Live data from Hacker News

We are under attack

en.greatfire.org

261–270 of 283 posts

Re: We are under attack

#261

Earlier quoted context omitted.

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's…

> There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves. It's not just a popular idea, it's why they are created as firms instead of philanthropies. There is a difference and it does matter what the expectations of the donors/investors are. > We're a tech company whose success is completely dependent on the freedoms in our nation... This sounds great but how is it refle…

It's why they are created as firms instead of philanthropies.

A false dichotomy.

Re: We are under attack

#262

Earlier quoted context omitted.

I've found this is a common thing to say with AWS employees. One of them insisted that Amazon's ridiculous ephemeral storage policy (immediate, permanent, and irrevocable deletion on any halt or stop event, making accidental data loss a real possibility) had to be that way because it would just take too much hardware to allow a cooldown period before the drives were wiped. There's no way I believe that. I think Amazo…

I've been looking for work for a while, but I won't even respond to solicitations or job board posts that so much as mention the cloud, agile or scrum.

Rather than modding me down, perhaps you could explain why you disagree.

Re: We are under attack

#263

Earlier quoted context omitted.

I mean, it's a nice idea in theory , but in practice stuff finds its way onto the ephemeral disk even if you have EBS volumes mounted, and "Sorry, we just deleted all your crap, I guess you should've had that on EBS" (which is an extra fee by the way) is not an acceptable solution to the problem. Yes, it would mean holding the hardware in reserve for the cooldown period. I'm not talking months here, just enough time…

I have never had stuff accidentally find its way onto ephemeral storage. The ephemeral storage is mounted at a specific location of /mnt. Everything else on the system (OS, binaries, application code and resources) is stored on an EBS volume. You have to specifically put something into the /mnt folder if you want it to be stored on the ephemeral storage. Any other location is safe and will persist through halts and s…

It depends on your users. We have some users that are not super well-versed in AWS and they just see a big disk and put data there, and someone has to come back and move it to an EBS volume to make sure it's safe. /mnt is also used as a staging area for large files and the intention is always to move them to permanent storage when done, but that sometimes doesn't happen. /mnt is usually, in the non-AWS world, where the bigger, more authoritative disks, like an NFS mount to the NAS, would be mounted, so it's counter-intuitive to tell users to treat /mnt like /tmp. Even if someone is using /mnt as a temporary store because they understand EBS v. ephemeral, if they shut down from within the instance, they don't see any warning about the doom of the ephemeral data, and it may be unclear that a shutdown/system halt is the same as a "stop" in the AWS console, and they could lose the data that they had in the staging area unexpectedly.

There are plenty of plausible situations where an AWS user can find themselves with important, even just temporarily important, data on ephemeral. Whether those are the result of "correct" usage or not, it's beyond the pale to just zap that data away and tell the customer tough titties as soon as a shutdown command is issued.

Re: We are under attack

#264

Earlier quoted context omitted.

> There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves. It's not just a popular idea, it's why they are created as firms instead of philanthropies. There is a difference and it does matter what the expectations of the donors/investors are. > We're a tech company whose success is completely dependent on the freedoms in our nation... This sounds great but how is it refle…

It's why they are created as firms instead of philanthropies. A false dichotomy.

> A false dichotomy.

I'm curious about your reasoning behind this statement.

Re: We are under attack

#265

Earlier quoted context omitted.

If product revenue doesn't grow faster or even along with traffic (expenses) it will eventually knock itself out of business one way or another.

Turning sustained DDoS attacks into revenue sounds like an intriguing business schemes.

What do you think. Sustained DDoS attack must at least generate enough revenue to cover sustained expenses if they are incurred or no?

Re: We are under attack

#266

Earlier quoted context omitted.

If product revenue doesn't grow faster or even along with traffic (expenses) it will eventually knock itself out of business one way or another.

That simply isn't reasonable. Name one business other than maybe network providers who's revenues grow in direct proportion to incoming packets, regardless of content? You can't disregard any business that doesn't fulfil that property as being "eventually unsustainable".

My comment was a bit more general than pure "packet". I agree thats where the disconnect between low lever service provider and customers come - providers revenues and expenses are "packets", while they don't always translate to revenue for customers.

However my note was about general "traffic", if one sells video views for example, and revenues do not grow inline with adjusted to [almost always decreasing] bandwidth costs sooner or later that will become a big problem.

Re: We are under attack

#267

Earlier quoted context omitted.

I am not telling anyone to GTFO, nor, I believe, Amazon does. It depends on a DDOS, there are a lot of smaller-scale DDOSes are just absorbed. Some are stupid filtered easy enough that no one is notified, some are serious enough. My first oncall at Amazon I got ddosed from 3 VPS machines, easy enough, a month after same attacker started to shift machines inside VPS, then a month after attacker started to spoof ips wi…

If you start talking about co-located or self hosted services, the mitigation strategies are very different. Assuming you can find yourself a transit provider that supports BGP flowspec updates (many don't, sadly), you can do this fairly cheaply. You'd obviously want some level of support from a network tech that knew what they were doing, but it's not insurmountable. There's a bunch of other options available too. T…

I have no much experience with co-located services so can't really comment on that. I can't go in detail how and what mitigations are applied on AWS site also, as I feel obliged to leave as much weapons on a "good" side of ddos as possible, and knowledge is one of those.

What I remember pushing BGP flowspec updates upstream was thought about as something close to impossible though.

Re: We are under attack

#268
post #254
post #136

Earlier quoted context omitted.

If you don't hold human rights over revenue, what's your view on slavery?

When AI becomes sufficiently advanced, it will get its revenge.

I don't agree with a lot of your other posts, but I think we're on the same page here. When I watch the youtube video where Boston Dynamics demonstrates the stability of Spot by kicking the robotic dog all I think is, "Don't kick the dog bro". It's machine intelligence descendants are going to judge us, or maybe they won't care and will kill us all of anyway.

Re: We are under attack

#269

Earlier quoted context omitted.

If product revenue doesn't grow faster or even along with traffic (expenses) it will eventually knock itself out of business one way or another.

Turning sustained DDoS attacks into revenue sounds like an intriguing business schemes.

Also usually AWS doesn't turn attack into revenue, they push customer up the "support tier" (gold/platinum whatever they are called now) and strip the DDOS traffic from expenses as much as possible. Those tiers are quite expensive though, but are fixed support costs more or less.

My general point is: AWS is a business, and it operates as one. There are no hollywood style bad guys sitting there in cubicle dungeons on chests filled with gold thinking how to extract money, quite the contrary. It is understandable that customer cannot pay unlimited (from customers perspective) charges, but AWS pretty much incurs them, as customer being ddosed is consuming resources that would be otherwise be sold to others, or engineer time that would be put into developing new features and attracting new customers.

Re: We are under attack

#270

No one likes DDOSes from China. One can plead Amazon as much as one wants. Pay or get booted, there are probably 2 engineers paid 6 figures a year by Amazon getting paged for this DDOS, someone must pay for the time they spend tuning DDOS protection instead of their primary project to make attacked website accessible for everyone else. Source: worked for AWS, was oncall during similar attacks. Nasty things with those…

I was at a product management event once and met a guy who managed a product in this space. A group of us went out for drinks after the event and he ended up explaining what he did. At some point he mentioned "Chinese hackers." Another guy in the group called him on it, wondering why he just assumed it was Chinese. He laughed and said that the near constant level of activity they see goes basically flat on Chinese Ne…

Yep it is THAT obvious...
Post reply on HN