Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

131–137 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#131
post #117

Earlier quoted context omitted.

And it's written in Haskell. Which makes me want to take a look at Haskell again :)

I thought they used Ur/Web.

Ur/Web is used mostly for generating JavaScript and part of web server. Most backend is written in Haskell.

You could look more here https://github.com/bazqux/bazqux-urweb

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#132
post #102

Earlier quoted context omitted.

An accusation should not be sufficient, obviously. Why can't CloudFlare take abuse complaints, verify and take action based on that? In fact, this is precisely what they've done in the past, though they'd only provide the host details rather than stopping service to a site. (I don't think they'll even go this far anymore, rather they'll give you the abuse email for the host and tell you to have the host contact them,…

Your experience seems to contradict the insinuation that "Cloudflare is knowingly providing cover to the DDOS-for-hire companies after being informed of what they are doing", to which I responded. So I guess there's no problem after all?

I may not have been clear where I made that comment, so let me explicitly say that I do not know the history or state of CF's abuse policies. CF may, in fact, be doing everything right. I was merely stating a condition that, if CF is doing what you quoted, then it would be a "big bunch of bullshit."

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#133

Earlier quoted context omitted.

Or he saw the other guy is open to trying different RSS readers and simply made a recommendation.

I'm moving TO Feedly since they've already had their attack. Next round would be the some other provider.

Sadly, that doesn't seem to be the case, they're being DDoS'd again today (new attack).

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#135
post #110

Earlier quoted context omitted.

Multiple devices is the main reason I rely on a web service.

That's why I read RSS via IMAP. All of my devices have an IMAP client on them. I have a script which downloads RSS feeds and sends an email to me for each item, which is then filtered into a News folder via a Sieve filter. I spend half my time in my email clients anyway so I may as well get my RSS fix in the same place.

Interesting flow!

Personally I'm beginning to hate email... sorta wish the actually-important stuff in my email were sent to my RSS reader...

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#136
post #119

Earlier quoted context omitted.

Are you actually claiming that CloudFlare is paying for DDoS attacks, or is that a really poor metaphor?

Perhaps a poor metaphor in your opinion. I don't believe, nor did I claim, CloudFlare themselves is carrying out DDoS attacks. What they _are_ doing is making it way easier for others to do it. So, perhaps more to your liking would be selling armed guard services to guard against a gang robbery, while simultaneously funding and supporting (but not actually participating in, i.e. not actually providing people for) sai…

If you're looking for an actual metaphor, it would be selling armed guard services to you and also to gangs. Its not even clear, in this metaphor, that said armed guard vendor can even tell the difference between law-abiding citizens and gangs - and they can't just shut down services to anyone accused of being a gang, because then the gangs get you by telling ARMED GUARDS, INC that you're a gang and then robbing you while you're not protected.

This metaphor got long and stupid, but at least its accurate. Stop fear-mongering just because you don't like CloudFlare.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#137
post #119

Earlier quoted context omitted.

Perhaps a poor metaphor in your opinion. I don't believe, nor did I claim, CloudFlare themselves is carrying out DDoS attacks. What they _are_ doing is making it way easier for others to do it. So, perhaps more to your liking would be selling armed guard services to guard against a gang robbery, while simultaneously funding and supporting (but not actually participating in, i.e. not actually providing people for) sai…

If you're looking for an actual metaphor, it would be selling armed guard services to you and also to gangs. Its not even clear, in this metaphor, that said armed guard vendor can even tell the difference between law-abiding citizens and gangs - and they can't just shut down services to anyone accused of being a gang, because then the gangs get you by telling ARMED GUARDS, INC that you're a gang and then robbing you…

You aren't getting it. The issue isn't that CloudFlare doesn't proactively seek out such sites. The issue is that when they are advised a site using their service is a DDoS service, and provided proof of that, _they don't care_ and continue providing service to it. The proper action would be to investigate the abuse complaint, try to conclusively determine if it is true and if so, terminate service to the site.

They don't do that, but continue to sell their DDoS protection service (beyond the free tier), so they are indeed a racketeering operation.

Post reply on HN