9 ms·
It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of ha
by dangxiaopin 7y ago
It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. During an attack, you make a BGP announcement and the traffic goes via Verisign scrubbing/tunnels. No application changes are required, no Matthew Prince selectively and benevolently enforcing CF neutrality. It's used by large banks.
- deleted 7y ago[deleted]
- gruez 7y ago>no Matthew Prince selectively and benevolently enforcing CF neutrality. What's the logic behind this? It's still a single point of failure and relying on a corporation. If the daily stormer or 8chan tried to use them, they would probably kicked off as well.
- nine_k 7y agoIf you are not a political undesirable, it does help, though. I think Wikipedia is fine in this regard, not something to shun of for a big corp.
- dangxiaopin 7y agoThere's always something "undesirable" for someone in a big crowdsourced website.
- rocqua 7y agoThe cloudfare 8chan action was based on a direct link with multiple actual mass-shootings. Moreover, as they took the decision they went to great pains to explain this was an exceptional case. Going from that to 'undesired political speech will be censored' requires more of a slippery cliff than a slippery slope.
- gruez 7y ago>The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?
- nl 7y agoThere are multiple instances of them announcing them and implying they are follow-ups of previous discussions on 8chan. These include the Christchurch shootings, the Poway synagogue shooting and the El Paso Walmart shootin. The Christchurch shooter shared his Facebook stream to 8chan before the shooting started, and it was spread from there. The Poway shooter blamed/thanked 8chan for his views.
- dangxiaopin 7y agoSo FB's internet peers should depeer Facebook then in their routers, since the original material (the stream) was on FB? Or you prefer your justice selective?
- nl 7y agoI'm sure you already realize this, but to make it clear: FB has enormous utility for billions of people outside that and that is worth defending. You are expanding a lot of effort defending 8chan here. Perhaps consider that it might not be worth defending.
- dangxiaopin 7y ago8ch had a lot of very interesting and non-violent stuff. Have you been reading it regularly? I did. I lived in a socialist country and you did not. Perhaps consider that you might not know where these current trends are pointing to.
- nl 7y ago
- wwright 7y agoI think it’s somewhat misleading to refer to those who support genocide and child abuse as simply “political undesirables.”
- nine_k 7y agoThey are beyond a certain line; some very-very far past it, some just crossed it. It makes them unsupportable by any corporation that aims to look decent.
- deleted 7y ago[deleted]
- bitwize 7y agoIt's not just supporting. Taking a neutral stance on censoring these things, or not being adequately proactive on hate speech, is now seen as condoning. You either censor your user base, or upstream will censor you. Gone are the days of "The net interprets censorship as damage and routes around it." The new policy is "The net interprets wrongthink as noise and filters it out."
- wwright 7y agoIt’s not censorship: they are not suppressing information, they just aren’t allowing their resources to be used to spread it. It would be “censorship” if they actively antagonized any attempt to spread the information, such as by lawsuit or DMCA notice. They are just refusing to participate. And given that the “information” is definitively known to be child pornography and violent white supremacy propaganda presented as news, I would personally say refusing to participate is the only responsible action.
- claudiawerner 7y ago> Gone are the days of "The net interprets censorship as damage and routes around it." But it's clear that it matters just what's being censored. Surely you wouldn't say the same trite clever-sounding hackerspeak if we're talking about censorship of threats, assault and child pornography, would you?
- 7y ago
- sannee 7y agoWikipedia is blocked in China. It's politically undesirable for 1/8 of the human population...
- nine_k 7y agoUnlike a DDoS attack, this is not a technological problem.
- NotSammyHagar 7y agoI think undesirable here describes something like white nationalists. They have a problem getting web hosting.
- sannee 7y agoCloudFlare has strategic business partnership with Baidu [1]. They are very likely to cooperate with the chinese government to implement the great chinese firewall. Additionally, helping to block Wikipedia because China says so is much easier to excuse than blocking 4chan - they would just be complying with local regulations after all. [1] https://www.cloudflare.com/press-releases/2015/cloudflare-and-baidu-announce-strategic-partnership-to-help-build-a-better-internet/ https://www.cloudflare.com/press-releases/2015/cloudflare-an...
- allard 7y agoBecause all of them don't want it?
- amaccuish 7y agoWhat's with the username? Are you trying to equate dang to Deng Xiaopin?
- lkoolma 7y agoAfter working with a few large corporations and their DDoS protection solutions, I did not have a good experience with Verisign, and they were not able to handle attacks or get things working. However, I have great experiences with Akamai and Cloudflare. I trust the people at Wikimedia will choose wisely. I would I have learned that Verisign has one of the worst BGP mitigation/scraping solutions out there. There are a few alternatives that have more experience and provide much better uptime, include solutions from Cloudflare and Akamai.
- dangxiaopin 7y agoAny serious mitigation solution must be BGP based, not proxy. Besides its technical merits and convenience, it also minimizes the risk of a benevolent controller (e.g. Matthew Prince of Cloudflare) ruining your company, because it becomes your upstream provider only during the attacks. Otherwise the GRE tunnels are not in use. The IP addresses are still yours always. We used Verisign for mitigation of a 44Gbps volumetric attack and it worked very well. We also evaluated Neustar, but Verisign's infrastructure seemed to be more robust.
- snazz 7y agoA proxy is a perfectly acceptable “serious” solution for this type of problem, as well as nearly all of the rest. Wikipedia is not the kind of website that would warrant being removed from Cloudflare. What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack?
- SahAssar 7y ago> What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack? The problem is that you are basically mitm:ed all the time.
- acdha 7y agoThat’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.
- judge2020 7y agoThis recent CF product announcement might be the same thing (not sure, sounds similar): https://blog.cloudflare.com/magic-transit/ https://blog.cloudflare.com/magic-transit/
- nullc 7y ago> It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. Great way for a state actor to intercept your traffic. little bit of volumetric dos and the target themselves responds by tunning through your partner(s).
- lima 7y agoThere's plenty of specialized providers which provide this service, Verisign is one of many. The issue with on-demand BGP mitigation is that an attacker can do short attacks on and off over a long period of time. Each time the mitigation kicks in, BGP propagation takes at least ~1 minute and will cause some downtime. Proper protection is always-on without requiring redirection.
- joatmon-snoo 7y agoAnyone that suggests that there is One True Solution TM is either biased or ignorant. You also don't get to claim it supports 2Tbps if you've only weathered 44Gbps.
- jopsen 7y ago> no Matthew Prince selectively and benevolently enforcing CF neutrality. Is this a slippery slope argument. Because there is a world in difference from discontinuing a few extremists customers, to discontinuing service for something akin to Wikipedia. I'm not sure every slight compromise of principals is a slippery slope. It seems to me that CF generally aims at being neutral.
- palerdot 7y agoThe argument made here is there is a chance (however minute) that the same can happen to something like Wikipedia because of some misplaced sense of morality, like say - we don't agree with wikipedia edits and editing process which we see if offending certain sections of X population. It does not matter how right their reason is. The fact that providers like cloud flare are in such position to take a moral high stance is not right ...
- jopsen 7y agoI don't disagree, but has it ever been any different?