6 ms·
After working with a few large corporations and their DDoS protection solutions, I did not have a good experience with Verisign, and they were not able to handl
by lkoolma 7y ago
After working with a few large corporations and their DDoS protection solutions, I did not have a good experience with Verisign, and they were not able to handle attacks or get things working.
However, I have great experiences with Akamai and Cloudflare. I trust the people at Wikimedia will choose wisely.
I would I have learned that Verisign has one of the worst BGP mitigation/scraping solutions out there.
There are a few alternatives that have more experience and provide much better uptime, include solutions from Cloudflare and Akamai.
- dangxiaopin 7y agoAny serious mitigation solution must be BGP based, not proxy. Besides its technical merits and convenience, it also minimizes the risk of a benevolent controller (e.g. Matthew Prince of Cloudflare) ruining your company, because it becomes your upstream provider only during the attacks. Otherwise the GRE tunnels are not in use. The IP addresses are still yours always. We used Verisign for mitigation of a 44Gbps volumetric attack and it worked very well. We also evaluated Neustar, but Verisign's infrastructure seemed to be more robust.
- snazz 7y agoA proxy is a perfectly acceptable “serious” solution for this type of problem, as well as nearly all of the rest. Wikipedia is not the kind of website that would warrant being removed from Cloudflare. What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack?
- SahAssar 7y ago> What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack? The problem is that you are basically mitm:ed all the time.
- acdha 7y agoThat’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.
- judge2020 7y agoA better comparison would be Cloudfront and Application Load Balancers since you can expose your own ec2 server or load balancer and be e2e encrypted (unless AWS wanted to run commands on your instance, which they could do, but that's a different threat vector entirely).
- acdha 7y agoThat was the model I had in mind but it’s not really a meaningful distinction since the host could almost certainly compromise those servers as well. In any case, you’re trusting a third party rather than having their involvement maliciously imposed.
- dangxiaopin 7y agoYou upload your private SSL key to Cloudflare for example. And I was talking about hosting on your own hardware/colos like most large sites do (7x cheaper than AWS list prices on avg)
- acdha 7y agoPlease specify in detail how you believe that’s an MITM using the standard industry definition. In particular, consider whether “attack” and “voluntary business agreement” are synonyms.
- lazyguy2 7y agoMITM is not a uncommon term to use when you do things like install corporate SSL certs on laptops so you can monitor people's activities.
- OBLIQUE_PILLAR 7y agoYou appear to be extremely mad Cloudflare stopped proxying a website that encouraged large gun massacres.
- aceofspades19 7y agoHow did 8chan "encourage" large gun massacres exactly? By allowing users to post content?
- Operyl 7y agoBy not moderating content largely, it was no secret what the site was letting go.
- o-__-o 7y agoBy your statement then reddit was complicit with the Russian trolls during election season because the bitcoin trolls who evolved into trump trolls were not punished in the slightest (I have a list of 300+ usernames that are still active today)
- judge2020 7y agoThe point is that Reddit tries to moderate, which is good enough for their providers (AWS/Fastly). The 8ch takedown wasn't actually due to issues with moderation, since (at least based on the owner's video) 8ch removed the post, actively responds to real law enforcement requests, and the original post was actually posted to IG. The issue was that CF was getting enough bad press, and more importantly enough calls/concerns from real Enterprise clients (this is speculation on my part), to take down the website.
- Operyl 7y agoReddit is actively moderated by both paid Admins (site wide rules) and volunteer Mods (per subreddit rules). So no, I disagree.
- aftbit 7y agoThat's your requirement, but it might not be Wikipedia's requirement. Ownership of IPs is really a technical detail invisible to most people; ownership of eyeballs by way of the domain name and top Google result is probably more important. Cloudflare doesn't impact that ownership other than being able to temporarily take you offline if they choose to terminate your site. Still, large proxy-based CDNs do have the ability to completely bypass all the same-origin protections in the browser. Even if they are angels and don't abuse this trust for identity theft and surveillance, it makes them a juicy target for bad actors, state sponsored and otherwise.
- awirth 7y agoAkamai has a BGP based DDoS mitigation service via their prolexic acquisition.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]