Live data from Hacker News

We are under attack

en.greatfire.org

161–170 of 283 posts

Re: We are under attack

#161

You should trace the attackers by tracing back. Work with your upstream providers and mailing lists (NANOG) and publicly shame these attackers. Likely, they are spoofing addresses - validate that and make sure you let the network know where the spoofed traffic is sourcing from to follow BCP38 and BCP84, defined by RFCs 2827 and 3704.

Transit providers do not care. They make money on it, some people are using it legitimately, and they just don't care, for the most part. It's a well known problem. It might not hurt to mention it, but they know what they're doing.

Re: We are under attack

#162

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

You mean more than I already am paying them?

The two colo centers we've hosted in have always helped us with DDOS issues free of charge. Maybe that's not normal, but even a former employee telling us to GTFO looks bad on Amazon to me.

Re: We are under attack

#163

Contact Akamai who recently bought the DDOS mitigation service Prolexic. They may be able to mitigate the attack and save you bandwidth costs. Alternatively, call CloudFlare. Don't just absorb this through Amazon.

For the record WSJ does use Akamai already for many of it's static resources. These are mostly requests for things that can not be cached already in some way. (I'm sure the crew is looking for some additional ways now =) Source: I used to work on WSJ and now within a different division of Dow Jones.

Re: We are under attack

#164
post #154

Earlier quoted context omitted.

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source. I know you can do this on the server, using many different techniques. But this does not help a…

The point of their website is to make censored content available to Chinese users. China is attacking them to prevent Chinese people from reading the website. Your suggestion is to make the site unavailable to China. Do you see why it is not a solution? You are basically setting up a market for censorship-- the attack doesnt ever have to end-- depending on how much China is willing to pay to keep the website offline.

OTOH if the great firewall already blocks this site, wouldn't that mean normal Chinese citizens would access it through a VPN via another country?

Re: We are under attack

#165
post #162

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

You mean more than I already am paying them? The two colo centers we've hosted in have always helped us with DDOS issues free of charge. Maybe that's not normal, but even a former employee telling us to GTFO looks bad on Amazon to me.

[deleted]

Re: We are under attack

#166
post #124

Earlier quoted context omitted.

I think JEDEC is in the wrong here, though. Memory prefixes sound like SI prefixes, but they're not. That's clearly a bug.

I was unaware they had a monopoly on language usage. A byte is not an SI unit. Base2 is vastly more defensible and natural than base10. The real issue is that everyone in networking likes round base10 numbers divided over some arbitrary cesium fluctuations. This leads to 1GB / 1Gbps not being 8 seconds, which is confusing. But in JEDEC's and others defense: "why should I have to change, he's the one that sucks."

Because the "he" in question is the relevant standards authority.

Re: We are under attack

#167
post #164
post #154

Earlier quoted context omitted.

The point of their website is to make censored content available to Chinese users. China is attacking them to prevent Chinese people from reading the website. Your suggestion is to make the site unavailable to China. Do you see why it is not a solution? You are basically setting up a market for censorship-- the attack doesnt ever have to end-- depending on how much China is willing to pay to keep the website offline.

OTOH if the great firewall already blocks this site, wouldn't that mean normal Chinese citizens would access it through a VPN via another country?

If normal citizens had access to a VPN in which to access this site from another country, it would be quite redundant to use this site then wouldn't it? Maybe I'm not understanding.

Re: We are under attack

#168

Earlier quoted context omitted.

Actually the Prolexic product is one of the most innovative and effective one we've seen to date. DDoS attacks are not a commodity issue, you have to pay to play..Not sure how that makes Akamai horrible..

I can confirm that Akamai is a pain to deal with. Defense.Net as well. Cloudflare is what I would chose but they are siding with the Chinese gov't at this point.

Not sure what you're basing that statement on. Cloudflare very recently gave support to various parties involed in the pro-democracy movement in Hong Kong. They claimed to have weathered the largest DDoS in history in the process.

Re: We are under attack

#169
post #36

Earlier quoted context omitted.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

Forgive my outburst, and maybe this sentiment won't be well received given the context, but I just find it to be downright unpatriotic for a US company like CloudFlare to stand there saying things like what Matt Prince says in your quote, when someone comes under attack by an opposing nation state. Again, I realize this place isn't exactly a bastion for this kind of sentiment, but have some thought for freedom here,…

Patriotism is not a virtue, it's a pretty empty and meaningless value

Re: We are under attack

#170

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Wow, I haven't done dedicated hosting in a long time, the prices are insane there! https://www.ovh.com/us/dedicated-servers/enterprise/2014-MG-... Thanks for posting :-) I've been looking for provider possibilities for my next failed startup. I'm not sure how they can deliver for that price but who am I to complain!

"...for my next failed startup." Thanks for helping me give my sinuses a nice coffee rinse :)
Post reply on HN