20 ms·
Linode launches free DDoS protection
- regecks 7y agoI guess this is basically the same as OVH's "VAC" system? I sometimes get these emails: >We have just detected an attack on IP address x.x.x.x. In order to protect your infrastructure, we vacuumed up your traffic onto our mitigation infrastructure. The entire attack will thus be filtered by our infrastructure, and only legitimate traffic will reach your servers. and then: >We are no longer able to detect any attack on IP address x.x.x.x. Your infrastructure has now been withdrawn from our mitigation system. I never need to do anything, but I don't think these attacks are real anyway.
- judge2020 7y agoHacker: ping -t 1.2.3.4 OVH: go into lockdown!
- codexon 7y agoThey are very likely real and OVH has a very good system. You can thank them for making free DDoS protection mainstream, dragging all other hosts kicking and screaming into providing DDoS protection. In the past providers like Linode were happy to just null route your IP for several hours/days or charge you thousands to block a small flood.
- ignoramous 7y ago> You can thank them for making free DDoS protection mainstream AWS does charge for WAF and Shield, I believe. I also remember comparing AWS Lambda at Edge vs Cloudflare Workers (though Lambda allows for longer execution times and generally provides more flexibility like RAM, CPU, Runtimes since it runs on a Linux VM vs V8 Isolates for Workers), costs were something like 10x apart. Can't wait for WebSockets support for Workers.
- lentil 7y ago> I also remember comparing AWS Lambda at Edge vs Cloudflare Workers ... costs were something like 10x apart. According to the AWS pricing example[1] 10 million requests per month on Lambda@Edge costs $9.13. The same thing on Cloudflare Workers[2] costs $5.00. So I would expect it to be closer to 2x. Although as you say there's a bit more flexibility with Lambda@Edge so it'll depend on your particular case. I'm curious if your situation was different somehow that made for such a big cost difference between the two? [1]https://aws.amazon.com/lambda/pricing/#Lambda.40Edge_Pricing https://aws.amazon.com/lambda/pricing/#Lambda.40Edge_Pricing [2]https://workers.cloudflare.com/#plans https://workers.cloudflare.com/#plans
- ignoramous 7y ago$5 includes a generous free tier for Workers KV that can hold upto 10MiB of data against a single key. Cloudflare does not charge for bandwidth consumed, I believe. Also, use of Cloudflare's zonal http-cache is free. I guess, when I compared, I took Lambda@Edge's per second billing into consideration and not per 50ms (which brings down the RAM usage cost from $62.52 to $3.13 and total usage from $68.52 to $9.13). What really sealed the deal for me was the very low cold-start times with Workers. I'm not aware of recent improvements with Lambda@Edge, but the last time I tried them, it wasn't uncommon to hit 100ms+ start times.
- lentil 7y agoThat's interesting, thanks. I haven't really used Cloudflare Workers for much myself so it's interesting to hear folks' comparisons.
- ignoramous 7y agoOne more thing, I am not sure if Lambda@Edge charges based on wall-time or cpu-time. Workers' 50ms is cpu-time only and not wall-time. You could, in theory, spend 30s waiting for a fetch to return as awaiting on the network doesn't count against a Workers' 50ms cpu-time limit. Ref: https://developers.cloudflare.com/workers/about/limits/ https://developers.cloudflare.com/workers/about/limits/
- latch 7y agoIt wasn't just Linode (a provider that's generally much cheaper than OVH), but high end providers like Softlayer too (and, as far as I know, still are)
- ryanlol 7y agoHow is Linode “much cheaper than OVH”? Their margins are probably way higher.
- latch 7y agoLinode's origin is as a VPS provider. OVH's is as a dedicated server provider. OVH's top server is twice the cost of Linode's and their cheapest is 5x the price (10 vs ~50).
- luckylion 7y agoComparing prices for bare metal with prices for shared infrastructure is pretty much useless though.
- ryanlol 7y agoWhy is that?
- urbanjunkie 7y agoI mean, I'm not trying to be rude, but you're pretty fucking stupid. OVH's cheapest VPS is just over $3 per month.
- ryanlol 7y agoCheapest OVH dedi I see is the KS-1 for 3.99eur, which is less than the cheapest Linode VPS. OVH also doesn’t try to nickel-and-dime you by charging for data transfer. I wouldn’t recommend the cheapest Kimsufi offerings though, something like the SYS-WS-1 goes for $33 and is easily comparable with Linode offerings priced at multiple times that. OVH has a VPS product that’s far cheaper than what Linode offers, but I can’t speak to the quality of that offering.
- Matt3o12_ 7y agoI’m curious, does anyone know what that means specifically? How can they differentiate normal traffic from malicious traffic? What exactly triggers it? Is a ping flood with a slow (50mbits) internet connect enough? I am aware that the details are mostly likely private to protect them from abuse and are also a trade secret but I have a very hard time to find a general approach that might be similar to their solution?
- cortesoft 7y agoI don't know their solution exactly, but what usually happens is they look for common packet signatures. Most DDOSes aren't very sophisticated, and can be blocked with fairly simple rules.
- Thaxll 7y agoIt's much more advanced than you think : custom asics etc...
- telesilla 7y agoLinode support is fantastic and we host some critical infrastructure with them for this reason and have been happy for years. DO has the managed DB however so we've been migrating some services to them. If Linode offers a managed DB I'll move everything back.
- buro9 7y ago> I never need to do anything, but I don't think these attacks are real anyway What would it take to convince you an attack is real when it has been 100% mitigated and you never saw it in your backend infrastructure? I ask as the engineering manager for DDoS protection at Cloudflare, and we stop a lot of attacks. But I feel this tension in the communication and product offering... if we do our job well enough that a customer's system does not see the attack, how does a customer see and feel the value? An example is that as a reverse HTTP proxy we are implicitly also a full TCP proxy for HTTP traffic and so we receive significantly large SYN or ACK floods. We stop these 100% by virtue of being the terminating TCP proxy, but also by using connection tracking, anycast, XDP + eBPF, and so forth... you won't see a single one of these SYN or ACK packets hitting your infrastructure... so what would we have to communicate to convince you that the attack existed?
- rmdashrfstar 7y agoDo you publish metrics on “attacks prevented” (or access to logging and monitoring) for customers?
- buro9 7y agoYes. For HTTP customers there are full SIEM logs under Firewall > Overview on our dashboard, and for paid tiers there are drill-down analytics in addition to the full SIEM logs. There is also log push to receive near real-time full HTTP logs into Google or AWS for your own analysis and these show if a firewall feature touched the request or if it was served from cache. In addition for HTTP customers we show graphs of SYN floods, etc for the IPs your web properties are advertised on. For L4 customers via Magic Transit we also have Network Analytics showing what we received at our edge network and a log of attacks detected and mitigated. There is still lots of room for improvement... that's really what I'm asking, what does the ideal system look like for someone where they see and understand the data and trust it. For example, is it valuable to see the attack landscape and what is happening across our systems even when you are not the target? Would that help give perspective to attacks that do target you, and also increase faith that this system exists and is stopping attacks when attacks do not target you?
- wielebny 7y agoI've been using OVH services to host game servers for several years now, and their "VAC" is a godsend. Other providers would prefer to terminate my account or offer some kind of protection for thousand of dollars.
- tomrod 7y agoFascinating! I learned about fail2ban this week as well as how to search for bad SSH actors -- I was amazed at the traffic requests my Linode was getting decked with. Having this as a default seems good.
- RL_Quine 7y agoSpurious SSH traffic is not a DOS, and isn’t the sort of attack this is talking about, rather volumetric floods and things of that matter.
- deleted 7y ago[deleted]
- mappu 7y agoFail2ban (and IP blocking in general) breaks down a bit on IPv6 when the attacker has a /48 or /64. Are you going to block a single IP address or the whole netblock? What size block is safe to not cause collateral damage for e.g. mobile users?
- EugeneOZ 7y agoI was on this step. After some time you'll hate fail2ban. Big part of attacks comes from hacked "regular desktops", by blocking their IP permanently you will block access for legitimate (and non-hacked) users - providers often change user's IP.
- porker 7y agoIf your SSH logins are key-only (and they should be) then fail2ban is unnecessary IMO. No one is going to gain access without your private key, and while it's a nice feeling that the bad actors are "blocked" - fail2ban is using more resources to block them than their attempts are using. Assuming you aren't getting 1000s per minute, of course.
- arrty88 7y agoDoes AWS or any other large cloud provider offer this type of service?
- RL_Quine 7y agoAWS has strong DOS protection and just doesn’t tend to shout about it. Putting services behind AWS for some basically free protection has been a trick against basic volumetric attacks for a while.
- Something1234 7y agoSo how does that actually work? Doesn't AWS charge an arm and a leg for traffic?
- pansa2 7y agoYes - this is my main concern about moving a website from a fixed-price service to S3+CloudFront.
- dylz 7y agoBasic volumetric - which is what the smaller providers can't handle, AWS can eat easily. I don't believe I've been charged for this type of attack. The one you should look out for if you are new to AWS and trying to do this "trick" is L7 repeated downloads of high-file-size content to consume your budget rapidly.
- pansa2 7y ago> L7 repeated downloads of high-file-size content to consume your budget rapidly. How an one protect against this type of attack?
- toast0 7y agoAWS charges an arm and a leg for outbound traffic, inbound traffic is free. Volumetric attacks are all about overwhelming your inbound; if AWS will swallow that at their ACL layer for you, that's seems pretty useful, and shouldn't generate billing.
- nerdbaggy 7y agoCongrats to them. Linode always has a special place in my heart.
- ta999999171 7y agoCouple reasons for those less experienced with VPS?
- mekster 7y agoNot GP but for me, Linode had been fine for 5+ years and it speaks but Vultr has been having choppy network at least once a month for few years now (detected by port monitoring) and that also speaks too. DO has been good on me too.
- debian3 7y agoSame experience here with Vultr, always go down. But seems to be a bit better now than before.
- pm90 7y agoSerious question: why would I want to use Linode over GCP or AWS? Asking as someone who hasn’t really dabbled with smaller cloud providers. Is it cost? Support? Developer tooling?
- papito 7y agoI want to run demo software on a JVM, and the box beefy enough to do that is MUCH cheaper on Linode.
- wolco 7y agoCost and freedom.
- Something1234 7y agoI personally would say simplicity and up-front pricing. I don't need to make a spreadsheet to figure out what I'm going to pay to host a simple web site or project.
- vfinn 7y agoYes, up-front pricing is very essential. I don't want any surprises. If there's a chance for that, I won't be using the service at all.
- oefrha 7y agoCost and ease of onboarding. For $5/mo you get 1 vCPU, 1GB RAM, 25GB SSD, 1TB egress quota. Try calculating the egress cost alone for GCP or AWS.
- chomp 7y agoIs this an on-demand solution using something like BGP+ Radware or Arbor? At what volume or pps will they announce a nullroute?
- ksec 7y agoNice. Apart from the security incident that took place long time ago, are there any reason why everyone is going straight to DO instead of Linode? For a long time Linode has had better features, performance and bandwidth. It wasn't until recently DO had Managed DB and many other additions. Linode's High Memory Plan also has much better Memory : CPU Ratio. Still waiting for their CDN, ( Not sure why they are not exposing it and instead requires going through CS ), Managed DB and Bare Metal. Once those three are in place, ( and well tested ) It should provide decent competition to the HyperScalers.
- mekster 7y agoWho is "everyone"? Linode has been my primary choice over DO for some years.
- voidfunc 7y agoBetter marketing from DO. There strategy of content marketing with how-to guides has been massively successful. Personally, think DO has a more pleasant UX too.
- Carpetsmoker 7y agoDO has been posting (or rather, spamming IMHO) /r/golang with fluff like "how to use switch statement in Go". You know, the sort of articles that someone who learned Go a week ago can write.
- commandersaki 7y agoHope they use fastnetmon.
- geuis 7y agoI’ve been a Linode customer for at least a decade. Cheapest bandwidth I’ve been able to find anywhere and their data centers are super reliable.
- ryanlol 7y ago> Cheapest bandwidth I’ve been able to find anywhere Have you looked? Linode BW is incredibly expensive compared to just about any dedi provider.
- kundi 7y agoMaybe because you only host static websites
- geuis 7y agoI run https://jsonip.com https://jsonip.com on linode. I push about 5-6 terabytes of data outbound each month. Linode is a dream.
- jitendrac 7y agoOne more reason to Like Linode.
- pqdbr 7y agoI wish they had a datacenter in Brazil.
- mike_d 7y agoBandwidth in South America is approximately 8x the cost of North America or Europe. There are almost no carrier neutral datacenters or peering where you can exchange traffic with other in-country networks without paying for transit. Most countries will strong arm you in to buying "local" for your hardware - which means using in country re-sellers that drastically mark up prices for foreign businesses. Next to Moscow it is one of the most difficult places I've tried to put servers.
- AC_Fan 7y agoThe only semi-competitive option for bandwidth in South America is Oracle Cloud, but of course that comes with it's own issues (primary amongst them being you'll be using Oracle). But if you can deal with that, a basic 2vCPU/8GB VM comes to less than 25 USD, with bandwidth costing 8.5 USD/TB.
- nickjj 7y agoWell done Linode. I wonder how quickly DigitalOcean will add this to remain competitive. It's a huge win to have your hosting provider handle this and it's also nice to not be "forced" into using Cloudflare for such an important feature.
- acetheface 7y agoDigitalOcean has had free DDOS protection for quite awhile. And it sounds like Linodes solution is fairly similar. DigitalOcean decided to not advertise the fact because advertising your defenses is an open invitation to break them. They still null route when the upstream links become congested but this is becoming less and less frequent as their network edge grows.
- nickjj 7y agoDo you have any documentation that mentions your droplets are protected from a ddos attack without you having to do anything? Even DO themselves mention they don't protect against it and even go as far as saying to use Cloudflare. Here's a tweet of that from Jan 2018: https://twitter.com/digitalocean/status/958364631671758854?lang=en https://twitter.com/digitalocean/status/958364631671758854?l... Is that them taking the "not advertising it" line to the next level by publicly stating they don't protect you even though they do? I'm a bit skeptical.
- nik736 7y agoAbout time after everything was down for weeks in 2015.
- diftraku 7y agoIs it free [1], free* [2] or "free" [3]? [1]: free as in free beer, at no direct cost to users [2]: terms and conditions apply, free until you hit certain conditions (for example, constant barrage) [3]: free as in the customers pay for the (mandatory) DDoS protection via increased prices (similar to how I remember OVH handling their "free" DDoS protection)
- skrebbel 7y agoI don't understand the difference between 1 and 3.
- diftraku 7y agoI may have used "free as in free beer" in a wrong way, what I meant with 1 was there are no additional costs to the current or new users (the rates for the services on offer stay the same). For 3 (as was in the example), the cost of the DDoS protection service is directly added to the rates of services on offer. OVH was quite blatant in this, as it had offered an optional DDoS protection service for a fixed rate of 3€/mo (this was a few years ago, exact details might be hazy). After they had a large network overhaul (with major interruptions), they simply raised the prices by 3€ and advertised the new, "free" DDoS protection service which was included in all of the services.
- mmahemoff 7y ago3 is very unlikely, hosting plans generally go down over time, not up. And Linode, like most metered hosting services, where you're billed hourly, don't normally distinguish pricing for new versus recurring customers.
- tristador 7y agoInstead the price would just go down more slowly. So the price drop that you'd otherwise expect is paying for the new features.
- buboard 7y agoi m always surprised by the obvious promotion posts here. I 've had free Ddos protection in my hetzner servers since forever and nobody ever mentioned it
- iMerNibor 7y agoThere was a hn thread on it aswell when they finally added it instead of nullrouting ips Might be this one? https://news.ycombinator.com/item?id=12403783 https://news.ycombinator.com/item?id=12403783
- vld 7y agoThis isn't on the level of some other providers, they'll still null route you if you go over an unspecified amount of traffic. IIRC they use Juniper and Corero. This is the reply I got from their support, just a few days ago: >In short, our DDoS protection works by filtering out DoS-like traffic and is applied via the Linode network, so all Linodes are automatically protected. If your server were to be on the receiving end of a larger attack that impacts the Linode's host, we would need to prevent your server from receiving traffic until the attack ends. If you're concerned that you might be the target of a large DoS attack, there are a number of third-party DDoS mitigation services that you can use alongside your Linode. >We aren't able to provide specific numbers since effects can vary depending on the attack. If you wanted to be sure your Linode is protected, we would recommend utilizing a third-party DDoS protection service overtop of your Linode's included protection. You also have the option of waiting to apply third-party protection until a null route is found to be necessary.
- KaoruAoiShiho 7y agoThat's not protection, that's literally the opposite of protection lol. If you get attacked they take your service out the back and shoot it in the head. Edit: To clarify, filter = protection. Preventing all traffic is not. Both were stated in the description above so they should be clear which one it is.
- chias 7y agoHeh, that reminds me of my first bank account. They told me I had something called "overdraft protection", which I stupidly assumed would protect me from overdrafting my account by declining transactions. Then I forgot to deposit a check at one point and overdrafted my account. I assumed things were fine because none of my transactions were getting declined. Instead I was being charged an extra $15 fee on every transaction, so that $0.75 stick of gum? $15.75, etc. This went on for about three weeks before I got my statement and talked to my bank. They informed me that in fact the protection was from my transactions from being declined, at the paltry expense of $15 per transaction.
- 7y ago
- kundi 7y agoOVH and Linode are what Bluehost is for shared hosting. Hosting providers that you want to stay away from if you want good for your server infrastructure.
- appleflaxen 7y agocan you elaborate?
- theyak 7y agoThe Christmas 2015 hack has now been fixed :) My boss has been begging us to leave Linode ever since. We haven't left.
- PretzelFisch 7y agoGood for them. Having DDoS protection included in pricing is now one of our core purchase criteria. There are many ransom hackers that target nobody companies like where I work were this kind of protection is now mandatory to ensure uptime.