Live data from Hacker News

DDoS protection

wiki.hetzner.de

81–90 of 175 posts

Re: DDoS protection

#81
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

what the heck:

    VPS VC1 S - €2.99 /month
    2 x86 cores	2 GB	200 Mbit/s	50 GB SSD
That is really cheap.

Re: DDoS protection

#82
post #66

Earlier quoted context omitted.

Yeah, but they've also the "Wifi Captive Portal" of the internet, which frequently creates trouble (if you're using Tor for example).

Tor is used for abuse. If you want the privacy* you get with Tor the price you pay is that sites and services will check that you're not one of the abusers. At least it's not a flat-out ban. Any other large network on such a small IP space (as an example maybe a NAT-using mobile ISP) would be checked just as harshly. * Or any other reason you're using it. Edit: If I'm wrong can you please reply explaining why? I'm ha…

that's a pretty poor excuse. why is privacy only available by submitting to a poor experience? privacy should be default, not a punishment

Re: DDoS protection

#83
post #61

Earlier quoted context omitted.

I think their work is fantastic, but I really don't like that every site I visit meets me with CF's captcha page. It's not only annoying per se, but the privacy implications are unsettling. I welcome the competition.

This was never the intention. Part of the problem is inertion - cf operates large and complex application that was designed back when we had only a handful of customers. Part of the problem is technical - the privacy-centric anti-abuse technologies don't exist yet. Please do help us fix this. Report issues, help us understand when we have incorrect IP reputation. Help us find captcha accessibility problems. And maybe…

Problem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.

Re: DDoS protection

#84

We used to run some basic infrastructure on Hetzner. The support was appalling – any requests for help were swiftly met with short answers such as "Unfortunately we can not help you here". That makes me question how responsive and understanding Hetzner's staff will be in case of an on-going DDoS that their automated systems are unable to detect and take care of. What sort of scenario would benefit from the announced…

> People are surely not running websites on commodity hardware.

That actually is such a growing trend that one of the more popular NoSQL databases is called...

Cluster Of Unrealiable Commodity Hardware Database,

aka CouchDB.

Re: DDoS protection

#85
post #66

Earlier quoted context omitted.

Tor is used for abuse. If you want the privacy* you get with Tor the price you pay is that sites and services will check that you're not one of the abusers. At least it's not a flat-out ban. Any other large network on such a small IP space (as an example maybe a NAT-using mobile ISP) would be checked just as harshly. * Or any other reason you're using it. Edit: If I'm wrong can you please reply explaining why? I'm ha…

that's a pretty poor excuse. why is privacy only available by submitting to a poor experience? privacy should be default, not a punishment

You're looking at it purely from the user side. Look at it from the admin side. Tor is basically a massive open proxy, and by blocking it or throwing up human checks like captchas, you eliminate a significant source of spam and abuse.

There's not much to be done about this otherwise - a Tor user is sharing a network with a significantly higher than usual amount of the bad elements of the internet.

Re: DDoS protection

#86
post #66

Earlier quoted context omitted.

Tor is used for abuse. If you want the privacy* you get with Tor the price you pay is that sites and services will check that you're not one of the abusers. At least it's not a flat-out ban. Any other large network on such a small IP space (as an example maybe a NAT-using mobile ISP) would be checked just as harshly. * Or any other reason you're using it. Edit: If I'm wrong can you please reply explaining why? I'm ha…

that's a pretty poor excuse. why is privacy only available by submitting to a poor experience? privacy should be default, not a punishment

Using a massively shared IP space of any kind is only available by submitting to a poor experience.

Nobody is saying "hey this guy has privacy, lets make this experience a pain in the arse". They're saying "Man this set of specific IPs are really hammering my system looking for WordPress exploits and we're not even running that".

To treat Tor better than regular traffic would be to discriminate against Tor, which would invite more abuse of Tor.

Re: DDoS protection

#87
post #13

I'm from Germany but Online.net is the way better alternative to Hetzner for me. Server grade hardware, cheaper, no compromises, internal network, etc. etc. I think they even hired a lot new support people recently so you get an answer pretty fast. Hetzner always has this "cheap feeling" even though the hardware looks good on paper.

You can get server grade hardware with the PX line at Hetzner, which is a bit more expensive of course. And an internal network is possible as well from what I read, though you have to pay for the Flexi pack because it counts as a modification of your server.

The main reason why we migrated our servers from Hetzner to OVH is Hetzner's hard drive policy. Basically, if one of your drives fails, they will swap it for… another failing drive. You will keep getting various refurbished or re-tested drives. Basically, if it passes their test, it is considered a good drive, even if SMART shows a history of errors.

Obviously, these drives do not last very long, so you end up with hardware that fails more and more often as time passes. Makes you look bad in front of customers.

I guess it's a matter of pricing — Hetzner is relatively cheap, and you get what you pay for. But you should know what you're getting.

Re: DDoS protection

#88

Can someone from the EU or DE talk about where Hetzner sits reputation-wise for those not familiar with them. Are they a solid provider?

Solid. I've been running my private servers with them for years now. Had problems with company work, specifically with them replacing failed hard drives with "shows errors, but barely-passed-testing" hard drives (see my other comment), but you don't normally hit that problem unless you have multiple physical servers.

Re: DDoS protection

#89

Can someone from the EU or DE talk about where Hetzner sits reputation-wise for those not familiar with them. Are they a solid provider?

Having servers with Hetzner for the last 15 years I'm a happy customer.

Caveat: (Root servers) They won't help you find problems or solve problems. They don't monitor your hardware. If you've got hacked and send spam, they close you down. If you have harddrive problems, you need to show them otherwise they will not easily swap drives. It's bare bone, though if they are responsible for the problems, their support is fast when notified. They are also helpful, e.g. when moving servers to a different data center, keep old servers so you can migrate to new ones etc.

Re: DDoS protection

#90
post #83
post #61

Earlier quoted context omitted.

This was never the intention. Part of the problem is inertion - cf operates large and complex application that was designed back when we had only a handful of customers. Part of the problem is technical - the privacy-centric anti-abuse technologies don't exist yet. Please do help us fix this. Report issues, help us understand when we have incorrect IP reputation. Help us find captcha accessibility problems. And maybe…

Problem is, your "incorrect IP reputation" concept is fundamentally flawed. As an example, I noticed that most VPN exit nodes have "incorrect IP reputation", which means if I want to browse the internet without my government spying on me, I have to wade through all your CAPTCHAs.

Keep in mind, unless you're using your own personal VPN off a self-hosted machine, you're likely to be sharing your IP address with other (potentially) malicious actors trying to hide their tracks
Post reply on HN