Live data from Hacker News

We are under attack

en.greatfire.org

121–130 of 283 posts

Re: We are under attack

#121
Should the Chinese government have the power to shield their citizens from information and monitor them electronically?

Should a group of people in democratic, Western countries be able to subvert the will of a world superpower with impunity?

Of the two scary worlds, I guess I'd rather choose the latter. But I don't even like having to choose.

(I doubt Amazon like being asked to choose even less, and I would be surprised if they cut you any slack. Sedition is not looked upon favorably, and abetting those perpetrating it is not either.)

Re: We are under attack

#122

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

I chuckled, because when everyone tells me "AWS is practically the internet" I can point out "The Internet is resilient at a far lower cost than Amazon".

Re: We are under attack

#124
post #84

Earlier quoted context omitted.

To be exact, he probably means 64 GiB¹ of RAM (see IEEE 1541-2002²). ―――――― ¹ — http://www.wolframalpha.com/input/?i=1%20GiB%20to%20MiB%20an... ² — https://en.wikipedia.org/wiki/IEEE_1541-2002

No, GB is perfectly correct when referring to memory. Just because some people standardized on Gibibyte and redefined gigabyte doesn't invalidate what memory makers have been doing for ever. JEDEC still uses GB, as they should.

I think JEDEC is in the wrong here, though. Memory prefixes sound like SI prefixes, but they're not. That's clearly a bug.

Re: We are under attack

#126

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source.

I know you can do this on the server, using many different techniques. But this does not help as the traffic still reaches you (that you have to pay for).

You can also do this with Geo DNS (and get much less of a bill).

And the ISPs, datacenters, and anyone with a router can block ASIA or China allocated IP ranges. Especially if it's not the type of a flood that's designed to attack the routers (instead of the web-server).

So what's stopping Amazon?

Re: We are under attack

#127
post #124

Earlier quoted context omitted.

No, GB is perfectly correct when referring to memory. Just because some people standardized on Gibibyte and redefined gigabyte doesn't invalidate what memory makers have been doing for ever. JEDEC still uses GB, as they should.

I think JEDEC is in the wrong here, though. Memory prefixes sound like SI prefixes, but they're not. That's clearly a bug.

I was unaware they had a monopoly on language usage. A byte is not an SI unit. Base2 is vastly more defensible and natural than base10. The real issue is that everyone in networking likes round base10 numbers divided over some arbitrary cesium fluctuations. This leads to 1GB / 1Gbps not being 8 seconds, which is confusing. But in JEDEC's and others defense: "why should I have to change, he's the one that sucks."

Re: We are under attack

#128

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source. I know you can do this on the server, using many different techniques. But this does not help a…

Please, don't perceive this as being rude, it's not meant to be.

Having provided IP transit at a largish network provider in a previous life, you have no idea at the complexity involved what you're asking for. It could be done, but the costs involved are non-trivial.

If you're honestly interested in the complexity involved, start reading about BGP, dynamic routing protocols, router/switch fabrics, control plane integration, autonomous systems, peering agreements, etc.

Re: We are under attack

#129

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

That sounds too good to be true. I guess after a 24/7 china DDoS their costs are higher than that and they ask for more.

Re: We are under attack

#130

You should trace the attackers by tracing back. Work with your upstream providers and mailing lists (NANOG) and publicly shame these attackers. Likely, they are spoofing addresses - validate that and make sure you let the network know where the spoofed traffic is sourcing from to follow BCP38 and BCP84, defined by RFCs 2827 and 3704.

Assuming it is direct spoofed traffic and not a reflection, naming and shaming will accomplish nothing. Names of the big ISPs allowing this are not a secret.
Post reply on HN