Live data from Hacker News

DEF CON 32 Was Canceled. We Un-Canceled it

forum.defcon.org

41–50 of 408 posts

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#42

I find it hilarious that defcon.org can't handle the traffic from being on HN.

Without robust and easily scaled infrastructure in place ahead of time, an organic DDOS is one of the most difficult situations to mitigate. Not much can be done in terms of traffic shaping, rate limiting, or bot detection.

I agree. Protecting against DDoS attacks is incredibly difficult. I'm just enjoying the irony of Def Con, the premiere computer security and hacking convention, not being able to handle traffic.

To be fair, I don't think they crashed; I saw a "sorry too much traffic try later" type message. Still amuses me.

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#43

I find it hilarious that defcon.org can't handle the traffic from being on HN.

Without robust and easily scaled infrastructure in place ahead of time, an organic DDOS is one of the most difficult situations to mitigate. Not much can be done in terms of traffic shaping, rate limiting, or bot detection.

the current way to most effectively get around DDoS seems to be using a proof-of-work based frontend run on as many revolving reverse proxies around the world as you can afford. this is what kiwifarms does. seems pretty effective and a lot cheaper than what the people bankrolling the attacks on them are spending.

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#45

I find it hilarious that defcon.org can't handle the traffic from being on HN.

Without robust and easily scaled infrastructure in place ahead of time, an organic DDOS is one of the most difficult situations to mitigate. Not much can be done in terms of traffic shaping, rate limiting, or bot detection.

Of course, a robust and easily-scaled infrastructure is pretty easy to rent these days...

... if you're willing to trust another company with your data.

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#47

I find it hilarious that defcon.org can't handle the traffic from being on HN.

Without robust and easily scaled infrastructure in place ahead of time, an organic DDOS is one of the most difficult situations to mitigate. Not much can be done in terms of traffic shaping, rate limiting, or bot detection.

An HN front page “DDoS” is like 20K hits. This isn't some complex scaling challenge. Any website on the internet should be able to handle it, especially a purely informational one.

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#48
post #37
post #33

Earlier quoted context omitted.

There are certainly a lot of DefCon attendees who think that this describes them. In my observation they are all very incorrect, usually humorously so fortunately.

My first thought was that GP was saying DefCon attendees would be counting cards, which is an effective and legal way to beat the house[1] (until you're caught and banned from the casino). 1. https://www.freep.com/story/entertainment/nightlife/2016/04/...

Casinos in Vegas use too many decks and reshuffle frequently enough that there is no edge gained over the house when card counting.

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#49

Hypothesis : Result of last years bomb-scare and evacuation?

Or Caesar's being hacked last year and a belief (right/wrong/indifferent) that they don’t want to be hosting the kind of folks who could do that.

https://www.securityweek.com/caesars-confirms-ransomware-hac...

Re: DEF CON 32 Was Canceled. We Un-Canceled it

#50

Earlier quoted context omitted.

Doubtful, I'm sure it's related to the constant attacks against their infrastructure they must defend against (let's be honest, I'm sure Caesars is not defending successfully). The juice just ain't worth the squeeze. They have a business to run, and the risk of having a bunch of drunken and high hackers who happen to be the best in the world running amuck is not their idea of a good corporate event.

Caesar's apparently explicitly said it wasn't related to anything the community did. It's possible that they're lying for some reason, but it's also possible that they're telling the truth. > We don’t know why Caesars canceled us, they won’t say beyond it being a strategy change and it is not related to anything that DEF CON or our community has done. https://www.reddit.com/r/Defcon/comments/1aj6ixn/def_con_was...

> for some reason

To avoid any legal liability. Stating a specific reason would open them to possible "breach of contract" depending on whether the act(s) were significant enough or justifiable, based on the contract terms. Just say nothing, part amicably, everyone moves on without drama.

With that said, they probably weren't lying. Most likely, months after ponying up $10 million to a sophisticated international hacking group, Caesars Entertainment probably doesn't want to invite some of the world's best hackers to stay and meet at its flagship resort.

Post reply on HN