Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

121–130 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#121

I wonder why they're not using Cloudflare.

If you read the comments on the Feedly blog, they are using Cloudflare.

Not sure what plan they're on or what kind of revenue they generate, but even the $200/month business plan is a life saver considering some of the features:

- Advanced DDoS protection (layers 3,4 and 7)

- 100% uptime guaranteed

- BGP Origins protection

- Web Application Firewall

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#122
post #6

Earlier quoted context omitted.

There's no reason you can't punish criminals like this and still have a free, democratic, and open society.

I guess if by open you mean the government has surveillance everywhere and all your secrets are out in the open, that's true.

Bullshit. It's perfectly possible to get warrants to track down the bad guys in a case like this. No surveillance state needed.

https://mobile.twitter.com/ziobrando/status/2896350607585075...

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#123
post #119

Earlier quoted context omitted.

Perhaps a poor metaphor in your opinion. I don't believe, nor did I claim, CloudFlare themselves is carrying out DDoS attacks. What they _are_ doing is making it way easier for others to do it. So, perhaps more to your liking would be selling armed guard services to guard against a gang robbery, while simultaneously funding and supporting (but not actually participating in, i.e. not actually providing people for) sai…

I confess I'm not very familiar with CloudFlare -- in what way are they making it easier to carry out a DDoS?

This comment by michaelt provides some background: https://news.ycombinator.com/item?id=7878053.

In more detail:

- These DDoS-for-hire services being referred to are called "booters," "stressers," or similarly retarded names. For a low fee (I think the average is probably around $10, but you can check yourself), one can buy access to one, where they're able to launch an attack for a period of time (the exact period depends on the booter, and some even charge more for longer attacks; 5-10 minutes at a time is probably around average now) by logging into a website, entering the IP/host, and clicking the "attack" button. That is, no skill. Check places like hackforums yourself and you'll find tons of these. Usually the booters are using Ecatel boxes (generally paid for by the booter owner) because they allow spoofing (which is another topic entirely), some use rooted boxes as well.

- These are very common in gaming, because any 12-year-old with access to mommy's credit card can get their hands on one. That's where the "booter" name comes from; the original meaning was to "boot" someone off Xbox Live (residential connections are obviously really easy to knock out).

- The vast majority of these booters are behind CloudFlare to mask their true host. This serves two purposes: it discourages abuse complaints against the host and also provides the sites with DDoS protection.

- Now, this is like drugs - booter owners don't tend to be friendly with each other. As with rival drug dealers, they'll attack each other and generally try to knock out their competition.

- The only reason these booters are able to operate is because of CloudFlare eliminating the DDoS aspect. If CloudFlare stopped providing service to these illegal sites, they'd be forced to fend for themselves, and it would basically be a "gang war" - everyone attacking each other. Which is fine with me, as if the booter kids are attacking each other, their booters aren't able to mess with anyone else. (Let dumb kids be dumb kids.) Eventually perhaps there will be a small number of booters that come out "on the top," able to withstand attacks, but this then has the effect of eliminating most of the competition, which means the prices will rise. This is also a desired effect, because it's harder to get mommy to agree to pay $100 for something (I'm sure they lie about it) than $10.

- So why not just put your own stuff behind CloudFlare and get rid of the problem? Well, besides the whole issue of not wanting to support this racketeering scam (yes, there is a free level of CloudFlare, but certainly they want to sell you the paid ones and the higher levels can withstand different attacks), this option is only open for websites.

FYI, my position in all this is as a game server owner who has dealt with this BS enough, and I'll admit I'm certainly biased towards that side.

CloudFlare stopping support here would go a long ways towards eliminating the booter problem. It won't eliminate DDoS attacks entirely, of course, but it will eliminate a whole class of them and probably the largest class (because actual botnet owners are rarer). I agree entirely with the assessment that CloudFlare is engaging in racketeering.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#124
post #122

Earlier quoted context omitted.

I guess if by open you mean the government has surveillance everywhere and all your secrets are out in the open, that's true.

Bullshit. It's perfectly possible to get warrants to track down the bad guys in a case like this. No surveillance state needed. https://mobile.twitter.com/ziobrando/status/2896350607585075...

Regular warrants given after the attack (to get records or add logging and records) and no pre-existing logging on the network (enforced on providers, or done by a central entity with or without legal permission) makes it really hard to track down attacks which are short-lived, highly mobile, etc.

I'm not sure where the current, ideal, and historical tradeoffs have been for this.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#125
post #102

Earlier quoted context omitted.

If Cloudflare kicked accused DDOS-for-hires, the first step in any DDOS campaign would become "accuse target of being DDOS-for-hire". That wouldn't actually be a step forward for DDOS victims who use Cloudflare, because then they would have to provide human input to some sort of appeal process ASAP, rather than Cloudflare just working automatically to thwart an attack.

An accusation should not be sufficient, obviously. Why can't CloudFlare take abuse complaints, verify and take action based on that? In fact, this is precisely what they've done in the past, though they'd only provide the host details rather than stopping service to a site. (I don't think they'll even go this far anymore, rather they'll give you the abuse email for the host and tell you to have the host contact them,…

Your experience seems to contradict the insinuation that "Cloudflare is knowingly providing cover to the DDOS-for-hire companies after being informed of what they are doing", to which I responded. So I guess there's no problem after all?

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#126
post #102

Earlier quoted context omitted.

An accusation should not be sufficient, obviously. Why can't CloudFlare take abuse complaints, verify and take action based on that? In fact, this is precisely what they've done in the past, though they'd only provide the host details rather than stopping service to a site. (I don't think they'll even go this far anymore, rather they'll give you the abuse email for the host and tell you to have the host contact them,…

Your experience seems to contradict the insinuation that "Cloudflare is knowingly providing cover to the DDOS-for-hire companies after being informed of what they are doing", to which I responded. So I guess there's no problem after all?

I don't think it contradicts that. CloudFlare is indeed knowingly providing cover to them. The fact that they'll give you an abuse email to the actual host doesn't change them continuing to provide service to such sites, even when they acknowledge a site is a booter.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#127
post #126

Earlier quoted context omitted.

Your experience seems to contradict the insinuation that "Cloudflare is knowingly providing cover to the DDOS-for-hire companies after being informed of what they are doing", to which I responded. So I guess there's no problem after all?

I don't think it contradicts that. CloudFlare is indeed knowingly providing cover to them. The fact that they'll give you an abuse email to the actual host doesn't change them continuing to provide service to such sites, even when they acknowledge a site is a booter.

I think we agree, that any defensible policy would lie somewhere between "ignore all accusations of booting" and "credulously believe all accusations of booting". Re-reading your comment, I'm not sure, but are you saying that CF are at the former end of the policy spectrum? That's regrettable.

I wonder, however, if even the latter policy would solve the booter problem. Accessible websites are convenient for commerce, but they aren't required.

Also, any argument you make about CloudFlare could also be made about Google: I see http://quantumbooter.net as the second link and http://top10booters.com/ as the fifth link at https://www.google.com/search?q=booter+services

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#128
post #126

Earlier quoted context omitted.

I don't think it contradicts that. CloudFlare is indeed knowingly providing cover to them. The fact that they'll give you an abuse email to the actual host doesn't change them continuing to provide service to such sites, even when they acknowledge a site is a booter.

I think we agree, that any defensible policy would lie somewhere between "ignore all accusations of booting" and "credulously believe all accusations of booting". Re-reading your comment, I'm not sure, but are you saying that CF are at the former end of the policy spectrum? That's regrettable. I wonder, however, if even the latter policy would solve the booter problem. Accessible websites are convenient for commerce,…

> I think we agree, that any defensible policy would lie somewhere between "ignore all accusations of booting" and "credulously believe all accusations of booting".

I agree with this.

> Re-reading your comment, I'm not sure, but are you saying that CF are at the former end of the policy spectrum? That's regrettable.

Somewhat. As of my last experience with them (which was like a year ago), they will accept abuse complaints for booters. If you can prove to them the site is a booter, by providing documentation on the site itself (not hackforums or anywhere else where it's being advertised, which is understandable as it's basically hearsay, though a bit difficult) indicating the site offers a DDoS service, they will provide the abuse@ email of the hosting company. They will tell you to have the abuse@ people contact them directly for further details. This is the only action they will take.

But my opinion is they should, upon confirming the site is a booter, terminate their service to the site. It would also be nice if they would continue to provide the host details, in addition, so the reporter can contact the actual host and have the site taken down from there as well.

> Also, any argument you make about CloudFlare could also be made about Google: I see http://quantumbooter.net as the second link and http://top10booters.com/ as the fifth link at https://www.google.com/search?q=booter+services

Very good point, thank you for mentioning.

The difference I see is that CloudFlare actively provides a service to them, while Google is merely maintaining a keyword-based search listing for them. That being said, I can see both sides of this one.

My views on the legitimacy (rather, lack thereof) of booters: they are a service that serves absolutely no legitimate purpose. The sole purpose is to perform an illegal act against another person. I know a bunch of them are sold on hackforums as "stressers," i.e. "stress test your own server," but that also isn't a legitimate purpose - I can see no case where one would want to stress test their own services with some UDP or SYN flood over the Internet. Such a thing would only be done over a private network using your own packet generator.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#129
post #117
post #71

Earlier quoted context omitted.

I was a very happy Digg Reader user for a while, but the bugs just kept getting worse and worse, and I jumped ship. Now I'm on BazQux, which works very, very well and very, very quickly, but has no mobile version and a design straight out of 1996.

And it's written in Haskell. Which makes me want to take a look at Haskell again :)

I thought they used Ur/Web.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#130

Earlier quoted context omitted.

If you were a former Google Reader user, you might like Feedbin. I've been with them for the last year or however long and have been fairly happy.

I've been using Digg Reader for a while and I'm actually kind of shocked that most people haven't moved to that. It has its bugs (sometimes showing incorrect numbers, the mobile app locks up sometimes), but it's honestly the best alternative that I've found so far. Maybe it has to do with its free-ness, as people worry about them shutting doors like Google Reader, but if you're looking for a free solution then I'd de…

The development has been glacial bordering on non-existent since launch on digg reader. The betaworks team that created it was able to do so in a matter of weeks– after re-writing and launching the new digg on a similar timeframe – which makes me think the current lack of progress is because they've moved on to other things (Instapaper, for one).

It's too bad, digg reader had a lot of promise.

Post reply on HN