Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

91–100 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#91

I wonder why they're not using Cloudflare.

I don't know anything about Cloudflare, but isn't using a CDN with dynamic web-apps difficult? Sure you can host static content like javascript, CSS, images, etc. but caching stuff like what feeds, articles, etc. you've read can't be easy or efficient for a CDN.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#92
post #79
post #75

Earlier quoted context omitted.

Tell dont not to open .exe file in Email. "What is .exe files?" Dont use IE "What is IE? Next time they click on it to get to the Internet" Can You please stoping using XP? "Why should I pay for upgrade when everything i do is working perfectly fine?" Honestly, there are people who dont know Shxt. And they dont want to know about it either. To them even basic computer usage is extremely complex. That is why Tablet, i…

How much do you know about your car's internal combustion engine and components? Your home electrical? Your home plumbing? Natural Gas? Lawn care? The pumps that fuel your car tank? Not everyone can be an expert in everything. Someone who makes their living perfecting one of those aspects might look at things you do and say "don't do that, you're damaging it" but to you its "who cares? I just need it to work and its…

Indeed. I used to catch tons of shit about not understanding cars from a mechanic friend until his laptop died and I helped him recover photos of his kids.

Now we're both content to be wizards of our own domains without talking down to each other about it.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#93

Earlier quoted context omitted.

Drop all port 123 packets that are heading to the DDOS'd server from anything but the authorized NTP server is a pretty good start.

Where do you drop the packets? If your filter is inside your own network, and your bottleneck is your network connection to the outside world, then you're out of luck. If you can arrange with your upstream internet access provider for them to filter out junk before it hits the bottleneck, then great - but that involves cooperating with people, which may take some time.

DDOS is always handled by the upstream by definition.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#94

Earlier quoted context omitted.

If you were a former Google Reader user, you might like Feedbin. I've been with them for the last year or however long and have been fairly happy.

I've been using Digg Reader for a while and I'm actually kind of shocked that most people haven't moved to that. It has its bugs (sometimes showing incorrect numbers, the mobile app locks up sometimes), but it's honestly the best alternative that I've found so far. Maybe it has to do with its free-ness, as people worry about them shutting doors like Google Reader, but if you're looking for a free solution then I'd de…

I've been super happy with Digg Reader. The few bugs I've seen are not that big of a deal. I've never seen anything that an actual page reload didn't solve. I've not tried the mobile app though.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#95

I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?

A lot of these types of attack use amplification attacks (https://www.us-cert.gov/ncas/alerts/TA13-088A), often a carelessly-configured time server or name server, where only a small number of hosts are needed to wreak havoc.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#97

Earlier quoted context omitted.

How does this solve the problem of another DDoS against some other RSS reader? Are you going to suggest that if Feedbin gets attacked next, to hop to the next product?

Or he saw the other guy is open to trying different RSS readers and simply made a recommendation.

I'm moving TO Feedly since they've already had their attack. Next round would be the some other provider.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#98
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

Wow. FYI racket is defined as offering to solve a problem that does not exist, or that would not exist if the offerer wouldn't force it upon you. Unless you're claiming the blackmail group is made up of Cloudflare employees, you should choose your words more wisely.

IMO, CloudFlare meets this definition. For many DDoS victims, the problem would not exist without CloudFlare's help. Many cases like this are not some big bad guy with their own sizable botnet, they're just some kid using a booter bought with mommy's credit card. Without those booters being easily available, there would be no problem.

DDoS wouldn't go away without booters, but many small cases like this would be significantly reduced.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#99

Earlier quoted context omitted.

DDOS-for-hire websites are naturally unstable - if not for the protection CloudFlare provides, they would all knock one another offline and there would be no DDOS-for-hire websites (or only a single, expensive winner). Depending on your point of view, cloudflare providing the protection that makes DDOS-for-hire possible is either (a) them being fair and website-content-neutral, anything else would be censorship or (b…

The DDOS-for-hire company doesn't need a significant or even continuous web presence, does it? Seems ineffective to DDOS them. EDIT Surely many of these DDOS-for-hire companies cross into illegal territory. CF can maintain a content-neutral stance by kicking illegal activity off.

The DDoS-for-hire being discussed here are called booters. Access to them can be bought for a few dollars (~$10), and then one is able to log into the site and click a button to attack someone for a few minutes (the exact time depending on the booter itself and sometimes how much you pay).

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#100
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

That's like saying bodyguards are a protection racket because muggers and assassins exist. Yes, it sucks to have to pay for defense, but that doesn't mean the problem is your defense vendor's fault, or that said vendor has done anything wrong at all.

I don't think anyone has a problem with offering defense services. The problem lies in that CloudFlare is helping to create the problem. It would be analogous to your bodyguard constantly hiring hitmen to make attempts at your life.
Post reply on HN