Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

81–90 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#81
post #76
post #44

Earlier quoted context omitted.

I like TT-RSS, mostly because it's easy to install, doesn't require a beefy machine, and support themes and plugins. For example, I use it with the feedly theme ( https://github.com/levito/tt-rss-feedly-theme ) and af_feedmod to get a full text feed for various sites ( https://github.com/m42e/ttrss_plugin-af_feedmod ).

Second the recommendation for TT-RSS. For a few bucks it has a good Android app that can hook into your self-hosted server as well. For me it beats a plain old "dumb" mobile app with no sync service since I check so infrequently that I'll sometimes miss stories on feeds that don't maintain a full backlog of posts--it gives me peace of mind knowing that I have a cron job saving everything for me even when I'm not acti…

Since Google Reader went away I've tried to self-host from the Raspberry Pi. Low resource usage was a priority, then, and TT-RSS was a touch too heavy for my liking.

Miniflux was faster, which I now use for audio/visual content (also appreciated its encouragement to pare down my feed list) but the overall winner in terms of pure day-to-day simple usage is Newsbeuter.

It's a mutt-like RSS reader and it's just an extremely efficient way to keep on top of feed information. And of course it's nice to be able to read feeds over SSH directly.

[1] - http://miniflux.net/ [2] - http://newsbeuter.org/

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#82

I wonder why they're not using Cloudflare.

I was just thinking the same thing. I have a website that I run and I was DDoSed one week and got over 1 million page requests but Cloudflare deflected most of the traffic. My New Relic logs were crazy because it showed that traffic was WAY up; I immediately knew what happened though.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#83

Earlier quoted context omitted.

"not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime" In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime? Victim blaming is not the answer, it's just silly.

> In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime? Negligence. If you own a powerful tool, you are at least in part responsible for it not to be misused. Similarly to how you are usually required to keep your guns locked away and are held responsible (at least ideally…) if someone steals them from your…

A gun is one of the few things you could reasonably make the negligence argument with. Anyone can get a car, or a knife, or a big plank, and leaving one in the street with no lock does not meaningfully contribute to crime.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#84
post #76
post #44

Earlier quoted context omitted.

I like TT-RSS, mostly because it's easy to install, doesn't require a beefy machine, and support themes and plugins. For example, I use it with the feedly theme ( https://github.com/levito/tt-rss-feedly-theme ) and af_feedmod to get a full text feed for various sites ( https://github.com/m42e/ttrss_plugin-af_feedmod ).

Second the recommendation for TT-RSS. For a few bucks it has a good Android app that can hook into your self-hosted server as well. For me it beats a plain old "dumb" mobile app with no sync service since I check so infrequently that I'll sometimes miss stories on feeds that don't maintain a full backlog of posts--it gives me peace of mind knowing that I have a cron job saving everything for me even when I'm not acti…

Third here! I have it running on a $5 DigitalOcean VPS (along with Exim, Dovecot and a static website on Nginx) and it just flies. The SSD helps, though - it can be heavy on I/O.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#85

Earlier quoted context omitted.

"not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime" In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime? Victim blaming is not the answer, it's just silly.

> In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime? Negligence. If you own a powerful tool, you are at least in part responsible for it not to be misused. Similarly to how you are usually required to keep your guns locked away and are held responsible (at least ideally…) if someone steals them from your…

If someone tells you "Enter this flat over there, take the computer, bring it to me and I’ll give you 10€", its on you to realize that that is illegal (and morally wrong) and refuse to comply.

"Double-click this for fantastic porn", on the other hand, will sound perfectly legitimate to many unsuspecting computer users. And there is nothing inherently illegal about the act.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#86
post #3

I was just wondering why I couldn't hop on Feedly. I feel sort of bad that this is what makes me finally self host my RSS reader, since it's totally out of their control, but I've been planning on jumping ship for a while, it's just been low priority for me. Goread has been tempting me though, so I guess I'll check it out.

Any suggestions on the best RSS reader to self-host?

Since it hasn't been mentioned yet, I'd like to suggest NewsBlur[1].

[1]https://github.com/samuelclay/NewsBlur

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#87

Earlier quoted context omitted.

The DDOS-for-hire company doesn't need a significant or even continuous web presence, does it? Seems ineffective to DDOS them. EDIT Surely many of these DDOS-for-hire companies cross into illegal territory. CF can maintain a content-neutral stance by kicking illegal activity off.

Illegal where? Their position is a reasonable one: they are not the host, they are not responsible for content, don't ask them to censor.

Illegal in the country that CloudFlare does business in, the USA.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#88

Earlier quoted context omitted.

From what I have read, Cloudflare takes considerable flack because they willingly provide services to the websites that let you buy and sell ddos-for-hire services. Also, I believe their defense is "we are a proxy, not the host, go elsewhere to complain". So, yes- They appear to allow these booters to exist and thrive in a world where they were unable to (at this level) before. * http://www.webhostingtalk.com/showthr…

If Cloudflare is knowingly providing cover to the DDOS-for-hire companies after being informed of what they are doing, that's a big bunch of bullshit right there. Just because a company temporarily relocates behind Cloudflare doesn't mean CF is guilty, though. They can't vet every website before it goes up and each time it updates. If they aren't kicking these guys off their network for performing the same activities…

If Cloudflare kicked accused DDOS-for-hires, the first step in any DDOS campaign would become "accuse target of being DDOS-for-hire". That wouldn't actually be a step forward for DDOS victims who use Cloudflare, because then they would have to provide human input to some sort of appeal process ASAP, rather than Cloudflare just working automatically to thwart an attack.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#90
post #79
post #75

Earlier quoted context omitted.

Tell dont not to open .exe file in Email. "What is .exe files?" Dont use IE "What is IE? Next time they click on it to get to the Internet" Can You please stoping using XP? "Why should I pay for upgrade when everything i do is working perfectly fine?" Honestly, there are people who dont know Shxt. And they dont want to know about it either. To them even basic computer usage is extremely complex. That is why Tablet, i…

How much do you know about your car's internal combustion engine and components? Your home electrical? Your home plumbing? Natural Gas? Lawn care? The pumps that fuel your car tank? Not everyone can be an expert in everything. Someone who makes their living perfecting one of those aspects might look at things you do and say "don't do that, you're damaging it" but to you its "who cares? I just need it to work and its…

Yeah, exactly. We almost live in computers, most of our friends and colleagues do, but there are so many people for who computer is just a black box. And there is nothing to be angry about. You don't want car mechanic, or plumber to be thinking that you are an idiot, casual users don't want that either, they just have more important things to care about :)
Post reply on HN