Live data from Hacker News

We are under attack

en.greatfire.org

141–150 of 283 posts

Re: We are under attack

#141
post #67

Post the IP addresses from which you're getting attacked. Others can analyze them by ISP, and public pressure on the worst ISPs might help.

The bad ISP in question is the People's Republic of China.

I mean post the whole IP address list for public analysis.

Re: We are under attack

#142

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

I chuckled, because when everyone tells me "AWS is practically the internet" I can point out "The Internet is resilient at a far lower cost than Amazon".

Internet as a whole yes, making a single attacked web service resilient to DDOSes at a low cost is quite a challenge.

Re: We are under attack

#144

Earlier quoted context omitted.

The bad ISP in question is the People's Republic of China.

I mean post the whole IP address list for public analysis.

Honestly most companies I've worked for have blocked the entire Chinese IP block. Obviously Chinese hackers can use proxies but it honestly does cut out a TON of problems. The downside of course is you will never get a Chinese customer/viewer. In preparing to respond to this post I googled "China IP block" and pretty much every result was about how to configure .htaccess or iptables to block the entire country.

Re: We are under attack

#146
post #56

Earlier quoted context omitted.

Can you elaborate on why you think Akamai is horrible?

I've dealt with them in their CDN role on multiple occasions. They're the most abhorrent combination of incompetence and arrogance that I've ever met in the tech industry. They're the Oracle of the network world. Just don't waste your time on them. There's plenty better and cheaper CDNs nowadays. Leave Akamai to the Governments and MegaCorps, they deserve each other.

I am right there with you

Re: We are under attack

#147
post #36

Earlier quoted context omitted.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's…

Replying to my own comment (I'm too late to edit it).

My comment is about that concept in general, not about Cloudflare in particular. I don't pretend to know and won't judge Cloudflare based on one sentence taken out of context. For all I know they are excellent members of the community; in fact they could do be doing good things behind the scenes without publicizing it, which might be wise if they are as exposed to China as other commenters say.

Re: We are under attack

#149
post #131

Earlier quoted context omitted.

> There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves. It's not just a popular idea, it's why they are created as firms instead of philanthropies. There is a difference and it does matter what the expectations of the donors/investors are. > We're a tech company whose success is completely dependent on the freedoms in our nation... This sounds great but how is it refle…

Everyone has a responsibility to the world around them. It may not be coded into law, but it is still a true statement.

Not sure how you thought my sentiments disagree with that.

Re: We are under attack

#150
post #36

Contact Akamai who recently bought the DDOS mitigation service Prolexic. They may be able to mitigate the attack and save you bandwidth costs. Alternatively, call CloudFlare. Don't just absorb this through Amazon.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

Historically Cloudflare have been quite strong in their support for free speech. For example, they run Project Galileo to protect public-interest sites against DDOS attacks: https://www.cloudflare.com/galileo

I'm guessing in this case it's simply a case of them choosing which battles to fight. They probably don't want to commit to run an open proxy for everyone in China to access banned websites. That would likely get them banned outright in China, which, for a CDN like Cloudflare, would really hurt their core business.

Post reply on HN