Live data from Hacker News

Basecamp was under network attack

gist.github.com

81–90 of 194 posts

Re: Basecamp was under network attack

#81
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

Disagree. Understanding the root cause helps even non-technical customers make the right decision. For example - "If I move to a different service (competitor of Basecamp), is there a chance that I will run into this issue there too? Answer is yes, based on how DHH explained the problem." Customers understand that shit happens. Particularly because many Basecamp users are business owners and can relate to shit happening in their business too. Explaining the root cause in plain language, and emphasizing that the user data is safe is a great way to deal with this situation.

Re: Basecamp was under network attack

#82
post #61

Earlier quoted context omitted.

Sounds like your issue is with DHH and not necessarily the copy.

Totes true. His selection of words is in one of the bombastic veins that rubs me the wrong way. It goes beyond just one piece of writing, that does make my issue with the writer.

[deleted]

Re: Basecamp was under network attack

#83

Earlier quoted context omitted.

The problem he may have is its a bit to reassuring. They claim user data is safe while being under attack. This is conceptually very similar to teaching kids that if you duck and cover during an ICBM strike you'll be fine. >This is like a bunch of people blocking the front door and not letting you into your house. The contents of your house are safe -- you just can’t get in until they get out of the way. If this is t…

Not sure that your missile analogy holds. Most DDoS attacks do not attempt to crack logins to servers, but rather try to flood the servers with as much garbage as possible. Besides, even if they were trying to crack the SSH password, a properly secured server (long passwords/public key auth + fail2ban) should be fine.

Okay here is a better one. Just because people are blocking each other trying to run into your front door doesn't mean they (or somebody else) aren't cutting open your windows, picking the lock on your garage door, or trying to climb down your chimney.

Re: Basecamp was under network attack

#84
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

Not sure why you got voted down (hopefully my vote will put it back at 1). I think it's a legitimate point of view. I can certainly imagine some company out there mad at 37signals because they can't get work done because of the attack, wasting thousands of dollars of labor.

Re: Basecamp was under network attack

#85
post #68

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

I have a service on OVH myself. Though a friend at another related service had been kicked from two VPS providers due to receiving a few DDoS attacks. These providers claimed it was against their Terms of Service and ejected him as a customer. That day he learned it is best to keep offsite-cross-company backups of everything, since he did not get a single byte from his machines.

Claiming it was against the terms might be an easy out for them but is silly since being a target is outside of your control, for the most part. Hosts will usually null route customers without sympathy to protect other customers so it's the price of doing business.

Re: Basecamp was under network attack

#86
post #61

Earlier quoted context omitted.

Sounds like your issue is with DHH and not necessarily the copy.

Totes true. His selection of words is in one of the bombastic veins that rubs me the wrong way. It goes beyond just one piece of writing, that does make my issue with the writer.

>"His selection of words is in one of the bombastic veins"

I am not completely sure what this even means, but I am sure there is irony in there!

Re: Basecamp was under network attack

#88
post #71

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

What happens when a ddos is indistinguishable from regular traffic? Or is it the case that it almost always follows a particular pattern?

[deleted]

Re: Basecamp was under network attack

#90

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

Products by people like Arbor Networks (http://www.arbornetworks.com/) helps with this -- I think they essentially observe traffic patterns and siphon what they detect to be DDoS traffic to alternate routers at the edge of the network to study and blackhole.
Post reply on HN