Live data from Hacker News

We are under attack

en.greatfire.org

51–60 of 283 posts

Re: We are under attack

#51
post #36

Contact Akamai who recently bought the DDOS mitigation service Prolexic. They may be able to mitigate the attack and save you bandwidth costs. Alternatively, call CloudFlare. Don't just absorb this through Amazon.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

This is actually pretty eye opening to me considering they tout themselves as a top notch defense against DDoS attacks.

I might have to reconsider mine and my clients choice of providers for this very purpose.

Re: We are under attack

#52

Contact Akamai who recently bought the DDOS mitigation service Prolexic. They may be able to mitigate the attack and save you bandwidth costs. Alternatively, call CloudFlare. Don't just absorb this through Amazon.

[deleted]

Re: We are under attack

#53
post #20
post #8

Earlier quoted context omitted.

Route them through a cached captcha page. Or just call cloudflare.

Serving a captcha page is more work than serving a static page.

You can block with firewall IPs of users, who didn't solve captcha. You will get only SYNs from incoming connection requests then.

Re: We are under attack

#54
post #29

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Unrelated to the story at hand. Have you been recently DDoSed on OVH? I know that (at least some time ago) they just null-route/deactivate your account on spot with no notification on anything that looks like a DDoS.

This may be true. However, they are FAR more inclined to work with a customer before just flipping a switch like a lot of (for example) American hosting companies will. I have nothing but good things to say about OVH. They were helpful during a DDoS I had about a year ago throughout the incident, but I'm sure they would have nullrouted me had I not been so responsive to their support guys when things started going badly. "I'm sure" here is pure anecdote and based on zero evidence, but it's the feeling I got.

Re: We are under attack

#55
post #36

Contact Akamai who recently bought the DDOS mitigation service Prolexic. They may be able to mitigate the attack and save you bandwidth costs. Alternatively, call CloudFlare. Don't just absorb this through Amazon.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law."

There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's a more accurate statement:

We're a tech company whose success is completely dependent on the freedoms in our nation and many other nations around the world, and on the political and economic systems, infrastructure, and enormous wealth that blossomed from them. Without the sacrifices of blood and treasure by our predecessors of hundreds of years, and of many people today, we would not have these resources or opportunities today. There are many talented people born in many countries who, without these benefits, have no opportunity for success.

They can't sacrifice their company for every principle, every time, but there's a middle ground between that and 'we're just a tech company so we have no responsibilities'.

Re: We are under attack

#56
post #24

Earlier quoted context omitted.

Don't call Akamai. Never call Akamai. They are horrible. Try Incapsula, GigENet, Blacklotus, Cloudflare first.

Can you elaborate on why you think Akamai is horrible?

I've dealt with them in their CDN role on multiple occasions.

They're the most abhorrent combination of incompetence and arrogance that I've ever met in the tech industry.

They're the Oracle of the network world. Just don't waste your time on them. There's plenty better and cheaper CDNs nowadays.

Leave Akamai to the Governments and MegaCorps, they deserve each other.

Re: We are under attack

#57

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Wow, I haven't done dedicated hosting in a long time, the prices are insane there! https://www.ovh.com/us/dedicated-servers/enterprise/2014-MG-... Thanks for posting :-) I've been looking for provider possibilities for my next failed startup. I'm not sure how they can deliver for that price but who am I to complain!

100% worth it. I have monitoring/notification set up on my infrastructure, and have had two hardware failures since becoming an OVH customer a few years ago. OVH techs in the datacenter were on the scene before I got downtime notifications. Their techs must deal with this kind of thing all night, every night, because they seem to have this process of replacing hardware down to a science. This as opposed to my other dedicated providers, who basically don't give a shit, for the same hardware at the same price. OVH is an excellent budget investment!

Re: We are under attack

#58

Earlier quoted context omitted.

Anyone who has ever dealt with Akimai knows that you have to have your Buckets O' cash ready. Cloudflare would probably be the best bang for the buck.

Actually the Prolexic product is one of the most innovative and effective one we've seen to date. DDoS attacks are not a commodity issue, you have to pay to play..Not sure how that makes Akamai horrible..

I can confirm that Akamai is a pain to deal with. Defense.Net as well. Cloudflare is what I would chose but they are siding with the Chinese gov't at this point.

Re: We are under attack

#59
post #9

Are you using Cloudflare?

A lot of CloudFlare IPs are blocked by the chinese firewall, for a site that's primarily aimed at chinese users probably not an option. Edit: I don't actually know if this is still true and on what scale, I just know that's it's true for a website I use according to chinese users.

Even if it is true, getting an enterprise account, which is still very reasonably priced, gives you dedicated IP addresses to your site, so this shouldn't be a huge concern. Generally when under fire, Cloudflare is also happy to get you up and running and talk finer details on billing for the long term later.

The bigger problem is their stance on Latern mentioned above.

Re: We are under attack

#60

It would be interesting to see which IP space the bulk of the traffic is coming from. Seems like it would be trivial for the Chinese government to spoof traffic from any IP within China...

For a DDoS, you can spoof your IP to anything, because you don't care about actually receiving response packets. This is standard in a SYN flood.
Post reply on HN