6 ms·
DDoS Protection
- skilled 3y agoI’m going to bite and ask myself, Do you only have to pay if you have been exposed to an attack?
- re-thc 3y ago> Do you only have to pay if you have been exposed to an attack? It's like insurance. Do you buy it after an accident or before?
- capableweb 3y agoCan I purchase insurance while I'm crashing? Sounds like getting insurance and getting DDoS protection isn't really the same thing after all...
- mdasen 3y agohttps://docs.digitalocean.com/products/networking/ddos/details/pricing/ https://docs.digitalocean.com/products/networking/ddos/detai... You pay for it at a price of 20% of your plan's price. If you have a $25/mo plan, it'll be a $5 add-on. You can enable/disable it so that it's only on when you want it and it is pro-rated in that case. If you want to respond to an attack for 2 weeks of the month, it'll cost $2.50. So you can manually turn it on if you're under attack and only pay for that time, but if you want it to automatically handle an attack you have to pay for the month. I think most people would just turn it on if they were a likely attack target. You don't want your site to go down and either get paged or find out about it hours later. If you're an unlikely attack target or a site that can stand some downtime, you could leave it off and just enable it when under attack.
- skilled 3y agoThat makes sense. Thanks.
- nubinetwork 3y ago> You will be charged up to 20% based on your total monthly resource usage covered by DDoS Protection with a total monthly maximum of $1000/mo. I get that someone has to pay for this, but if I had 50 servers here and they all got shit on, I'd be on the hook for a lot of money through no fault of my own.
- robbiemitchell 3y agoThat’s pretty much how insurance works. This is a 20% fee for DDoS insurance.
- belter 3y agoAWS has an (expensive) option with DDoS cost protection. https://aws.amazon.com/shield/features/#AWS_Shield_Advanced https://aws.amazon.com/shield/features/#AWS_Shield_Advanced
- johnklos 3y agoThey gotta get more money from all the scammers they host somehow.
- stevenicr 3y agoI partially wanted to LOL this. Realized that's not a thing for HN. Thought that this will likely be downvoted because HN. Then I thought, what a great way to tax the spammers / hackers that use DO! I would gladly pay the $5 ddos fee to hammer the ips that keep trying to login to my wordpress sites. just kidding, I would not actually do that.. but the thought is pleasant. I've used DO many times and I am a fan btw - just looked back at their pricing page a couple days ago considering spinning up a droplet to self host a git thing.
- stevenicr 3y agonot sure if I was clear enough for the downvoters to get it, ddos the ips and have DO charge the spammers / hackers a fee is the point.. Not that I advocate for ddos - I think it's a terrible thing, and I've been through it a few times. DO and OVH are my most blocked ip blocks on several servers. I also get some hetzner and aws and microsoft blocks a lot among others sure. Interesting that I just launched a brand new WP on a brand new domain, and in less than 24 hours half of the hack attempts are from DO ips. You could lecture me about reporting and blah blah. I've been down those roads spending literal months doing that. With DO's cheap boxes and rotating IPs it's not worth it, I just block the entire CIDR every time, today it's 157.245.0.0/16 and 174.138.0.0/17 If DO was serious about stopping these abuses they would offer a WP plugin or opt-in setting that could check data from wordfence and similar and easily see which of their boxes are being used to hack into sites, all this could be automatic, without the form filling and delays that are required.
- janejeon 3y agoAt the risk of sounding like the "why do you need DropBox if you have rsync herr derr" guy, why... do I need DDoS protection from my VPS provider if I have Cloudflare anyway?
- whitepoplar 3y agoIsn't it trivial to discover the origin IP and then just hit it directly?
- andersa 3y agoIf you set it up correctly, it's not possible.
- Sebguer 3y agoDepends on the usecase, and whether you're shelling out the huge sums for Cloudflare Enterprise. Don't think there's too many cheap options for obfuscation if e.g. you're hosting a game server, which also happens to be one of the most common DDoS targets.
- berkle4455 3y agoyou deny all, accept <cloudflare IPs> to the machines actually serving content.
- stavros 3y agoHow would you?
- charcircuit 3y agoone method is to look up what IPs someone owns and try to direct connect to them. Or you can just guess and assume they picked an IP address near the start of the block they have.
- stavros 3y ago
- revskill 3y agoOne question, what's current best practice for DDOS prevention on my own VPS Ubuntu box ?
- bombcar 3y agoDon’t get DDoS’d or use a provider that has built-in DDoS protection. Depending on what you’re using it for you could “cloak” it.
- revskill 3y agoWhat if the situation is the provider doesn't have built-in DDos protection ?
- bombcar 3y agoThen you switch providers, go behind something like cloud flare, or contract with a DDoS protection provider (there aren’t many). If it is an unimportant service you just suffer the DDoS or switch IPs. Or you use a front end on a VPS that does have DDoS and use a IPv6 tunnel or tail scale to connect to your actual service.
- roncesvalles 3y agoWell you just have to find a way to eat the traffic without using up too many resources. Rate-limit by IP, drop certain types of packets, cache aggressively, respond to 400 errors with empty response, timeout long-running requests etc.
- lxchase 3y agoDepends what you are protecting. A website or http traffic? Stick it behind cloudflare. Services on other ports or protocols like TCP or UDP? You could rent a cheap VPS at a provider that DOES have inline protection and use that instance to reroute traffic to your own server via a GRE tunnel.
- GartzenDeHaes 3y agoD/DOS protections mostly have to happen before the network packet reaches the OS. Handling the incoming data request requires enough OS resources to be used for DOS. There are some things you can do application wise, such as avoiding reflection and amplification attacks. https://blog.cloudflare.com/reflections-on-reflections/ https://blog.cloudflare.com/reflections-on-reflections/
- nazgulsenpai 3y agoI have some cheap(east) VPS with OVH that I didn't even know had DDoS protection until I got the emails that my host was temporarily migrated to mitigation infrastructure during a DDoS, and back a few minutes later. Was pretty impressed especially since I don't pay extra for it or even know I had it!
- taskforcegemini 3y agoit benefits them, since DDoS will take down not just your VPS, but more infrastructure along the way. there are probably downsides as well, like blocking crawlers from search engines
- lifelong 3y agoFor comparison, I believe AWS LightSail users might be covered for DDOS protection for free but maybe I'm reading too much into their statement. https://docs.aws.amazon.com/waf/latest/developerguide/ddos-standard-summary.html https://docs.aws.amazon.com/waf/latest/developerguide/ddos-s...
- capableweb 3y agoMight be "free" but then you also have to endure using AWS LightSail which you'll regret quickly.
- vizzah 3y agoI run a couple of dev instances on LightSail and a couple on EC2 - what exactly is the difference one should be observing there? (except intended by design)
- iKlsR 3y agoDO killed 2 of our production server some weeks ago erroneously due to an issue on their end that claimed we were part of a ddos attack. Took us an entire week to recover properly... maybe this might have helped... also was promised credits for the downtime but never received them, minor after the fact as we're pretty happy with the service overall. > The Incident: Beginning at 17:10 UTC, May 9th, multiple DigitalOcean customers experienced Droplet network outages due to an action on Droplets by an automated mechanism. This mechanism has been in place at DigitalOcean since 2019. It helps us ensure that any potentially compromised Droplet seen participating in an outbound Denial of Service attack is quickly taken offline. This is in place to assist in protecting all DO customers by ensuring we have a network focused on delivering legitimate traffic at speed and scale, unencumbered by illegitimate traffic. When triggered, this mechanism suspends networking capabilities on the Droplet or Droplet-based services temporarily to allow the owner to investigate the issue. Users are informed via a support ticket and email that details the paths to recovery. This incident was triggered by an unannounced data change made by a third-party, which DigitalOcean uses to assist in analyzing traffic flow and metrics, as well as detecting malicious traffic patterns. Due to this mechanism constantly running and no changes being made directly by DigitalOcean, our teams were delayed in beginning an incident response. After multiple reports from customers that they believed the notification of outgoing Denial of Service attacks from their Droplets were false positives, an internal incident was declared to investigate the issue and start remediation efforts. After a thorough investigation by the DigitalOcean Security and Networking teams, the root cause was discovered to be an erroneous change made by a third-party service that reports data on traffic. Contact was established with the third-party, and they confirmed a change had been made. Investigation began on their side, and they confirmed there was a bug causing bad data to be returned from their API. Remediation of this incident was done through multiple paths. Complete resolution was achieved once the third-party rolled back the change that was made, which was causing bad data to be reported to DigitalOcean systems. Before that rollback was able to be put in place, DigitalOcean took direct action to take the automated mechanism that disables Droplet networking offline, given the suspected bad data. The support teams also worked throughout this incident to directly address customer tickets and re-enable networking on impacted Droplets.
- DoItToMe81 3y agoOVH offers DDoS protection for free, and BuyVM for around 3 bucks a month. This is an awful deal.
- remram 3y agoThis is very tangentially related, some comments here made me think of this: What happened to the DDoS Open Threat Signaling (RFC 8811) protocol? Do any of the many service providers, most of which include some sort of DDoS protection, use this system at all? https://www.rfc-editor.org/rfc/rfc8811 https://www.rfc-editor.org/rfc/rfc8811
- lxchase 3y agoVery vague. Doesn’t specify if it is in-line or offload. Linode, with some research you can figure out they use Corero appliances that will cover 40 gbps floods. Also didn’t see what their policy on tweaks are and or expectation on mitigating a more advanced attack. I.e. DNS, NTP floods are low hanging fruit but it doesn’t take much nowadays to do something more custom.