Live data from Hacker News

Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

blog.cloudflare.com

11–20 of 20 posts

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#11
post #8

Earlier quoted context omitted.

The amount of work required to stand up 330 well connected locations and then operate infrastructure to filter traffic at that scale profitably is more than "tossing" cabinets at problems. This is on the level of BrandonM's famous comment on Dropbox. https://news.ycombinator.com/item?id=9224

Nah, not really. I know the amount of work standing up even 5% of that requires because I've been there, done that, have the sheet metal scars to prove it. It's a lot of effort. It's just not -hard-. After a while it's a copy-paste problem with it bottle-necking around the human: signing documents, waiting for tickets and whatnot, and it's pretty disingenuous to suggest it's not. And ooh, ooh, I can flippantly dismis…

Is your speculated 11.5gbit per location not a result of their system rather than something to look down on?

Yes, anyone can shove a bunch of network equipment into a bunch of cabinets.

No, not anyone can shove a bunch of network equipment into a bunch of cabinets and run a service like cloudflare on top of that.

And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?”

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#12
post #11

Earlier quoted context omitted.

Nah, not really. I know the amount of work standing up even 5% of that requires because I've been there, done that, have the sheet metal scars to prove it. It's a lot of effort. It's just not -hard-. After a while it's a copy-paste problem with it bottle-necking around the human: signing documents, waiting for tickets and whatnot, and it's pretty disingenuous to suggest it's not. And ooh, ooh, I can flippantly dismis…

Is your speculated 11.5gbit per location not a result of their system rather than something to look down on? Yes, anyone can shove a bunch of network equipment into a bunch of cabinets. No, not anyone can shove a bunch of network equipment into a bunch of cabinets and run a service like cloudflare on top of that . And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?”

> And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?”

Actually quite a few more than that, but yes.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#14
post #11

Earlier quoted context omitted.

Is your speculated 11.5gbit per location not a result of their system rather than something to look down on? Yes, anyone can shove a bunch of network equipment into a bunch of cabinets. No, not anyone can shove a bunch of network equipment into a bunch of cabinets and run a service like cloudflare on top of that . And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?”

> And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?” Actually quite a few more than that, but yes.

Then you must know how terrible that argument is

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#15
post #14

Earlier quoted context omitted.

> And is your argument really “I’ve spun up 16.5 PoP locations before, so I know what I’m talking about?” Actually quite a few more than that, but yes.

Then you must know how terrible that argument is

Who cares about justifying an argument to an internet forum when all that cash is being dropped in my account.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#16
post #14

Earlier quoted context omitted.

Then you must know how terrible that argument is

Who cares about justifying an argument to an internet forum when all that cash is being dropped in my account.

You do, given your replies and initial post.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#17
post #7

I worry that CF has perverse incentives

What "perverse incentives" do you think they have? They have a product. This is marketing for that product. The incentive is to make money. It's very clear imo.

CF sells treatment, not cure, for ddos. They are a major player in internet technology.

I presume that fora exist for players to discuss blue-team strategy, and that decisions are nuanced and detailed. If so, there's a lot of leeway to pursue a hidden agenda.

I'm not so concerned about what their doing now. It's about in a few years, when stock isn't as strong and MBAs are parachuted in to perk up the bottom line.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#18
post #17

Earlier quoted context omitted.

What "perverse incentives" do you think they have? They have a product. This is marketing for that product. The incentive is to make money. It's very clear imo.

CF sells treatment, not cure, for ddos. They are a major player in internet technology. I presume that fora exist for players to discuss blue-team strategy, and that decisions are nuanced and detailed. If so, there's a lot of leeway to pursue a hidden agenda. I'm not so concerned about what their doing now. It's about in a few years, when stock isn't as strong and MBAs are parachuted in to perk up the bottom line.

How do you suggest CloudFlare "cure" DDoS? Wouldn't that mean finding the people who make the decision to do this and physically stop them? They're a CDN not the Mafia.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#19
post #17

Earlier quoted context omitted.

CF sells treatment, not cure, for ddos. They are a major player in internet technology. I presume that fora exist for players to discuss blue-team strategy, and that decisions are nuanced and detailed. If so, there's a lot of leeway to pursue a hidden agenda. I'm not so concerned about what their doing now. It's about in a few years, when stock isn't as strong and MBAs are parachuted in to perk up the bottom line.

How do you suggest CloudFlare "cure" DDoS? Wouldn't that mean finding the people who make the decision to do this and physically stop them? They're a CDN not the Mafia.

I never suggested anything so simplistic.

Imagine some replacement for tcp is proposed and a working group is set up to develop it. A member of that group might advocate for or against features. You could take the position "we should not include Feature X because it will have a performance impact in Scenario Y".

Scenario Y may or may not be real, but it doesn't matter, because you're using it as a stalking horse to get the outcome you actuality want, which happens to be defeated by Feature X.

The other group members know what you're up to, but they can't prove it because you have plausible deniability. They can't kick you out of the group because you serve 20% of the web.

To reiterate, I have no allegations to level against Cloudflare. I think it's a useful heuristic to assume that a public company, given sufficient market power, will become evil. CF has the market power.

Re: Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack

#20
post #19

Earlier quoted context omitted.

How do you suggest CloudFlare "cure" DDoS? Wouldn't that mean finding the people who make the decision to do this and physically stop them? They're a CDN not the Mafia.

I never suggested anything so simplistic. Imagine some replacement for tcp is proposed and a working group is set up to develop it. A member of that group might advocate for or against features. You could take the position "we should not include Feature X because it will have a performance impact in Scenario Y". Scenario Y may or may not be real, but it doesn't matter, because you're using it as a stalking horse to g…

> Imagine some replacement for tcp is proposed

No need to imagine, QUIC exists.

Like every technology since 1980, it's unlikely to supplant Ethernet and TCP/IP, but it's the most successful effort yet.

SCTP also solves the problem of TCP-based DDOS because the client must participate in the handshake.

Good luck convincing all existing network software to switch to these protocols. I would like that too but it won't happen.

Post reply on HN