Live data from Hacker News

Basecamp was under network attack

gist.github.com

51–60 of 194 posts

Re: Basecamp was under network attack

#51
I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account.

There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but...

OVH doesn't even feel a 85 Gbps attack (let alone a 20 Gbps one like in the article). They can deal with attack much larger than that automatically.

They seem to have very good DDoS protection against the "flood" type of DDoS. And this is pretty much transparent to users.

I hope more and more hosting company start implementing similar anti-DDoS features: more competition would bring better protection against flood-type DDoS and cheaper price.

Here's the explanation as to how their system works (in french but there are several graphics):

http://www.ovh.com/fr/a1164.protection-anti-ddos-service-sta...

Basically as soon as a DDoS trying to saturate your server(s) is detected the attacker faces the problem of needing to DDoS... OVH itself.

And the DDoS doesn't even make it to your server while the legitimate trafic still does.

I find it great that there are people actually looking for solutions to the DDoS issue.

Re: Basecamp was under network attack

#52

Does anybody know how many companies, upon receiving a blackmail "give us $300 or you'll be DDoSed" email, pay it? For every meetup.com or Basecamp that resist, how many actually give in to the blackmailer's demands?

It isn't $300, it's "up to $50,000"[0]

I've seen articles before saying online gambling websites often do pay up as the downtime isn't just lost revenue but customers going elsewhere.

[0] http://www.prweb.com/releases/2012/4/prweb9455636.htm

Re: Basecamp was under network attack

#53
post #50
post #37

Earlier quoted context omitted.

While I agree, the term blackmailer or extortionist would had been better.

Which are just specific types of criminals. I don't see the problem.

Criminals are just specific types of people, and people are just specific types of mammals. Being more specific sometimes aids understanding.

Re: Basecamp was under network attack

#54
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

>Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen.

Burglary and murder happen too. No reason to hold your language back. Not even lawyers and prosecutors do, and they deal with those everyday.

For the company loosing millions or the Basecamp client whose unable to enter his account, that "those things happen" is not much of a response.

Re: Basecamp was under network attack

#55
I wonder if there will be a day where on-premise solutions will be touted as the solution to the DDoS vulnerability of cloud-based solutions, in much the same way that there seems to be an ebb and flow between fat and thin clients over the course of computing history.

Re: Basecamp was under network attack

#56
post #3

Would CloudFlare help here?

After taking a look at CloudFlare's knowledge base, it seems that their services would definitely help if you were under attack. According to CloudFlare, they offer basic DDoS Protection with their plans, and it seems like you can upgrade to a business account during attacks for improved protection/mitigation. They also claim that they don't have a cap on the size of attacks they can handle.

Relevant links: https://support.cloudflare.com/hc/en-us/articles/200172676-C... https://support.cloudflare.com/hc/en-us/articles/200170216-H... https://support.cloudflare.com/hc/en-us/articles/200170196-I...

Re: Basecamp was under network attack

#57

Earlier quoted context omitted.

I used to know people who performed these types of DDoS attacks. Usually it was because they were hired to do so by a competitor. Every time they would claim to demand a ransom, although they didn't expect for it to be paid. It just made people less suspicious.

A competitor using a DDOS against you seems like a very bad idea. A likely outcome, for a popular service, is that you get free press as a result. The news, combined with the way Bootcamp has handled this, will probably increase their business.

s/Bootcamp/Basecamp

Re: Basecamp was under network attack

#58
post #41

Earlier quoted context omitted.

How is torrents protocol used to DDoS you? I never came across torrents being used as a DDoS. I would appreciate more details on what sort of torrent attack it was, and whether you found any ways of partially neglecting damage.

A malicious tracker, or a peer if using DHT, can claim an IP, the victim, is active in the swarm and has valuable bits of the torrent. Then torrent clients will try to connect to the victim. The attack is pretty clever, being indirect it is hard to trace and because bittorrent allows arbitrary ports you can hit a specific ip & port pair. The one downside is the victims can be sure it is a bittorrent DDOS by checking…

I'm always amazed at the clever ways people come up with to use non-aware clients for malicious purposes.

Re: Basecamp was under network attack

#59
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

Some great language there

It is. Only 4 words into the DDoS announcement and I rolled my eyes. I think that's a record for DHH.

Post reply on HN