4 ms·
Unfortunately, all of these "Best Practices" are "spend more money," which effectively means the attacker wins. They're forcing you to spend more money, even if
by AgentK20 10y ago
Unfortunately, all of these "Best Practices" are "spend more money," which effectively means the attacker wins. They're forcing you to spend more money, even if they're not attacking you now/recently. Would love to see more things that reference open source mitigation software and such like that, e.g. tossing a hardened nginx in front of your Tomcat server, stuff like that.
Granted, at some point, you're going to have to spend money to mitigate the attack no matter what, but if mitigation of DDoSs becomes entirely focused on "Go with a big centralized provider" or "Spend lots of money to mitigate the attacks," we end up in a much different Internet.
- dorianm 10y agoCloudflare is free, so there is that :)
- Thaxll 10y agoCloudflare only works for http/https.
- dorianm 10y agoThey have DNS too, and they also protect at lower OSI levels (like TCP / etc.) https://www.cloudflare.com/security/ https://www.cloudflare.com/security/
- jaawn 10y agoWhoah, I did not know they had a free plan for personal use. Thanks for the tip!
- AgentK20 10y agoTrue, and while Cloudflare is a great company, putting all our eggs in one basket isn't particularly wise. Not saying that this'll happen, but we've seen "great companies" that were great while there was strong competition, but eventually when they became the monopoly began to strangle out anything that they were against. Protection providers like Cloudflare would have enormous power to simply kick out a user for being "too costly to host," like Akamai did to KrebsOnSecurity, and then you'd get destroyed by attacks.
- dx034 10y agoKrebs didn't pay akamai. It will be similar on cloudflare. If you're on a free plan, they will have a limit on what they will defend for you. Layer 3/4 and 7 attacks are only covered in business plan, but if you use this plan (which likely makes sense for many due to other features), I'm pretty sure they won't throw you out. Mitigating DDos is one of the main selling points nowadays. That's why OVH wrote so much about the huge attack they defeated (and they didn't name the impacted clients), Cloudflare offered Krebs to host him (he refused) and other providers add scrubbing centers. I actually think it's rather cheap to defend against DDos if you're a small company. Large companies will have it harder as they have typically more complex requirements and cannot just shift everything behind cloudflare or similar services.
- dorianm 10y agoThe CEO of Cloudflare talked about it at Black Hat[1], and for instance they protected an Hong Kong voting website for free while it was under heavy DDoS attacks. [1]: https://www.youtube.com/watch?v=SWFX-zEYwN0 https://www.youtube.com/watch?v=SWFX-zEYwN0
- lossolo 10y agoThey will direct traffic to your site on ddos if it will affect their infrastructure in free plan. And this will not protect you from level7 ddos.
- deleted 10y ago[deleted]
- erikb 10y agoNot really spend more money necessarily. Using dedicated hardware with prevention technology built in, making sure your servers are spread around the planet, all that sounds more like having a better architecture than necessarily spending more money.
- AgentK20 10y agoTrue, but there are certain scenarios (think gaming, VoIP, etc) where you can't really decentralize in the way that traditional websites can. On top of that, many lower-tier websites and service companies have to use budget hosts simply by the nature of them being an initial startup. Unless we're talking SV startups, it's much more difficult to throw big money around when you're just starting out to get that kind of dedicated hardware protection.