Live data from Hacker News

We are under attack

en.greatfire.org

131–140 of 283 posts

Re: We are under attack

#131

Earlier quoted context omitted.

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's…

> There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves. It's not just a popular idea, it's why they are created as firms instead of philanthropies. There is a difference and it does matter what the expectations of the donors/investors are. > We're a tech company whose success is completely dependent on the freedoms in our nation... This sounds great but how is it refle…

Everyone has a responsibility to the world around them.

It may not be coded into law, but it is still a true statement.

Re: We are under attack

#132
post #18

Sitting down and writing a blog-post seems a pretty laid back reaction to $30k/day in Amazon bills... First thing I'd have done is take the site offline and call the various DDoS mitigation services (Incapsula, Cloudflare, etc.). Pretty surely most of them would gladly pick up the slack here, given the free PR (possibly even in mainstream press) they get in return.

If they're a non profit, then maybe this is exactly what their mission is. They can sit back and rack up a huge aws bill, then Amazon has to decide whether to collect. If they do collect, then that was what the money was for anyway. I'm guessing that giving in to bullying from the Chinese government is against their core principles here.

Re: We are under attack

#133

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source. I know you can do this on the server, using many different techniques. But this does not help a…

I think this would not be intended. The page is DDoSed from China and supposed to be reachable from China at the same time.

Re: We are under attack

#134
post #110

Earlier quoted context omitted.

That's an optimistic view. My take on it is "market share|revenue > human rights". EDIT: It turns out Lantern was using an exploit at Cloudflare [+], and wasn't a customer. My apologies /u/eastdakota. [+] https://news.ycombinator.com/item?id=9234367

More accurately "market share|revenue > political activism"

And in this case political activism = human rights.

Re: We are under attack

#135

Should the Chinese government have the power to shield their citizens from information and monitor them electronically? Should a group of people in democratic, Western countries be able to subvert the will of a world superpower with impunity? Of the two scary worlds, I guess I'd rather choose the latter. But I don't even like having to choose. (I doubt Amazon like being asked to choose even less, and I would be surpr…

>Should a group of people in democratic, Western countries be able to subvert the will of a world superpower with impunity?

Crazy time we live it that this is even possible.

Re: We are under attack

#136
post #116

Earlier quoted context omitted.

That's an optimistic view. My take on it is "market share|revenue > human rights". EDIT: It turns out Lantern was using an exploit at Cloudflare [+], and wasn't a customer. My apologies /u/eastdakota. [+] https://news.ycombinator.com/item?id=9234367

What counts as human rights is subjective. The UN says that it is a human right to receive and express opinions through any medium. Does that mean that we should hold "human rights" to be more important than revenue and forbid service providers from charging for access to information? Like the WSJ who wrote the article that's supposedly to blame here?

If you don't hold human rights over revenue, what's your view on slavery?

Re: We are under attack

#137
post #29

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Unrelated to the story at hand. Have you been recently DDoSed on OVH? I know that (at least some time ago) they just null-route/deactivate your account on spot with no notification on anything that looks like a DDoS.

Yes, and the service has remained available to most users. It's just the initial flood knocked stuff out for about 2 minutes as the worker threads dropped their request queues.

Re: We are under attack

#138
post #18

Sitting down and writing a blog-post seems a pretty laid back reaction to $30k/day in Amazon bills... First thing I'd have done is take the site offline and call the various DDoS mitigation services (Incapsula, Cloudflare, etc.). Pretty surely most of them would gladly pick up the slack here, given the free PR (possibly even in mainstream press) they get in return.

Its also toxic PR if you want to expand in the Chinese market.

Re: We are under attack

#139

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source. I know you can do this on the server, using many different techniques. But this does not help a…

Geo DNS (to be more precise AS numbers is what is used) is something that is sometimes used as a very last resort - customers in China are customers as well, and if you drop everything from China thats effectively what the attacker wanted.

I recall only hearing about one time when packets from Chinese ISPs were completely dropped for some reason and only for short period.

I've also have an anecdotal reference that one can persuade providers that actually deliver traffic from China to do filtering on ingress on next hop routers after China, but that should be something very serious, that impacts their revenue as well and prolonged. As another commenter noted - costs for providers are very non-trivial.

In my experience DDOS is always money competition, it costs money to mount one, it costs money to defend against one. Unfortunately when one of the sides is [allegedly] a country it doesn't play very well.

Re: We are under attack

#140
post #132
post #18

Sitting down and writing a blog-post seems a pretty laid back reaction to $30k/day in Amazon bills... First thing I'd have done is take the site offline and call the various DDoS mitigation services (Incapsula, Cloudflare, etc.). Pretty surely most of them would gladly pick up the slack here, given the free PR (possibly even in mainstream press) they get in return.

If they're a non profit, then maybe this is exactly what their mission is. They can sit back and rack up a huge aws bill, then Amazon has to decide whether to collect. If they do collect, then that was what the money was for anyway. I'm guessing that giving in to bullying from the Chinese government is against their core principles here.

As xnull6guest already noted, they are most probably already financed by the US government, that's why they can be laid back: they are exactly doing what they are paid for.
Post reply on HN