Live data from Hacker News

AWS Shield – Managed DDoS Protection

aws.amazon.com

71–79 of 79 posts

Re: AWS Shield – Managed DDoS Protection

#71
post #4

I've been saying for years that AWS has secret DDOS protection. Never confirmed, but I'm pretty sure the basic level is just them admitting that they've always had that service.

Most DOS/DDOS attacks you need to stop as soon as possible, so the kit to do it has to be on the edge, and they don't want to be doing 'who is this for and what plan are they on' provisioned onto all of their edge kit - they may as well just nuke everything that looks bad.

Re: AWS Shield – Managed DDoS Protection

#72
post #48

Earlier quoted context omitted.

How often are people on a budget the target of serious ddos attacks?

Pretty often, especially in the realm of journalism (Wikileaks et al) and especially in network-security journalism. (Imagine writing exposés about botnet-owners. Imagine what kind of DDoS results from that.)

Yes and Amazon is the company to go running to if you are doing things that the establishment does not like. I don't think so.

Re: AWS Shield – Managed DDoS Protection

#73

So credits are limited to specific services > usage spikes on Elastic Load Balancing (ELB) If traffic has reached the load balancer than it's probably reached your app. No ec2 / storage / traffic credits here. > Amazon CloudFront Neat. Like cloudflare but with less features though. > or Amazon Route 53 DNS... Not really sure what to make of this one.

> DNS... Not really sure what to make of this one.

You only have to think back a couple of weeks to recall the DDos that took down Dyn:

https://news.ycombinator.com/item?id=12759697

DDos attacks DNS servers are pretty common, not least because a lot of hosting companies regard DNS as low priority.

I have an interest in Amazon's DNS setup, as I use it to provide my own git-based DNS hosting " rel="nofollow">https://dns-api.com> so I'll be curious to see how this works in practice myself.

Re: AWS Shield – Managed DDoS Protection

#74
post #48

Earlier quoted context omitted.

How often are people on a budget the target of serious ddos attacks?

Pretty often, especially in the realm of journalism (Wikileaks et al) and especially in network-security journalism. (Imagine writing exposés about botnet-owners. Imagine what kind of DDoS results from that.)

Brian Krebs is basically who you're talking about. https://krebsonsecurity.com/

Re: AWS Shield – Managed DDoS Protection

#75
post #23
post #16

Hetzner has this for quite a while now.

The problem is that the whole Hetzner network is only 1.4tbit/s. Recent attacks were large than that and would've likely saturated their network.

Source? When I search for 'hetzner tbps' I only see one unsubstantiated forum post claiming 1.2 Tbps [1]. There are other reports about new peering arrangements, submarine cables, etc. so I'm curious if you have something more concrete.

Disclosure: I work at Google Cloud (but not in networking / would know the answer)

[1] https://www.lowendtalk.com/discussion/70274/hetzner-new-ex41...

Re: AWS Shield – Managed DDoS Protection

#76
post #75
post #23

Earlier quoted context omitted.

The problem is that the whole Hetzner network is only 1.4tbit/s. Recent attacks were large than that and would've likely saturated their network.

Source? When I search for 'hetzner tbps' I only see one unsubstantiated forum post claiming 1.2 Tbps [1]. There are other reports about new peering arrangements, submarine cables, etc. so I'm curious if you have something more concrete. Disclosure: I work at Google Cloud (but not in networking / would know the answer) [1] https://www.lowendtalk.com/discussion/70274/hetzner-new-ex41...

They state it on their homepage, it's 1.46Tbps [1]. They upgraded a bit recently, still too small to handle attacks that are unfortunately common nowadays. I don't have numbers for OVH, but they should be closer to 5-10Tbps, as they stated that their scrubbing centres will be able to handle 5Tbps in the next months.

[1] https://www.hetzner.de/en/hosting/unternehmen/rechenzentrum

Re: AWS Shield – Managed DDoS Protection

#77
post #14
post #8

> AWS Shield Advanced comes with “DDoS cost protection”, a safeguard from scaling charges as a result of a DDoS attack that cause usage spikes on Elastic Load Balancing (ELB), Amazon CloudFront or Amazon Route 53. If any of these services scale up in response to a DDoS attack, AWS will provide service credits for charges due to usage spikes. This is a very big deal!

Not really. Now your $1K DDOS bill is a $1K AWS credit. Hardly any better. AWS desperately needs a way to turn off pay-by-use services through billing alerts. I don't believe this is possible right now.

Billing alerts are Cloudwatch alarms, capable of queueing SNS events. You can use those to scale down.

Re: AWS Shield – Managed DDoS Protection

#78
post #41

Earlier quoted context omitted.

I am surprised to hear someone saying anything positive about Hetzner. My only experience with them was a nightmare with terrible support and very inconsistent network performance.

I've never heard anything bad about them Been a Hetzner customer for years now

Most of the histories about Hetzner I've read could be divided to PEBKAC and Service Information is tl;dr problems.
Post reply on HN