Live data from Hacker News

Linode is suffering on-going DDoS attacks

status.linode.com

121–130 of 186 posts

Re: Linode is suffering on-going DDoS attacks

#121
post #75

Earlier quoted context omitted.

I have a hard time imagining how supporting multiple providers would cost millions of dollars per year. I think it's a worthwhile way to make your software and infrastructure more resilient. And it protects you from vendor lock-in. As long as you keep things simple and don't use features that are only implemented by one provider, VMs are basically interchangeable.

Do you run Postgresql, MySQL, or something else? What led you to your choice? Because one is inherently better than the others for what you want to do? That's why you stick with a single cloud provider. You want the vendor lock-in. You go whole hog into using everything that they provide. Once you start mixing and matching the best of breed across cloud providers, you've lost. Once you start coding to the least commo…

Based on your other comments on this thread, you seem to have real expertise in operating this kind of infrastructure. Nevertheless, this particular comment makes no sense to me; I'm not even sure if you're serious.

It does make sense to standardize on one open-source database package (MySQL in the case of my employer). But that's software that I can take with me anywhere. And it's open-source. So the risks of vendor lock-in don't apply.

> Otherwise, why are you running stuff in the cloud anyway?

How does it follow that if I don't lock myself into one cloud provider all the way, it's not worthwhile to use the cloud at all? Maybe using cloud providers is worthwhile simply because, at a certain scale, they're less expensive than leased dedicated servers, never mind the up-front cost of buying and colocating hardware. Also, it's easy to provision cloud VMs on demand, then throw them away when you're done with them. Those are good reasons to use cloud providers without locking into just one.

It seems to me that the best approach is to use only the subset of features that are common to DigitalOcean, Vultr, and maybe Linode, and abstract over those multiple providers with software like Ansible that can access multiple provider APIs.

I am indeed suspicious of proprietary solutions for deploying and migrating across cloud providers, such as Cloud66. But that's only because using one of those solutions would itself be an instance of vendor lock-in. If there were an open-source package with similar functionality to Cloud66, I would probably use it.

Re: Linode is suffering on-going DDoS attacks

#122

Strangely this whole thread convinced me to try Linode. Why? everyone keeps saying it's so cheap and I do A LOT of web crawling so I don't need 99.999% uptime

I use it for basic stuff, mainly for testing node apps, no high throughput. It's got a nice, simple management console. I don't like the fact that apt-get operations to set up your VM can blow your monthly quota pretty fast if you're not careful, but other than that, it's been fine. Periodically, they double everyone's bandwidth and storage for free; it's something to look forward to in another year or two... I hope.…

> I don't like the fact that apt-get operations to set up your VM can blow your monthly quota pretty fast if you're not careful

What are you talking about? From https://www.linode.com/pricing :

"Please note that all inbound traffic is free and will not count against your quota."

Re: Linode is suffering on-going DDoS attacks

#123
post #65

I would like to correlate the comments in this thread with past comments on every single article about AWS or GCE of the form "this is so expensive / complicated I run my boxes on Linode for half the price". DDoS protection is one of the things you pay for on the big clouds.

What DDoS protection does AWS provide? The only thing mentions on their webpage is autoscaling, more nodes, etc. In other words, AWS' DDoS protection strategy is to open up your wallet. About 6 months ago they did hire Jeff from BlackLotus. Given that timeline, I'd expect them to announce some sort of DDoS protection offering in the next few quarters. Edit to be more specific: AWS gets hit with a lot of DDoS attacks.…

Actually "Amazon CloudFront also has filtering capabilities to ensure that only valid TCP connections and HTTP requests are made while dropping invalid requests. This takes the burden of handling invalid traffic (commonly used in UDP floods, SYN floods, and slow reads) off your origin."

and

"By using multiple PoPs, Amazon CloudFront has the inherent ability to help mitigate against both infrastructure and some application layer DDoS attacks by dispersing the traffic across multiple locations."

source: https://d0.awsstatic.com/whitepapers/DDoS_White_Paper_June20...

Re: Linode is suffering on-going DDoS attacks

#124

I find this ironic because about 2 years ago I had a couple VMs with them that suffered CHRONIC DDoS attacks, all the time. I had to move my clients to a whole other platform. Linode, on the other hand, simply blamed us for supposedly causing the repeat DDoS attacks - one after another for months on end. They even got rather flippant with me exclaiming how "dumb" I was to not understand that is was MY problem apparen…

+1 for IP block DDOS'ing - last time I ran a Linode VM it was DDOS'd to smitheereens within half an hour of putting it up (and of course, without any notice that I was liable for overages...)

Re: Linode is suffering on-going DDoS attacks

#125
post #106

Earlier quoted context omitted.

OVH does VPS's and they have their own Anti-DDoS network setup that is pretty amazing: https://www.ovh.com/us/anti-ddos/

Interesting. What is "Multi-point Mitigation"? I know it mentions a few locations. I googled it and it just brings me back to that page. I wonder if any solution would shutdown a VM and then restart it on another host but that'd be really sucky in some situations like an app might not shutdown cleanly, or the app is in the middle of something like charging a credit card.

Multi-point just means that the traffic is going to flow to the nearest datacenter that hosts the VAC, gets filtered and checked and then traverses on to your system.

The goal is to spread the DDoS out over as many different bandwidth heavy locations as possible.

See the images at the bottom of this page:

https://www.ovh.com/us/anti-ddos/hoovering-up.xml

Re: Linode is suffering on-going DDoS attacks

#127
post #120

Earlier quoted context omitted.

What would be an effective alternative?

I’m a fan of OVH myself[1]. Heard good things about x4b.net as well. [1] https://news.ycombinator.com/item?id=10807392

If they're using the typical anti-DDoS mitigation equipment (usually Arbor) then they're almost certainly throwing out good traffic along with bad. AWS's approach of having an ingress pipe large enough to absorb DDoS traffic rates and allowing only valid HTTP requests to pass through the ELB is a superior solution, IMO.

Re: Linode is suffering on-going DDoS attacks

#128

Earlier quoted context omitted.

This type of action is what the people behind the DDOS attack are looking for. Its not Linode fault...

Thank you for being so understanding!

Assigning fault isn't productive. But as Linode customers, what are we to do? My trust in Linode's reliability is completely shot at this point. I filed a support ticket trying to get more information about the outage, and the response I got was absolutely worthless. No part of this has made me feel better about Linode at all.

AWS is so massive that they can just sustain most DDOSes, and they write real postmortems after attacks. They're not as fast as Linode, but what good is speed if my site is completely vulnerable to every botnet that decides to look Linode's way?

Re: Linode is suffering on-going DDoS attacks

#129
post #101
post #66

Earlier quoted context omitted.

Here's the email I received (many times) when someone sent a smallish 1Gbit/s DDoS to my digitalocean server: > Our system has automatically detected an inbound DDoS against your droplet named xyz with the following IP Address: xx.xx.xx.xx > As a precautionary measure, we have temporarily disabled network traffic to your droplet to protect our network and other customers. Once the attack subsides, networking will be…

I've received the same type of email multiple times from DigitalOcean and its extremely frustrating. With even the smallest of traffic spikes, DigitalOcean will detect it as a DDoS and immediately cut off your server for 3 hours. If even a typical ( I've used multiple VPS providers and dedicated-server providers and DO is absolutely the worst when it comes to DDoS policy.

That's why DigitalOcean isn't ready for production (unless hiding ip address behind, lets say, cloudflare is an option in your case) and that's why I decided not to use their services anymore.

Re: Linode is suffering on-going DDoS attacks

#130
post #120

Earlier quoted context omitted.

I’m a fan of OVH myself[1]. Heard good things about x4b.net as well. [1] https://news.ycombinator.com/item?id=10807392

If they're using the typical anti-DDoS mitigation equipment (usually Arbor) then they're almost certainly throwing out good traffic along with bad. AWS's approach of having an ingress pipe large enough to absorb DDoS traffic rates and allowing only valid HTTP requests to pass through the ELB is a superior solution, IMO.

Well, yeah, infinite resources are always the best DDoS solution ;)

Valid requests ≠ clean traffic. That just moves the attack couple of layers up.

Post reply on HN