I've been saying for years that AWS has secret DDOS protection. Never confirmed, but I'm pretty sure the basic level is just them admitting that they've always had that service.
AWS Shield – Managed DDoS Protection
71–79 of 79 posts
Re: AWS Shield – Managed DDoS Protection
#72Earlier quoted context omitted.
How often are people on a budget the target of serious ddos attacks?
Pretty often, especially in the realm of journalism (Wikileaks et al) and especially in network-security journalism. (Imagine writing exposés about botnet-owners. Imagine what kind of DDoS results from that.)
Re: AWS Shield – Managed DDoS Protection
#73So credits are limited to specific services > usage spikes on Elastic Load Balancing (ELB) If traffic has reached the load balancer than it's probably reached your app. No ec2 / storage / traffic credits here. > Amazon CloudFront Neat. Like cloudflare but with less features though. > or Amazon Route 53 DNS... Not really sure what to make of this one.
You only have to think back a couple of weeks to recall the DDos that took down Dyn:
https://news.ycombinator.com/item?id=12759697
DDos attacks DNS servers are pretty common, not least because a lot of hosting companies regard DNS as low priority.
I have an interest in Amazon's DNS setup, as I use it to provide my own git-based DNS hosting " rel="nofollow">https://dns-api.com> so I'll be curious to see how this works in practice myself.
Re: AWS Shield – Managed DDoS Protection
#74Earlier quoted context omitted.
How often are people on a budget the target of serious ddos attacks?
Pretty often, especially in the realm of journalism (Wikileaks et al) and especially in network-security journalism. (Imagine writing exposés about botnet-owners. Imagine what kind of DDoS results from that.)
Re: AWS Shield – Managed DDoS Protection
#75Hetzner has this for quite a while now.
The problem is that the whole Hetzner network is only 1.4tbit/s. Recent attacks were large than that and would've likely saturated their network.
Disclosure: I work at Google Cloud (but not in networking / would know the answer)
[1] https://www.lowendtalk.com/discussion/70274/hetzner-new-ex41...
Re: AWS Shield – Managed DDoS Protection
#76Earlier quoted context omitted.
The problem is that the whole Hetzner network is only 1.4tbit/s. Recent attacks were large than that and would've likely saturated their network.
Source? When I search for 'hetzner tbps' I only see one unsubstantiated forum post claiming 1.2 Tbps [1]. There are other reports about new peering arrangements, submarine cables, etc. so I'm curious if you have something more concrete. Disclosure: I work at Google Cloud (but not in networking / would know the answer) [1] https://www.lowendtalk.com/discussion/70274/hetzner-new-ex41...
[1] https://www.hetzner.de/en/hosting/unternehmen/rechenzentrum
Re: AWS Shield – Managed DDoS Protection
#77> AWS Shield Advanced comes with “DDoS cost protection”, a safeguard from scaling charges as a result of a DDoS attack that cause usage spikes on Elastic Load Balancing (ELB), Amazon CloudFront or Amazon Route 53. If any of these services scale up in response to a DDoS attack, AWS will provide service credits for charges due to usage spikes. This is a very big deal!
Not really. Now your $1K DDOS bill is a $1K AWS credit. Hardly any better. AWS desperately needs a way to turn off pay-by-use services through billing alerts. I don't believe this is possible right now.
Re: AWS Shield – Managed DDoS Protection
#78Earlier quoted context omitted.
I am surprised to hear someone saying anything positive about Hetzner. My only experience with them was a nightmare with terrible support and very inconsistent network performance.
I've never heard anything bad about them Been a Hetzner customer for years now