Live data from Hacker News

The Internet Archive is under a DDoS attack

mastodon.archive.org

181–190 of 227 posts

Re: The Internet Archive is under a DDoS attack

#181
post #151

Earlier quoted context omitted.

I find the idea of DDoS providers confusing. If someone tried to operate a service that can be abused easily to cause similar disruption in the physical world, the operation would be taken down quickly and the people behind it would probably end up in prison. But somehow the internet is still a lawless zone where crime is tolerated and everyone is out for themselves.

It used to be very rare for DDoS providers to publicly advertise their services, you kinda had to know a guy who knew a guy. If you put up a website offering this service the Good Guys of the Internet would track you down and get your provider to take you down, or that provider would in turn get disconnected from the internet. Now they hide behind Cloudflare who will refuse to turn over any information so that securi…

It's true that you can't practically block Cloudflare without impacting legitimate users, but they can absolutely be depeered if you're willing to pay a higher transit bill.

Re: The Internet Archive is under a DDoS attack

#182

Earlier quoted context omitted.

No, thanks. Cloudflare acts ethically only until it suits them. It is the pre-exploitation phase to lure a customer. We are not fools here. The report at https://news.ycombinator.com/item?id=40481808 says it all. Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy.

> Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy. This seems like a weak argument. Should we just take down anything widely accessed because it might be used by the NSA? What about AWS?

Yes, that's pretty much the view in Schrems II from the European Court of Justice. The CLOUD Act does not respect data protection rights.

Re: The Internet Archive is under a DDoS attack

#183
post #105

This is why I’ve gotten into the habit of maintaining my own WWW archive of sites I find interesting. Probably have around 1 TiB now, and One Of These Days I’d like to set my network up so it can serve arbitrary sites directly from local archive to revive any site I want. I have a `wget-mirror` shell function invoking wget with all the trimmings that takes care of 99% of sites. I’ll edit the full command into this co…

Assume everyone is familiar with this project, dating back to 1996: https://en.wikipedia.org/wiki/WWWOFFLE https://ftp.netbsd.org/pub/pkgsrc/distfiles/wwwoffle-2.9j.tg... The way the www is going, it seems like downloading a copy of libgen, i.e., nonfiction books, and scimag, i.e., academic journals, via torrent, would be more valuable than archiving websites, in general. These primary sources are part of the materia…

Do we know for sure that they trained on data from libgen etc? It's such a powerful source of information you'd assume they must have, although they would never admit it. There must be a way to test if they have, via enquiring about some niche information only found in certain books.

Re: The Internet Archive is under a DDoS attack

#184
post #31

Earlier quoted context omitted.

The user you're responding to is Jason Scott of TIA.

Shallow dismissal anyway, even if he was the Supreme Majestic King of New Americania. He might further explain his answer. And I'm truly sorry for the DDos happening to this guy's organisation!

What is there to explain further?

Re: The Internet Archive is under a DDoS attack

#186
post #173

Earlier quoted context omitted.

And yet if they ponied up the money, that issue of "tainting" shared IPs suddenly goes away. You can bet CloudFlare would graciously give the gambling site as much time as they need to bring their own IP (they went out of their way to link third party sellers of IPs with dubious provenance, after all).

Did you read the blog post? It doesn't include the entire correspondence so it's not clear how explicit Cloudflare was about this but the Enterprise plan they were trying to upsell them includes BYOIP. It's clear to me that Cloudflare insisted they buy the enterprise plan because it includes BYOIP. So in other words, Cloudflare noticed the author was running a gambling site, they decided that this was negatively impa…

To me it’s similar to the whole “SSO wall of shame” thing, where a vital feature is locked behind more expensive pricing. As said in the article:

“We tried saying that we don't need any number of the 14 features that are included”

Which, to me, is the crux of the issue. Is it fair for Cloudflare to say “You are breaking the terms of service if you do not change your set up in this specific way, and also the way you need to chance your setup is locked behind a significantly more expensive pricing.” Being able to bring your own IP does not, to me, seem like something that should require a plan that is orders of magnitude more expensive than the standard. It seems much more to me like something that is more fundamental, and should be included as an option in a lesser version of the product Maybe I’m wrong, and there is actually significant overhead to Cloudflare for letting customers bring an IP. But as is, it feels very much to me like a situation where something vital was locked at the most expensive tier to force certain kinds of customer to pay more.

Re: The Internet Archive is under a DDoS attack

#187
post #150
post #110

Earlier quoted context omitted.

Cloudflare is a data goldmine setup by people who love fedoras and newspapers. Professional DDOS providers won't use Cloudflare ever and have the skills, metal and (human) network to do everything in-house.

Yeah you're actually worse off using Cloudflare because you can't block attacker IPs anymore, once you're dependent on them to protect you, and they're not very good at protecting. I run an online service that invites hackers to DDOS the server. Cloudflare's servers would usually go down before we did. The only way we could stay online was by switching to GCS and using token buckets to blackhole IPs in the raw prerou…

You mention the key feature for ddos (self-)protection - zero ingress fees. Non-Availability hurts you in harder-to-quantify terms than a bill for bandwidth used.

Zero ingress puts the upfront bandwidth cost onto the attacker. Because... you actually may succeed to defend and stay up. Their success is not guaranteed, they might be shouting into the void.

Attack success (as in, "impact on you") is guaranteed if your ingress is chargeable.

Re: The Internet Archive is under a DDoS attack

#188

Earlier quoted context omitted.

No, thanks. Cloudflare acts ethically only until it suits them. It is the pre-exploitation phase to lure a customer. We are not fools here. The report at https://news.ycombinator.com/item?id=40481808 says it all. Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy.

> Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy. This seems like a weak argument. Should we just take down anything widely accessed because it might be used by the NSA? What about AWS?

Is AWS providing DDoS mitigation services now, coupled with MITM access to user traffic?

Re: The Internet Archive is under a DDoS attack

#189

Earlier quoted context omitted.

> Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy. This seems like a weak argument. Should we just take down anything widely accessed because it might be used by the NSA? What about AWS?

Is AWS providing DDoS mitigation services now, coupled with MITM access to user traffic?

They're the man at the end, actually. No extortion necessary.

Re: The Internet Archive is under a DDoS attack

#190
post #80

Earlier quoted context omitted.

What's the significance of that? (Googling "Jason Scott TIA" gives me "Dr Jason Scott is a Senior Research Fellow in the Tasmanian Institute of Agriculture" which doesn't explain much to me)

The beauty of acronyms/initialisms that people are too lazy to spell out! TIA = The Internet Archive (i.e. the victim of the DDoS). > The user you're responding to is Jason Scott of The Internet Archive

[deleted]
Post reply on HN