Live data from Hacker News

We are under attack

en.greatfire.org

241–250 of 283 posts

Re: We are under attack

#241
post #25

Earlier quoted context omitted.

Not sure that turning the light off is the first thing you want to do when you're bullied. And pretty certain that there's zero PR value in those stories.

They wouldn't just be giving in, it would take less than a day to get up and running on CloudFlare. That is probably worth avoiding $30k bill, especially for a non-profit. As for PR, there absolutely is good will towards organizations that take on censorship. This is the #1 story on HN, so a company stepping in and saying "we got this covered, free of charge" not only shows they are good people, but also gives would…

My reaction was based on the interview where they say that the 30k$ charge was harming, not killing them. You're more knowledgeable than me on CloudFlare and it may very well be a strong option.

Now in a way their $ penalty with this attack is not unlike growth. To me it sounds like they invested in their branding and will have a name as a company that can sustain damage and keep its ground - important because their goal is to be credible in bringing content in/out China.

What if they had given in? They'd be yet another victim of an attack sort of linked with China.

I do see a business sense behind what I assumed was their moral stance and I definitely stand by it.

Re: We are under attack

#242
post #155
post #136

Earlier quoted context omitted.

If you don't hold human rights over revenue, what's your view on slavery?

It's economically inefficient, as well as anti-human-rights?

Actually, there is some evidence that slavery was very economically efficient. 'The Half Has Never Been Told' by E Baptist lays out how enslaved labour picked much more cotton than the then free labour.

Re: We are under attack

#243
post #56

Earlier quoted context omitted.

Can you elaborate on why you think Akamai is horrible?

I've dealt with them in their CDN role on multiple occasions. They're the most abhorrent combination of incompetence and arrogance that I've ever met in the tech industry. They're the Oracle of the network world. Just don't waste your time on them. There's plenty better and cheaper CDNs nowadays. Leave Akamai to the Governments and MegaCorps, they deserve each other.

> "...They're the Oracle of the network..." That's a hilarious indictment of Akamai. lol... Its gotta be DEFCON 5 in their PR dept.

Re: We are under attack

#244

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

I was at a product management event once and met a guy who managed a product in this space. A group of us went out for drinks after the event and he ended up explaining what he did. At some point he mentioned "Chinese hackers." Another guy in the group called him on it, wondering why he just assumed it was Chinese. He laughed and said that the near constant level of activity they see goes basically flat on Chinese New Year.

I suppose if you're not a Chinese hacker, it might pay to pretend you are by tailoring your working hours and days.

Re: We are under attack

#245
post #56

Earlier quoted context omitted.

Can you elaborate on why you think Akamai is horrible?

I've dealt with them in their CDN role on multiple occasions. They're the most abhorrent combination of incompetence and arrogance that I've ever met in the tech industry. They're the Oracle of the network world. Just don't waste your time on them. There's plenty better and cheaper CDNs nowadays. Leave Akamai to the Governments and MegaCorps, they deserve each other.

From my experience, this is confusing the issue - the OP was talking about using their DDoS filtering service, not their CDN. This is done by Prolexic - who despite being acquired by Akamai, still seems to function fairly independently. I've no idea what the CDN team are like, but it's not really fair to say don't use product X from company Y, because product Z sucks.

We've tried a number of DDoS filtering services, and Proxleic/Akamai has been the most professional and effective so far. They're also the most expensive, by a fair bit, but you get what you pay for I guess.

Re: We are under attack

#246
post #162

Earlier quoted context omitted.

You mean more than I already am paying them? The two colo centers we've hosted in have always helped us with DDOS issues free of charge. Maybe that's not normal, but even a former employee telling us to GTFO looks bad on Amazon to me.

I am not telling anyone to GTFO, nor, I believe, Amazon does. It depends on a DDOS, there are a lot of smaller-scale DDOSes are just absorbed. Some are stupid filtered easy enough that no one is notified, some are serious enough. My first oncall at Amazon I got ddosed from 3 VPS machines, easy enough, a month after same attacker started to shift machines inside VPS, then a month after attacker started to spoof ips wi…

If you start talking about co-located or self hosted services, the mitigation strategies are very different.

Assuming you can find yourself a transit provider that supports BGP flowspec updates (many don't, sadly), you can do this fairly cheaply. You'd obviously want some level of support from a network tech that knew what they were doing, but it's not insurmountable. There's a bunch of other options available too.

This sort of thing is one of the downwsides of having your infrastructure managed by someone else. If things go wrong and your provider doesn't feel incentivised enough to help you out, there's a lot less you can do about it, other than just pay whatever sum they demand.

Re: We are under attack

#247

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

Why don't providers just set up a system that creates a country-level null route for a given destination IP? And have a UI with a checkbox for the user to do it, for any selected country. It would mitigate the issue, and once it's over, the user can un-restrict traffic / or just keep blocking if it's a non-valuable source. I know you can do this on the server, using many different techniques. But this does not help a…

DDoS come from hosts which are part of botnets, usually compromised hosts, from all over the world. Not one country or subnet.

Re: We are under attack

#248
post #152

Earlier quoted context omitted.

I was unaware they had a monopoly on language usage. A byte is not an SI unit. Base2 is vastly more defensible and natural than base10. The real issue is that everyone in networking likes round base10 numbers divided over some arbitrary cesium fluctuations. This leads to 1GB / 1Gbps not being 8 seconds, which is confusing. But in JEDEC's and others defense: "why should I have to change, he's the one that sucks."

The real problem is that mega/giga/tera/peta have well established uses meaning "factor or 10" for EVERYBODY except people talking about memory. Disk space even obeys this now even though it was only done by marketing so they could reduce the amount bits delivered while charging the same.

Trick question: How many bytes are in a 1.44MB floppy? In a 700MB CD? A 4GB USB stick? And a 480GB SSD? How many bytes/s bandwidth for 10Gb Ethernet?

I can't understand how people can be so delusional to think that randomly redefining prefixes is a good idea. It was never, ever used consistently, and JEDEC just should get rid of this idiocy.

Re: We are under attack

#249

Earlier quoted context omitted.

If you click on the day in the calendar to look at the details, the "Contradictory" status is when some of their test servers work and others don't. For this site in particular, there are several servers showing a timeout and no data received. So it's possible that HN is being partially blocked.

It looks specifically like cURL's exit value and the downloaded page size varied on some requests. It would be interesting to know what the contradictory download size was, and what the curl exit value was.

All that is there when you click on the date, if you scroll rightwards. The exit values in the blocked sites are timeouts (CURLE_OPERATION_TIMEDOUT), and the broken download sizes are 0 bytes.

Re: We are under attack

#250
post #199

Earlier quoted context omitted.

Not sure if it can handle the load...

http://conferences.sigcomm.org/sigcomm/2009/posters/sigcomm-...

Sure, the target will not be affected, but CoralCDN network will, and it will not be able to handle the load of the attack. They don't have enough resources.
Post reply on HN