Live data from Hacker News

We are under attack

en.greatfire.org

191–200 of 283 posts

Re: We are under attack

#191
post #53
post #20

Earlier quoted context omitted.

Serving a captcha page is more work than serving a static page.

You can block with firewall IPs of users, who didn't solve captcha. You will get only SYNs from incoming connection requests then.

You don't really understand the distributed part of DDoS. I've had services taken down my attacks and when doing a post mortem we could see the increase in traffic, but when accounting for frequency, our office was still the main user.

Re: We are under attack

#192
post #36

Earlier quoted context omitted.

CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re…

> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's…

Moreover, I'm not sure their argument makes sense even on its face. When they say they "comply with the law", which law do they mean? There are many thousands of lawmaking bodies. What if a small-town mayor passes a law outlawing the word "webinar"? What if China passes a law saying that DDOS protection is illegal worldwide? Or websites not properly registered with the Central Propaganda Department may not be carried by any network provider?

Cloudflare, I'm sure, will happily ignore any laws like that. The question is: why not ignore this too?

Re: We are under attack

#193

Earlier quoted context omitted.

I feel it shouldn't be unreasonable to expect AWS/Cloudflare/Akamai to have policy-based routing to blackhole a lot of these source subnets. Of course it's complex, but these are some of the largest hosting providers in the world.

I've found this is a common thing to say with AWS employees. One of them insisted that Amazon's ridiculous ephemeral storage policy (immediate, permanent, and irrevocable deletion on any halt or stop event, making accidental data loss a real possibility) had to be that way because it would just take too much hardware to allow a cooldown period before the drives were wiped. There's no way I believe that. I think Amazo…

I've been looking for work for a while, but I won't even respond to solicitations or job board posts that so much as mention the cloud, agile or scrum.

Re: We are under attack

#194
post #129

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

That sounds too good to be true. I guess after a 24/7 china DDoS their costs are higher than that and they ask for more.

I don't think it's too good to be true. They have over 2Tbps of unused inbound capacity (or at least they did in 2013, and probably more now), and their routers mitigate attacks at the boundary of their network.

Re: We are under attack

#195
post #164
post #154

Earlier quoted context omitted.

The point of their website is to make censored content available to Chinese users. China is attacking them to prevent Chinese people from reading the website. Your suggestion is to make the site unavailable to China. Do you see why it is not a solution? You are basically setting up a market for censorship-- the attack doesnt ever have to end-- depending on how much China is willing to pay to keep the website offline.

OTOH if the great firewall already blocks this site, wouldn't that mean normal Chinese citizens would access it through a VPN via another country?

The great firewall does already block this site, and I cannot view it now without turning on my VPN. Therefore this site is pretty useless to me currently, but someone has to fight the censorship. Maybe one day it will actually succeed?

Re: We are under attack

#197

Earlier quoted context omitted.

Actually the Prolexic product is one of the most innovative and effective one we've seen to date. DDoS attacks are not a commodity issue, you have to pay to play..Not sure how that makes Akamai horrible..

I can confirm that Akamai is a pain to deal with. Defense.Net as well. Cloudflare is what I would chose but they are siding with the Chinese gov't at this point.

Cloudflare didn't side with the Chinese govt. They sided against a group that was abusing their infrastructure.

Re: We are under attack

#198

Move to OVH -- they offer free DDoS protection as standard, and unlimited bandwidth. I just moved to OVH after getting DDoSed. I'm paying $109/month for a quad core 3.7Ghz Xeon, 64GB RAM, dual 2TB software RAID. It's a pretty sweet deal, and I haven't had any problems so far.

Wow, I haven't done dedicated hosting in a long time, the prices are insane there! https://www.ovh.com/us/dedicated-servers/enterprise/2014-MG-... Thanks for posting :-) I've been looking for provider possibilities for my next failed startup. I'm not sure how they can deliver for that price but who am I to complain!

If you don't need the latest hardware and enterprisey features, give soyoustart.com a look. It's an OVH company on same network with same DDOS protection that uses the 'OVH' brand recycled servers. About half the cost.

And if you don't need any support or server hardware, give kimsufi a look.

I do not work for OVH, but am so impressed by their automation and value in this field I refuse to use anyone else.

Re: We are under attack

#200
post #23

I think they need to use something similar to this ... http://en.wikipedia.org/wiki/Coral_Content_Distribution_Netw...

I would appreciate it if people who down voted my comment explained to me if it's because i'm wrong or because they don't understand what i am trying to say or just for the heck of it :).
Post reply on HN