Live data from Hacker News

DDoS Protection

docs.digitalocean.com

51–56 of 56 posts

Re: DDoS Protection

#51
post #15

Earlier quoted context omitted.

Don’t get DDoS’d or use a provider that has built-in DDoS protection. Depending on what you’re using it for you could “cloak” it.

What if the situation is the provider doesn't have built-in DDos protection ?

Depends what you are protecting. A website or http traffic? Stick it behind cloudflare. Services on other ports or protocols like TCP or UDP? You could rent a cheap VPS at a provider that DOES have inline protection and use that instance to reroute traffic to your own server via a GRE tunnel.

Re: DDoS Protection

#52
Very vague. Doesn’t specify if it is in-line or offload. Linode, with some research you can figure out they use Corero appliances that will cover 40 gbps floods.

Also didn’t see what their policy on tweaks are and or expectation on mitigating a more advanced attack.

I.e. DNS, NTP floods are low hanging fruit but it doesn’t take much nowadays to do something more custom.

Re: DDoS Protection

#53
post #12
post #6

At the risk of sounding like the "why do you need DropBox if you have rsync herr derr" guy, why... do I need DDoS protection from my VPS provider if I have Cloudflare anyway?

What if you want to run a service that can't go behind Cloudflare (such as a game server)?

You rent with a provider that uses Magic Transit by CF, Corero appliances, OVH, Psychz, or Path networks.

Re: DDoS Protection

#54

Earlier quoted context omitted.

> I can safely say it's a terrible option. Can you elaborate?

Compared to other mitigation providers there were very few filters, and when you were under attack it just seemed to throttle your whole connection to as low as 50Kbps, meaning players would disconnect.

Magic Firewall exists now which is pretty powerful a la wire shark filters if I remember correctly. Otherwise MT filters are pretty good now. However I have encountered a few cases where a valid connection may drop depending on how sensitive your application is but pretty rare.

Re: DDoS Protection

#55

I have some cheap(east) VPS with OVH that I didn't even know had DDoS protection until I got the emails that my host was temporarily migrated to mitigation infrastructure during a DDoS, and back a few minutes later. Was pretty impressed especially since I don't pay extra for it or even know I had it!

it benefits them, since DDoS will take down not just your VPS, but more infrastructure along the way. there are probably downsides as well, like blocking crawlers from search engines

Re: DDoS Protection

#56

Earlier quoted context omitted.

They gotta get more money from all the scammers they host somehow.

I partially wanted to LOL this. Realized that's not a thing for HN. Thought that this will likely be downvoted because HN. Then I thought, what a great way to tax the spammers / hackers that use DO! I would gladly pay the $5 ddos fee to hammer the ips that keep trying to login to my wordpress sites. just kidding, I would not actually do that.. but the thought is pleasant. I've used DO many times and I am a fan btw -…

not sure if I was clear enough for the downvoters to get it, ddos the ips and have DO charge the spammers / hackers a fee is the point..

Not that I advocate for ddos - I think it's a terrible thing, and I've been through it a few times.

DO and OVH are my most blocked ip blocks on several servers. I also get some hetzner and aws and microsoft blocks a lot among others sure.

Interesting that I just launched a brand new WP on a brand new domain, and in less than 24 hours half of the hack attempts are from DO ips.

You could lecture me about reporting and blah blah. I've been down those roads spending literal months doing that. With DO's cheap boxes and rotating IPs it's not worth it, I just block the entire CIDR every time, today it's 157.245.0.0/16 and 174.138.0.0/17

If DO was serious about stopping these abuses they would offer a WP plugin or opt-in setting that could check data from wordfence and similar and easily see which of their boxes are being used to hack into sites, all this could be automatic, without the form filling and delays that are required.

Post reply on HN