Live data from Hacker News

Tor’s history of D/DoS attacks and future strategies for mitigation

forum.torproject.org

21–30 of 103 posts

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#22

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Don't forget OVH. Their DDoS-protection is included in every server.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#23

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Don't forget OVH. Their DDoS-protection is included in every server.

What do you mean every server? Pardon my ignorance, first time I am hearing about these folks.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#24

Earlier quoted context omitted.

Don't forget OVH. Their DDoS-protection is included in every server.

What do you mean every server? Pardon my ignorance, first time I am hearing about these folks.

OVH is a hosting provider, you rent physical or virtual servers from them for a monthly fee. They protect their entire network with DDoS mitigation.

https://www.ovhcloud.com/en/security/anti-ddos/ddos-attack-m...

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#25

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Don't forget OVH. Their DDoS-protection is included in every server.

If cloudflare won't touch you, chances are neither will OVH.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#26

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

A bit dramatic right? Sure, it might be more expensive and difficult but obviously you can run your own WAF, DDOS protection etc.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#27
post #7

Earlier quoted context omitted.

I prefer it over every forum I’ve used, especially on mobile.

One of the design goals of Discourse was that it should work well on mobile phones. I guess most other forum software is either from the time of before widespread smartphone use or it doesn't consider mobile users. With that being said, I actually don't like discourse's UI and prefer more classical forums like PHPbb.

Discourse goes a bit overboard with the javascript and all the bells and whistles but I don't understand how anybody could prefer PHPbb over it, other than familiarity. That being said I always found PHPbb abysmal to use, even in the early 2000, so clearly I'm biased.

My main issue with Discourse is that I prefer HN/Reddit-like threading for replies rather than linear comments, but PHPbb does the same and there are pros and cons for both formats anyway.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#28
post #15

Earlier quoted context omitted.

It really isn't that dire, AWS has Shield (or really just Cloudfront), GPC has Cloud Armor, Azure has "Azure DDoS Protection", everything on Digital Ocean is protected by default. And if you're on-prem or colo then even a modestly sized edge router can handle quite a bit of traffic. And if all you want is the CDN part and not origin protection then every commercial CDN does DDoS protection. If you mean "providing exp…

Not a question of money. If i recall, all of these are as easy to reach for governments as cloudfare itself. Especially with the threat of KYC. Would be happy to be wrong here though.

"If a government decides they want you offline" is quite a big difference from the original "Once you get kicked off Cloudfare, thats mostly it for you".

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#29

I think its worth mentioning that DDOS protection has become a tool to control online discourse. Once you get kicked off Cloudfare, thats mostly it for you if you have a determined attacker. Thats quite a beneficial situation for governments.

Don't forget OVH. Their DDoS-protection is included in every server.

At-least in my experience, OVH was the only hosting company where their network engineers spoke to me when we had a ddos problem.

Had a situation where one of my servers were getting ddosed we tried multiple providers both cloud and dedicated, but the attack was not getting stopped by anyone, the customer service was useless on most other places its either we get null routed, or hours of back and forth with customer service without any solution.

We moved our servers to OVH the customer service rep directed us to an engineer within a few minutes. I remember we had to send a few packet captures during an attack to one of their network engineers and, not only did they block the attack in a few hours, the engineer in charge explained exactly what happened was such a nice learning experience, that one interaction with them will always make me recommend them.

Re: Tor’s history of D/DoS attacks and future strategies for mitigation

#30
post #7

Earlier quoted context omitted.

I prefer it over every forum I’ve used, especially on mobile.

One of the design goals of Discourse was that it should work well on mobile phones. I guess most other forum software is either from the time of before widespread smartphone use or it doesn't consider mobile users. With that being said, I actually don't like discourse's UI and prefer more classical forums like PHPbb.

Working well on crappy toy devices = working shittily on actual computers

Smart watches should have taken off, so everything could have been made post stamp-sized to work well on them and become completely unusable on a screen larger than your hand.

Post reply on HN