Live data from Hacker News

Linode launches free DDoS protection

linode.com

71–80 of 182 posts

Re: Linode launches free DDoS protection

#71
post #36

Earlier quoted context omitted.

> mind share is still low. I can tell that - many people in this thread are using “AWS” as though it’s synonymous with “EC2”.

I assure you that the majority of users in these discussions is perfectly aware of the extent of the AWS ecosystem.

I like the AWS ecosystem but I wouldn't touch it for anything that doesn't pay me back for monthly rent.

I build things with consideration to platform and vendor lock ins. Kube, containers, etc have resolved many deployment issues for me. For other things like authentication, logs, database, analytics, cache, search etc. There is parse, elastic/solid, postgres, redis, logio, ackee etc

Obviously, there are still many spaces left which AWS cover but most applications don't need them. Compliance is a big hurdle for businesses which they pay for. For individuals experimenting, not so much.

Re: Linode launches free DDoS protection

#72
post #43

Nice. Apart from the security incident that took place long time ago, are there any reason why everyone is going straight to DO instead of Linode? For a long time Linode has had better features, performance and bandwidth. It wasn't until recently DO had Managed DB and many other additions. Linode's High Memory Plan also has much better Memory : CPU Ratio. Still waiting for their CDN, ( Not sure why they are not expos…

A lot of it was inertia. But after some recent bad experiences with DO, we're planning on giving competitors a try. Looks like Linode is just the ticket; thank you for pointing it out.

Careful: https://news.ycombinator.com/item?id=10845278

Re: Linode launches free DDoS protection

#73
post #2

I guess this is basically the same as OVH's "VAC" system? I sometimes get these emails: >We have just detected an attack on IP address x.x.x.x. In order to protect your infrastructure, we vacuumed up your traffic onto our mitigation infrastructure. The entire attack will thus be filtered by our infrastructure, and only legitimate traffic will reach your servers. and then: >We are no longer able to detect any attack o…

I’m curious, does anyone know what that means specifically? How can they differentiate normal traffic from malicious traffic? What exactly triggers it? Is a ping flood with a slow (50mbits) internet connect enough? I am aware that the details are mostly likely private to protect them from abuse and are also a trade secret but I have a very hard time to find a general approach that might be similar to their solution?

Linode support is fantastic and we host some critical infrastructure with them for this reason and have been happy for years. DO has the managed DB however so we've been migrating some services to them. If Linode offers a managed DB I'll move everything back.

Re: Linode launches free DDoS protection

#74
post #10

Serious question: why would I want to use Linode over GCP or AWS? Asking as someone who hasn’t really dabbled with smaller cloud providers. Is it cost? Support? Developer tooling?

Cost and ease of development by not throwing thousand of options in front of your screen. Last time, I checked GCP costed me $26 (+ hidden charges) for the same I could get on many other places for $7. Some of them provide instant customer support too and are better because it's not an outsourced customer center in India or other places. Check out: vultr: https://www.vultr.com Scaleway: https://www.scaleway.com/en/ O…

Also: UpCloud https://www.upcloud.com

Re: Linode launches free DDoS protection

#75
post #2

I guess this is basically the same as OVH's "VAC" system? I sometimes get these emails: >We have just detected an attack on IP address x.x.x.x. In order to protect your infrastructure, we vacuumed up your traffic onto our mitigation infrastructure. The entire attack will thus be filtered by our infrastructure, and only legitimate traffic will reach your servers. and then: >We are no longer able to detect any attack o…

I’m curious, does anyone know what that means specifically? How can they differentiate normal traffic from malicious traffic? What exactly triggers it? Is a ping flood with a slow (50mbits) internet connect enough? I am aware that the details are mostly likely private to protect them from abuse and are also a trade secret but I have a very hard time to find a general approach that might be similar to their solution?

Most probably they have DDoS appliances (i.e. Arbor, corero, etc) installed in their network. One of the implementation is they will redirect all customer traffic to this appliance. And then the appliance will get some sample of the traffic and match it with their attack fingerprints database. If matched they will block the traffic. For the good traffic they will let it go to its final destination.

Re: Linode launches free DDoS protection

#76
post #10

Serious question: why would I want to use Linode over GCP or AWS? Asking as someone who hasn’t really dabbled with smaller cloud providers. Is it cost? Support? Developer tooling?

Cost and ease of development by not throwing thousand of options in front of your screen. Last time, I checked GCP costed me $26 (+ hidden charges) for the same I could get on many other places for $7. Some of them provide instant customer support too and are better because it's not an outsourced customer center in India or other places. Check out: vultr: https://www.vultr.com Scaleway: https://www.scaleway.com/en/ O…

Also www.wowrack.com

Re: Linode launches free DDoS protection

#77
post #43

Nice. Apart from the security incident that took place long time ago, are there any reason why everyone is going straight to DO instead of Linode? For a long time Linode has had better features, performance and bandwidth. It wasn't until recently DO had Managed DB and many other additions. Linode's High Memory Plan also has much better Memory : CPU Ratio. Still waiting for their CDN, ( Not sure why they are not expos…

I am not sure how is it now but not that long ago there were slight differences in backup price and floating ips. If i remember on Linode backups cost almost twice than DO. On Vultr you had to pay for floating ip which you dont on DO.

Also from benchmarks ive seen Linode was inconsistent and overall not that faster than it looks on paper. Vultr was best in things like cpu performance but had slower networking. DO was just ok in any matrics.

If you add that DO has best admin panel, usually are first with most services like Spaces (which are not that amazing but OK) and sponsor lot of good content (tutorials, podcasts).

They are all similar services once you get one one of them there arent many reasons to switch. Like i looked into vultr high frequency compute for new service and then i realized i will have to deal with two invoices instead of one every month... so i just used DO:))

Re: Linode launches free DDoS protection

#78
post #64
post #39

Earlier quoted context omitted.

They are very likely real and OVH has a very good system. You can thank them for making free DDoS protection mainstream, dragging all other hosts kicking and screaming into providing DDoS protection. In the past providers like Linode were happy to just null route your IP for several hours/days or charge you thousands to block a small flood.

It wasn't just Linode (a provider that's generally much cheaper than OVH), but high end providers like Softlayer too (and, as far as I know, still are)

SoftLayer, now IBM Cloud, does not provide “DDOS Protection”. Their filtering service is only up to a certain amount, iirc max 5.5 Gbit or something like that. It is absolute trash and pretty much kills all traffic legitimate or not. If you’re filtered for more than 6-8 hours, they will just nullroute the IP. I’ve had the misfortune of hitting this every few months and it’s a major headache. If they remove you from the nullroute, and you land back on it, they won’t remove you again for 24 hours. A few months ago we hit a bug with their detection where it considered outbound to be the same as inbound, and produced some wildly off base numbers that made no sense. We’re not a small account, I’d say medium sized probably at this point, but I wanted to hop a plane to Dallas and strangle the techs there. It’s really gone downhill since IBM acquired them, and I dread to see how Red Hat fares...

If you ask for any estimated traffic size so you can go to a service that does do filtering for a living, they won’t give you that stating “nobody does”. It took a lot of time getting numbers out of them, and that finally finding a top level employee through our account manager was what led to them going “oh yikes, yeah something is off.” Sigh.

Re: Linode launches free DDoS protection

#79
post #43

Nice. Apart from the security incident that took place long time ago, are there any reason why everyone is going straight to DO instead of Linode? For a long time Linode has had better features, performance and bandwidth. It wasn't until recently DO had Managed DB and many other additions. Linode's High Memory Plan also has much better Memory : CPU Ratio. Still waiting for their CDN, ( Not sure why they are not expos…

Two things that made me migrate (mostly) to DO from Linode:

1. For a long time, Linode did not have a terrform provider 2. DO's managed Kubernetes offering Just Works, and is very competitively priced

FWIW, I still run a small Linode box. It's been rock-solid, and the support they provide is absolutely top-notch.

Re: Linode launches free DDoS protection

#80
post #76

Earlier quoted context omitted.

Cost and ease of development by not throwing thousand of options in front of your screen. Last time, I checked GCP costed me $26 (+ hidden charges) for the same I could get on many other places for $7. Some of them provide instant customer support too and are better because it's not an outsourced customer center in India or other places. Check out: vultr: https://www.vultr.com Scaleway: https://www.scaleway.com/en/ O…

Also www.wowrack.com

WowRack still has a notorious reputation for hosting spammers.
Post reply on HN