Live data from Hacker News

Linode is suffering on-going DDoS attacks

status.linode.com

91–100 of 186 posts

Re: Linode is suffering on-going DDoS attacks

#91
post #65

Earlier quoted context omitted.

What DDoS protection does AWS provide? The only thing mentions on their webpage is autoscaling, more nodes, etc. In other words, AWS' DDoS protection strategy is to open up your wallet. About 6 months ago they did hire Jeff from BlackLotus. Given that timeline, I'd expect them to announce some sort of DDoS protection offering in the next few quarters. Edit to be more specific: AWS gets hit with a lot of DDoS attacks.…

I don't know, but all traffic to GCE is routed through Google's frontend, which provides in-built DDoS protections.

I'd imagine they use VRF's to quickly segment the traffic after ingress. Google.com might have DDoS protection, but I'm wary that it extends to GCE. I've read about Google Andromeda, but there's no real meat in any article about DDoS mitigation.

Re: Linode is suffering on-going DDoS attacks

#92

Earlier quoted context omitted.

BCP 38 is like herd immunity with immunization, and much like anti-vaccine folks, networks that don't follow it are knowingly choosing to infect people for any number of reasons. Despite your claim, it is extremely easy to implement and has been a known best practice, with accompanying educational Web sites devoted to the topic[0], for many years. There are nearly zero reasons for your AS to transmit forged packets,…

Given my ignorance of much of these issues, I probably shouldn't be commenting (take my comment with a huge grain of salt). But the idea of depeering networks on the Internet for misapplication of a voluntary protocol seems like the beginning of the end of a free Internet (if ever such a thing existed). If BCP38 is critical to the success of the Internet, I think rather than ranting about those not implementing it, e…

Your heart's in the right place, but the Internet is built on policies of individual networks because there is nobody to enforce. Your suggestion back to me is simply mine in different clothing, because you think someone can enforce such a global requirement. Enforcing policy like "filter or get depeered" is the only way to achieve a global requirement like you want with the way the Internet is structured. As akerl points out you need consensus, too, because such a policy could drive customers to other networks upon enforcement, which is a business disincentive to do it.

It's kind of a surprising moment when you realize what the Internet is and how little structure it has aside from the protocols themselves. We are one global Internet (semi) outage away from rethinking some of this structure, and I expect one in my lifetime.

Re: Linode is suffering on-going DDoS attacks

#93
post #77

Earlier quoted context omitted.

As of a few years ago Linode got transit from the facilities they are in and almost all of them had RTBH set up with a capacity of 5 or 10 routes. It would be incredibly foolish to operate a hosting provider without it.

Wait, you're saying that Linode uses facility transit? Like, they buy bandwidth from Savvis and TelX? Well that would be the problem right there. From what I can tell, Linode doesn't even have their own AS for customer traffic? It appears that they have an AS for some internal use, but not for customers?

Just because they purchase transit doesn't mean they don't have their own AS.

Everyone has to purchase transit at some point. Transit != AS.

Re: Linode is suffering on-going DDoS attacks

#94
post #76

Oh wow. I remember a couple months ago the ATL datacenter had network issues too. Really annoying, but I guess it's not their fault 100%. I wish they offered more DDoS protection solutions. I know some VPS companies specialize in that offering for things like game servers. It'd be nice if some sort of solution could just be included. I don't know if it's more of a technical issue or legal problem. As far as I know th…

OVH does VPS's and they have their own Anti-DDoS network setup that is pretty amazing:

https://www.ovh.com/us/anti-ddos/

Re: Linode is suffering on-going DDoS attacks

#96
post #91

Earlier quoted context omitted.

I don't know, but all traffic to GCE is routed through Google's frontend, which provides in-built DDoS protections.

I'd imagine they use VRF's to quickly segment the traffic after ingress. Google.com might have DDoS protection, but I'm wary that it extends to GCE. I've read about Google Andromeda, but there's no real meat in any article about DDoS mitigation.

It does extend to GCE, to an extent. The reason for this is that if someone is DDOSing your GCE VMs, they're going to be affecting the network performance of unrelated projects. So, Google has to provide some protection so that, at a minimum, other customers are not affected.

Re: Linode is suffering on-going DDoS attacks

#97
post #75

Earlier quoted context omitted.

I have a hard time imagining how supporting multiple providers would cost millions of dollars per year. I think it's a worthwhile way to make your software and infrastructure more resilient. And it protects you from vendor lock-in. As long as you keep things simple and don't use features that are only implemented by one provider, VMs are basically interchangeable.

Do you run Postgresql, MySQL, or something else? What led you to your choice? Because one is inherently better than the others for what you want to do? That's why you stick with a single cloud provider. You want the vendor lock-in. You go whole hog into using everything that they provide. Once you start mixing and matching the best of breed across cloud providers, you've lost. Once you start coding to the least commo…

Comcast as a company purchases from two vendors to avoid lock-in and to get the best prices. Juniper and Cisco, although last I heard Arista was also starting to be used.

Dual-sourcing makes sense in a lot of cases.

Re: Linode is suffering on-going DDoS attacks

#98

I would like to correlate the comments in this thread with past comments on every single article about AWS or GCE of the form "this is so expensive / complicated I run my boxes on Linode for half the price". DDoS protection is one of the things you pay for on the big clouds.

What about DigitalOcean? Its pricing is comparable to Linode's, yet DigitalOcean is now the second largest web host in the world according to Netcraft. Do you still think that AWS, Google Cloud Platform, and Microsoft Azure offer better protection?

If you even have the slightest inkling that your site will be attacked by a DDOS (either targeted or randomly) please reconsider DigitalOcean. Their method of handling a DDOS is basically "your node is being attacked, so we're disconnecting it from the network for a few hours. Try to figure out why someone is attacking you." Then, the machine gets reconnected three hours later and the attack cycle continues. Not to mention that since the machine is offline, there is no way of logging in to check access logs, modify firewalls, etc. I've never dealt with a company like DO before. Switched to AWS last year and, even when I was getting extreme traffic, AWS never just shut down access without notice.

Re: Linode is suffering on-going DDoS attacks

#99
post #34

Just 2 days ago, a Linode employee was badmouthing AWS here on HN for being too expensive: https://news.ycombinator.com/item?id=10796094 A DDoS will be much more expensive to customers than choosing AWS over Linode (or an equivalent low-priced service). EC2 has been around since 2006, and never has had any issues resembling this.

[deleted]

Re: Linode is suffering on-going DDoS attacks

#100
post #77

Earlier quoted context omitted.

As of a few years ago Linode got transit from the facilities they are in and almost all of them had RTBH set up with a capacity of 5 or 10 routes. It would be incredibly foolish to operate a hosting provider without it.

Wait, you're saying that Linode uses facility transit? Like, they buy bandwidth from Savvis and TelX? Well that would be the problem right there. From what I can tell, Linode doesn't even have their own AS for customer traffic? It appears that they have an AS for some internal use, but not for customers?

That's correct. They use facility transit everywhere except their newest datacenters (Singapore and maybe Frankfurt), where they operate their own AS and use blended transit.
Post reply on HN