Live data from Hacker News

Pastie.org host pulls hosting after DDoS attack

pastie.org

21–30 of 90 posts

Re: Pastie.org host pulls hosting after DDoS attack

#21

DDOS attacks are a fact of life, nice to know that Rails Machine will throw you under the bus when one happens. Doesn't seem to fit their homepage description: "You write Rails apps. We deploy, manage, support, monitor, and scale them. Done."

So if someone throws multiple tens of gigabits at your customer, and your upstream threatens to turn off your entire hosting company, you would respond "no way, we're going the extra mile for our customer"? Rails Machine was, in all likelihood, compelled to act to either (a) preserve its relationship with is upstream or (b) preserve its relationship with its other paying customers that do not attract DoS attacks. You…

I don't remember it being about either DDoS (if anything, I thought they went to Amazon to avoid the DDoS, seemingly somewhat successfully) or "ToS" (which to me has an implication that Amazon decided they didn't like the service, as opposed to caving under the pressure of other people not liking the service).

http://arstechnica.com/security/news/2010/12/wikileaks-kicke...

> The Wikileaks website migrated to Amazon's cloud hosting service yesterday after being hit by a distributed denial of service (DDoS) attack. Amazon decided to discontinue serving the controversial website this morning in response to pressure from critics, including prominent members of Congress. ... Senator Joe Lieberman (I-CT), chairman of the Homeland Security and Governmental Affairs Committee, was among the congressmen who pressured Amazon to stop hosting Wikileaks. He told AFP this morning that he plans to question Amazon about its relationship with Wikileaks.

Re: Pastie.org host pulls hosting after DDoS attack

#22
post #19

Earlier quoted context omitted.

So if someone throws multiple tens of gigabits at your customer, and your upstream threatens to turn off your entire hosting company, you would respond "no way, we're going the extra mile for our customer"? Rails Machine was, in all likelihood, compelled to act to either (a) preserve its relationship with is upstream or (b) preserve its relationship with its other paying customers that do not attract DoS attacks. You…

Amazon did not drop Wikileaks fearing DDOS attacks. They dropped Wikileaks fearing Lieberman.

[deleted]

Re: Pastie.org host pulls hosting after DDoS attack

#23
post #21

Earlier quoted context omitted.

So if someone throws multiple tens of gigabits at your customer, and your upstream threatens to turn off your entire hosting company, you would respond "no way, we're going the extra mile for our customer"? Rails Machine was, in all likelihood, compelled to act to either (a) preserve its relationship with is upstream or (b) preserve its relationship with its other paying customers that do not attract DoS attacks. You…

I don't remember it being about either DDoS (if anything, I thought they went to Amazon to avoid the DDoS, seemingly somewhat successfully) or "ToS" (which to me has an implication that Amazon decided they didn't like the service, as opposed to caving under the pressure of other people not liking the service). http://arstechnica.com/security/news/2010/12/wikileaks-kicke... > The Wikileaks website migrated to Amazon's…

[deleted]

Re: Pastie.org host pulls hosting after DDoS attack

#24
post #23
post #21

Earlier quoted context omitted.

I don't remember it being about either DDoS (if anything, I thought they went to Amazon to avoid the DDoS, seemingly somewhat successfully) or "ToS" (which to me has an implication that Amazon decided they didn't like the service, as opposed to caving under the pressure of other people not liking the service). http://arstechnica.com/security/news/2010/12/wikileaks-kicke... > The Wikileaks website migrated to Amazon's…

[deleted]

Well, if you want to believe that public statement (which I see maybe you don't in the second paragraph you edited in), then you also have to retract the DDoS argument, as Amazon expressly and clearly states that that is an incorrect assessment.

> There have also been reports that it was prompted by massive DDOS attacks. That too is inaccurate. There were indeed large-scale DDOS attacks, but they were successfully defended against.

Re: Pastie.org host pulls hosting after DDoS attack

#25
post #17

Perhaps an opportunity for Cloudflare to offer support?

We would love to help, and have offered.

Awesome; I hope Josh is able to get things back online. I'm curious how much support or assistance Rails Machine offered prior to pulling hosting.

Re: Pastie.org host pulls hosting after DDoS attack

#26
post #6

I can not understand these attacks. Why block a service that is free of charge, useful and did no harm? Unless of course this DDoS was not targeted, which makes even less sense to me. Also, why did Rails Machine throw out the site so quickly? If I choose to sponsor someone out of my free will, I'd do so without distinction from paying customers.

@everyone who doesn't work in hosting....

>"why did Rails Machine throw out the site so quickly?" If you run a datacenter, you pay for an uplink. That uplink has limited capacity. 4gbit, 10gbit...whatever. A big attack can saturate that link completely, so even with the biggest most expensive "mitigation device" on the market (some of this gear can get into the hundreds-of-thousands-of-dollars for /one/ device, mind you), if a DDoS is overloading your upstream bandwidth providers, you can either have your entire DC brought to a crawl, or null route the site.

With that said, how did CloudFlare keep lulzsec up? Anycast, lots of iron, lots of smart technicians, and probably tens to hundreds of thousands of dollars in bandwidth fees. TL;DR it was a publicity stunt that they very smartly played up.

DDoS is pretty misunderstood, and lots of clients think that there is some magical box that can take all the traffic. Again, if your link is saturated, a "mitigation" device can only filter the traffic; your upstream providers can and will take you offline if you don't fix it. Failing that, you get a massive overage bill and every other client at the facility is crawling. It's not really a good solution (mitigation devices /can/ help with smaller attacks, but for the big stuff, null routing is the best solution unless you have something like CloudFlare -- and even they will pull the plug if the attack gets too heavy, because it's simply not worth the expense to them to keep your site online.)

Re: Pastie.org host pulls hosting after DDoS attack

#27
post #22
post #19

Earlier quoted context omitted.

Amazon did not drop Wikileaks fearing DDOS attacks. They dropped Wikileaks fearing Lieberman.

[deleted]

>"Noteworthy: Getting attacked is against ToS at many hosts." Yes, and the action we take is largely dependent on the magnitude of the attack and how it affects /other/ clients.

Re: Pastie.org host pulls hosting after DDoS attack

#28
post #6

I can not understand these attacks. Why block a service that is free of charge, useful and did no harm? Unless of course this DDoS was not targeted, which makes even less sense to me. Also, why did Rails Machine throw out the site so quickly? If I choose to sponsor someone out of my free will, I'd do so without distinction from paying customers.

@everyone who doesn't work in hosting.... >"why did Rails Machine throw out the site so quickly?" If you run a datacenter, you pay for an uplink. That uplink has limited capacity. 4gbit, 10gbit...whatever. A big attack can saturate that link completely, so even with the biggest most expensive "mitigation device" on the market (some of this gear can get into the hundreds-of-thousands-of-dollars for /one/ device, mind…

People who haven't worked in hosting don't realize that not only is the gear $100,000+, the administrators that understand it are just as expensive. Annually. (Mitigation is a relatively rare skill for network administrators.)

Edit: Let's say you run Joe's Web Hosting. Joe's has three facilities, and you run redundant ten gigabit uplinks at each. Last I priced a device that could handle ten gigabit at line rate, it was ~$120,000, so figure:

   $120,000 x 2 uplinks x 3 facilities = $720,000
Just for the gear.

(I honestly don't remember if that figure was for the gigabit device or the ten gigabit device. I think the ten.)

Re: Pastie.org host pulls hosting after DDoS attack

#29
post #2

Sounds like an opportunity for the other managed Rails hosts.

>"Sounds like an opportunity for the other managed Rails hosts."

They can play it up, but if you throw enough bandwidth at /any/ host, they'll null route you. Other hosts (at least, the not-stupid ones who have been in this position before) know this and (hopefully) wouldn't sling mud at them over this.

Post reply on HN