6 ms·
Surprised they are not using a DDoS mitigation provider yet. With companies like Sucuri and CloudFlare providing it at $20 per month, seems a non-brainer.
by rmdoss 10y ago
Surprised they are not using a DDoS mitigation provider yet.
With companies like Sucuri and CloudFlare providing it at $20 per month, seems a non-brainer.
- pfg 10y agoMost of these services have some kind of fair-use policy. Nothing that you would notice as a small to medium-sized user, but if you push the kind of bandwidth that I imagine the Internet Archive would, or if you're suffering from a large-scale, targeted DDoS, I'm pretty sure you'd be "encouraged" to switch to the Enterprise plan, which starts at $3k/month if the numbers posted in various discussions on this topic can be trusted.
- rmdoss 10y agoTrue, good point. In their case, Sucuri actually offered to help for free via twitter, which is nice. CloudFlare has project Galileo, which they could apply for and get free DDoS help. The importance of the Internet Archive is such that we can not allow it to ever go down. thanks,
- mynewtb 10y agoI guess control over their user's privacy and the integrity of their connections is more important to them and I like that.
- greglindahl 10y agoA typical attack mitigation service involves HTTPS termination, and yeah, that's a privacy issue.
- rmdoss 10y agoI see a lot of reasons not to use these providers, but privacy and integrity is not one (and I find it a bad argument against them). Every traffic passes through so many hops, routers and networks that adding a secure, well tested and privacy-paranoid provider, like CloudFlare will not affect the privacy or integrity of your connection. Yes, they have to SSL terminate your connection, but does so every proxy that they decide to use (nginx, elb, whatever). Plus, the security that a company like CloudFlare has to protect that data is a lot higher and more strict than the majority of sites out there (including the Internet Archive). It is also frustrating that people would downvote me above for suggesting to use them, when in fact it is the only way to handle a large scale DDoS uness you have an insane pipe with hundreds of G of uplink.
- pfg 10y agoHaving access to the plaintext traffic of 5% of all web sites on the internet makes them a huge target for anyone from hackers to nation states/intelligence agencies and what not. I have a lot of faith in their security team, but this level of concentration is not healthy for the internet as a whole. There's a huge difference between having access to the plaintext of encrypted connections and merely seeing connection metadata, as would be the case with "traditional" DDoS mitigation services that do not act as a proxy. Reverse proxies are certainly not the only way to handle large-scale DDoS attacks, though I would agree that, leaving aside the privacy concerns, those services are hardly competitive in comparison to CloudFlare, especially on price and UX.
- PhasmaFelis 10y agoI'm guessing it's never come up before, because why would anyone ever DDoS the Internet Archive? They have no ideology, make no political statements, back no movements. They have no real money to extort. I suppose the lesson here is "never underestimate the stupidity and destructive power of wannabe vigilantes."
- sosuke 10y agoThe group says they are doing it because of ISIS material.
- joepie91_ 10y agoCloudFlare doesn't provide mitigation for $20/month. Unless you sign up for their Business plan at $200/month (or even Enterprise, in some cases), you won't get mitigation worth crap. A lot of people mistakenly think that CloudFlare provides "real" DDoS mitigation, but that's just not true. In fact, I'd wager that CloudFlare has mostly outlived its utility nowadays, and is primarily a risk rather than an asset - for it to work, you must compromise your users' privacy, unlike competing mitigation services. "Saving bandwidth" is hardly a valid argument anymore either. How much is your users' privacy worth to you? Traffic pretty much costs between $0.50 and $5.00 per TB nowadays -- would you essentially break TLS for everybody to save a few bucks a month? As for Sucuri - only their Business plan covers Layer 3/4 attacks, and it's not entirely clear to me what they mean with "site". Is it a single subdomain? If you want actual, real DDoS mitigation, then just pay a real mitigation provider like Voxility, X4B, Level3 (formerly Black Lotus), and so on. There are quite a few. EDIT: Yep, Sucuri classes a "site" as a "unique FQDN", more or less. It's not clear what the bandwidth/traffic limitations are. It also seems to me like it only does HTTP-based traffic, much like CloudFlare.
- saganus 10y agoWhat competitors are there for CLoudFlare that you consider better than them? I am genuinely interested since I was thinking on signing up for their service, but I would love to research some alternatives first.
- joepie91_ 10y agoThat depends on what you expect to get out of them. * If you're looking for DDoS mitigation, use basically any of the providers that offer it on a network level - it's really not necessary to have access to HTTP traffic to mitigate attacks. Also, don't run Apache - it's notoriously vulnerable to various low-bandwidth attacks. A non-exhaustive list of "real" mitigation providers (note that I am not making any particular recommendations): - Voxility - X4B.net - Akamai (formerly Prolexic) - Level3 (formerly Black Lotus) - Psychz Networks - CNServers - Sharktech - OVH (not as a separate service, but their entire network is covered) You'll want to avoid anything HTTP-specific (as it will be prone to the same privacy issues as CloudFlare), and opt for layer 3/4 mitigation only. Another option, if you're running at a larger scale, is to purchase mitigation appliances and just set up your own mitigation infrastructure. This will not be cheap and require some serious connectivity, but beyond a certain point it'll be more cost-effective. * If you're looking for a WAF, run one on your own backend server(s) and/or loadbalancer(s). There's no benefit to doing this remotely, really. Even something relatively simple like ModSecurity will cover a wide array of problems. * If you're looking to save bandwidth: don't bother. Traffic costs virtually nothing nowadays, and saving a few dollars by having another provider cache your assets hardly outweighs having the privacy (and potentially security) of all your users compromised. If you find traffic to be expensive, you should probably look for a different provider - some providers (like AWS) notoriously overcharge for it. * If you're looking for better performance: CloudFlare doesn't really provide that to begin with. There's an extra hop for non-static assets, and depending on the location of your server and users, it can actually slow things down. If your performance is really critical to the millisecond - and chances are, it isn't - look into hosting providers that offer anycast. * If you're looking for DNS hosting: plenty of options. Many providers offer it for free if you host with them, Hurricane Electric offers it for free regardless of where you are hosted (http://dns.he.net/ http://dns.he.net/), and if you need an SLA, there's Rage4 and Route 53. Pretty much every DNS hosting provider uses anycast. * If you're looking for magic SSL/TLS: Use Caddy (https://caddyserver.com/ https://caddyserver.com/), which is a HTTPd that will automatically set up and renew certificates for you through Let's Encrypt, as well as greatly simplifying TLS configuration. It's essentially zero-effort. Trying to outsource this to a third party (like CloudFlare's "Universal SSL/TLS" does) defeats the point - it means that the third party can see all of your traffic, all the while providing a false sense of security to your users; they see the padlock, but their traffic is not secured end-to-end. In short: the only correct place to terminate TLS is on your own servers. * If you're looking for something else that CloudFlare offers: Feel free to describe it, and I'll suggest an alternative.