Live data from Hacker News

We are under attack

en.greatfire.org

221–230 of 283 posts

Re: We are under attack

#221

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Thanks for sharing this info. Prices are really unbelievable.

Re: We are under attack

#222
post #198

Earlier quoted context omitted.

Wow, I haven't done dedicated hosting in a long time, the prices are insane there! https://www.ovh.com/us/dedicated-servers/enterprise/2014-MG-... Thanks for posting :-) I've been looking for provider possibilities for my next failed startup. I'm not sure how they can deliver for that price but who am I to complain!

If you don't need the latest hardware and enterprisey features, give soyoustart.com a look. It's an OVH company on same network with same DDOS protection that uses the 'OVH' brand recycled servers. About half the cost. And if you don't need any support or server hardware, give kimsufi a look. I do not work for OVH, but am so impressed by their automation and value in this field I refuse to use anyone else.

I am just wondering how can one know about such sites. I always thought the DO is one of the cheapest.

Re: We are under attack

#223
post #189

Earlier quoted context omitted.

Good luck DDoSing ReCAPTCHA, I'll wait

Greatfire is unique that they want the site to remain accessible to ordinary Chinese users while withstanding the DDoS attack (so they can't blackhole all traffic from China either). If they put a reCAPTCHA wall in front, the GFW can simply block reCAPTCHA (easy -- it is a Google property and they block everything else from Google anyway) and no one from China can access Greatfire without a VPN. Mission accomplished.

Assuming the attacker is indeed China:

If the goal was only to block Greatfire for non-VPN users, then they could just use the GFW for that from the start. The use of a DDoS can only imply that China wants the site offline for everyone, even VPN users.

Re: We are under attack

#224

Earlier quoted context omitted.

Greatfire is unique that they want the site to remain accessible to ordinary Chinese users while withstanding the DDoS attack (so they can't blackhole all traffic from China either). If they put a reCAPTCHA wall in front, the GFW can simply block reCAPTCHA (easy -- it is a Google property and they block everything else from Google anyway) and no one from China can access Greatfire without a VPN. Mission accomplished.

Assuming the attacker is indeed China: If the goal was only to block Greatfire for non-VPN users, then they could just use the GFW for that from the start. The use of a DDoS can only imply that China wants the site offline for everyone, even VPN users.

I think Greatfire is evading the GFW by hiding their mirrored content behind innocent looking websites such that the GFW does not block it. Once the censors discovers a Greatfire node, they block it, but then Greatfire just moves on to another IP address or domain name.

With this DDoS, they are taking the different route of attacking the infrastructure of Greatfire such that they can't serve traffic from China at all. Causing massive bills and outages for Greatfire is probably a bonus, but I don't think that is their main intention.

Re: We are under attack

#225
post #176

Earlier quoted context omitted.

If normal citizens had access to a VPN in which to access this site from another country, it would be quite redundant to use this site then wouldn't it? Maybe I'm not understanding.

If normal citizens have access to it without a VPN, then why doesn't China just block it with the firewall instead of ddosing? Maybe I'm not understanding.

From a source close to some organizations that tune/develop the chinese firewall (spoiler alert: public universities), they are adopting methods to trigger reversed censorships. And in my eyes, these methods, despite less technical challenging, are working as intended. Also, see this: http://furbo.org/2015/01/28/grass-mud-horse/

Re: We are under attack

#226
post #36

Earlier quoted context omitted.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's…

You forgot that their success is also built on the oppression of the Chinese, and low salaries etc that gives the rest of the world affordable hardware (and rare-earth minerals, metals, etc).

Not commenting on what CloudFare should or should not do, just indicating that your high horse actually has longer legs than you gave it credit for.

Re: We are under attack

#227

Earlier quoted context omitted.

Interesting when your product can be spiked, and make significant increases in profit. This looks like numbers that could potentially knock a business out of business. Reminds me of old phone bills.

If product revenue doesn't grow faster or even along with traffic (expenses) it will eventually knock itself out of business one way or another.

Turning sustained DDoS attacks into revenue sounds like an intriguing business schemes.

Re: We are under attack

#228

Earlier quoted context omitted.

This is the exact opposite of my interactions with Akamai.

My experience with them was exactly the same as OP. Wanted us to bring buckets of cash for 10-100TB of bandwidth. Went with CacheFly, super satisfied.

Could you define buckets of cash? On the low end, one gets 30TB/month (1gbps uplink, 200mbs guaranteed) included for ~60 Euro a month, or 100TB for ~160 Euro (for a single server, outbound) at Hetzner:

https://www.hetzner.de/gb/hosting/produkte_rootserver/ex60

Such a single server, isn't the same as a CDN of course, just curious what you consider "buckets of cash". I see cachefly asks for 400 USD for 2/TB a month, for comparison.

Re: We are under attack

#229

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

"Unlimited" bandwidth? What kind of uplink is it, and will they really let you max it 24/7? Honest question, not trying to troll.

(1gbps ~ 300 TB, 100mbit ~30TB/month)

Re: We are under attack

#230

Earlier quoted context omitted.

Wow, I haven't done dedicated hosting in a long time, the prices are insane there! https://www.ovh.com/us/dedicated-servers/enterprise/2014-MG-... Thanks for posting :-) I've been looking for provider possibilities for my next failed startup. I'm not sure how they can deliver for that price but who am I to complain!

I think the reason they can offer it so cheap is a combination of scale, cheap electricity, and tax breaks. iWeb is also in Quebec, so I figured there must be some tax break. Lo and behold there is one heck of a tax break: http://www.investquebec.com/quebec/en/financial-products/smb... Basically the Quebec government pays 24% of your company's wages, up to $83,333 per employee!

Whops, I think you got a downvote. Tiny buttons...
Post reply on HN