4 ms·
what? Have you ever dealt with a DDoS attack and the consequences on your availability and infra health?
by fierro 5y ago
what? Have you ever dealt with a DDoS attack and the consequences on your availability and infra health?
- stingraycharles 5y agoOf course from the perspective of the website operator it’s great, but from the perspective of the user it’s frustrating. I’m not sure whether this is true, but it seems like with Firefox I get these captchas much more often than with Chrome. Sometimes they’re so difficult to solve it really takes a minute or two to do so, and it’s incredibly disturbing / an unfriendly interaction. Surely there must be a better way to deal with this? Why do I have to keep proving again and again and again to Cloudflare I am, in fact, a person?
- booblik 5y agoBecause you don’t actually want Cloudflare to store your browsing history on their servers. If they did it would be an insane privacy concern. So every time you get there it is like the first time.
- grishka 5y agoAre ddos attacks a common enough occurrence to warrant putting half the internet behind ddos protection? In my impression you need to do something really wrong to deserve one.
- livueta 5y agoThat's unfortunately not true at all in my experience. Maybe if you're an anodyne SAAS, but if you host any user-generated content, especially if it's adjacent to gaming (my personal experience was mostly with gaming-related forums and IRC networks), politics or any other charged topic, expect to get hammered on a pretty frequent basis. IoT botnets are pretty easy to rent at this point, so the attack is accessible to every skid known to mankind. I actually agree with your overall point as I try to use Tor for a lot of "normal" browsing, but I'm not sure what the correct solution to accommodate both is. It's a hard problem, and having been in that position myself I have a hard time faulting small website operators who have no alternative defenses. e: just to add to this, I see the existence of ddosing as a significant driver towards centralized monolithic services. If your blog on Palestinian rights or whatever is getting hit, that's an incentive to move it to a platform that takes care of networking for you. It's a little absurd to go all-in on decentralized self-hosting without at least an acknowledgement that with current tech and typical personal-computing budgets, doing so is giving a heckler's veto to literally everyone. Cloudflare isn't the only dimension things can be centralized along.
- tick_tock_tick 5y agoYes, they absolutely are. Hell just getting a few random bots scraping stuck in a loop or being overly aggressive on your site is enough to double your bill. So yeah it's 100% required.
- grishka 5y ago> to double your bill Do you pay a variable amount for your hosting? How and why? All VDS and dedicated server offerings I've ever seen are fixed amount per month. And more often than not the network is limited by speed, not by data transfer.
- luord 5y agoIn that case then the service will just hang as it won't handle the requests caused by even a simple malfunction (not even an actual attack) like the one mentioned by GP. Mind you, I see your point and I generally don't like the captchas either, but it is definitely a trade-off and I won't blame webmasters that use the DDoS protection.
- nijave 5y agoWhen you get DoSd you either pay to absorb the traffic or go down. Usually paying a DDoS service is the cheapest option but if you're not, you're paying for more infrastructure (or going down)
- NaturalPhallacy 5y agoDid we collectively forget rate limiting exists or something? One bot that's just stuck on a loop or being overly aggressive is going to have one IP.
- tick_tock_tick 5y agoThat is fair but instead of bothering to set that up I can just sign up for a free service in a hour once and just never worry about it.
- fierro 5y ago
- midev 5y agoYes, attacks on the web are very common for any decent sized site. Just because something is publicly available doesn't mean you get unfettered access to do whatever you want.