they’ll help us mitigate the attack, creating firewall rules, identifying bad actors, and offering advice. So instead of just two of us respondin…

If someone is going to throw 10gbit ddos at your home ip - how few firewall rules are going to help?

I am not very well versed in ddos, but that's just traffic generated from thousands of bots. Its still takes bandwidth and will literally overload your link.

I assume AWS has multiple upstream links where the traffic is coming via multiple links and its easier for them to handle than for someone with one or few upstream links.

Post reply on HN