Live data from Hacker News

Basecamp was under network attack

gist.github.com

131–140 of 194 posts

Re: Basecamp was under network attack

#131
post #20

Earlier quoted context omitted.

It depends if this attack is on basecamp.com or the IPs that basecamp.com resolves to. It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.

...the attacker could still find their direct servers fairly easily and attack that IP. Can the upstream to the actual server restrict traffic to known Cloudflare blocks?

We've had issues with saturated upstreams and then been negotiating new ISP connections. All the ISPs I've asked (Level3, NLayer, Cogent) won't put an active restriction to only CDN blocks upstream.

The ISPs will help during a DDOS but response times are slow and we haven't tried getting them to put this type of block in place yet.

Re: Basecamp was under network attack

#132
post #120

Earlier quoted context omitted.

IANAL, but I've seen this discussion come up multiple times, and the problem is that the counterattack would technically be illegal. The fact that somebody else has already broken the law in order to compromise an innocent bystander does not give anybody else the right to do the same thing. Vigilantism is as illegal on the internet as it is in the real world. This is a huge constraint for the people (e.g. at Microsof…

But this could be considered self-defense which is granted by most law systems.

Again, IANAL, but my understanding is that the concept of self-defense is specific to the use of force, rather than broadly applicable. You'll find it difficult to prove an immediate thread of physical harm from a DDoS.

And even if it were legal, you'd still have to deal with all of the "$SELF_DEFENDER broke my web site" PR unpleasantness from the innocent bystanders.

Re: Basecamp was under network attack

#133

Earlier quoted context omitted.

http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... > As I noted in a talk I gave last summer with Lance James at the Black Hat security conference in Las Vegas, a funny thing happens when you decide to operate a DDoS-for-hire Web service: Your service becomes the target of attacks from competing DDoS-for-hire services. Hence, a majority of these services have chosen to avail themselves of Cloudflare’s fr…

I could post more, but why bother? The krebs story was interesting thanks, the forum posts less so. I understand why cloudflare are reluctant to start rejecting customers based on content, but surely it's illegal to sell DDOS services? Perhaps they should change their TOS to exclude any sites which sell attack tools/services, because it looks really bad for them to be protecting sites that promote DDOS, which then pr…

Yea. They don't really bother to take them down. Their logic is that the attack traffic isn't technically leaving via their network, so it's not their problem. Take a look at whois for the domains in that last forum link. Two of those domains are still pointed at cloudflare nameservers.

I'm sure there's tons more, but why bother compiling a list when nothing will change. If you're curious, a good place to look would be the hackforums 'DDOS as a service' section. I bet a lot of the active ones would go to cloudflare.

Re: Basecamp was under network attack

#134
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

> "It doesn't matter if your excuse is true, it's still an excuse."

you're seriously comparing handing in a term paper late to being targeted for extortion by an international crime syndicate?

of course handing in a term paper late is unexcusable - it's just a fucking essay and there's no reason why it should be late because you probably had weeks to do it.

waking up to find your entire network infrastructure under siege (and anything ELSE you put up as a contingency, because it's on the internet, remember?) is not some shit you can be "no excuses" hardcore about because this is in the real world which is complex, unlike slacking on a paper, which is very simple.

reasonable people know this, which is if you read their TOS and other SLA agreements, this is all spelled out for you. nobody wants ot hear "NO EXCUSES!" from some guy paying $50/month while gigabits worth of malicious traffic is pounding at your door.

the truth is it's YOUR business, just like basecamp is THEIR business which they are QUITE obviously in the middle of running. if you're concerned your $50 saas product is not delivering the goods, it's on YOU to find an alternative.

Re: Basecamp was under network attack

#135
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Yes, "criminals" is much too harsh. Let's replace it with "unfortunately misguided souls xoxo".

Re: Basecamp was under network attack

#137
I'm wondering what happens to botneted subscribers from which the attacks originate. Is any attempt made to locate them and contact their ISPs? I think there should be, and subscribers found to be participating in the attack (presumably unknowingly) should be disconnected immediately. After all it's the subscribers' responsibility to keep their computers botnet free. Launching a DOS attack, even unknowingly, is probably violating the contract they signed with their ISP.

Re: Basecamp was under network attack

#138
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

Customers, especially non-technical ones, don't give a crap.

The fact that this is on a Github Gist, as opposed to a static page (like on s3), suggests an audience that would understand those subtleties.

Re: Basecamp was under network attack

#139

Earlier quoted context omitted.

Okay here is a better one. Just because people are blocking each other trying to run into your front door doesn't mean they (or somebody else) aren't cutting open your windows, picking the lock on your garage door, or trying to climb down your chimney.

Yes you do. Because DDoS, so like the service is down for users and attackers. I'm surprised that on a technical forum there is still this complete misconception of what a DoS is.

There are different types of DDoS attacks.

Each level of the OSI model can be attacked in a DDoS, and its still of Denial of Service attack. I.E.: You can hold down a pre-2009 windows server with as little as 10-15 packets per second, totally less then a kilobyte per second.

Yes if your have a 10/100/1000 nic and your getting 20Gb/s then yeah nothing's getting in. Or if you have a 10Gb/s router, then 20Gb/s will freeze the whole data center. But if you have a 100Gb/s router with a 4x bounded 10Gb/s nics. And your service is down, then it isn't your hardware, but your software. Your kernel, sockets.h, are still processing packets, you can still be attacked.

Re: Basecamp was under network attack

#140
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

So if a pizza delivery guy gets shot on the way do you still demand better service? Just trying to see if you believe in the principle or just the practical aspect. :)
Post reply on HN