4 ms·
> pay Google, Amazon or Cloudflare a protection tax. Just FYI: hetzner has free DDoS https://www.hetzner.com/unternehmen/ddos-schutz https://www.hetzner.com/un
by vmfunction 3y ago
> pay Google, Amazon or Cloudflare a protection tax.
Just FYI: hetzner has free DDoS https://www.hetzner.com/unternehmen/ddos-schutz https://www.hetzner.com/unternehmen/ddos-schutz
I'm sure other hosting companies also offers it.
- tpetry 3y agoOnly for mini DDoS attacks - for larger ones they disable routing for your ip address. I guess they don‘t have the capacity to handle the big DDoS attacks nowadays.
- tmpX7dMeXU 3y agoYep, and null-routing your IP is exactly what providers did in the days GP is longing for, and still do do, especially outside of big cloud providers.
- ilyt 3y agoDoesn't really work for those types of attacks > In this final layer, we filter out attacks in the form of SYN floods, DNS floods, and invalid packets. We are also able to flexibly adapt to other unique attacks and to reliably mitigate them. Which means any legit http2 connection will go just fine. Even if such connection now triggers hundreds of substreams. Push for end to end encrypted internet also means you can't really stop any more advanced attack. You could have just few dozen of hosts doing 20-30 connections each (i.e. "looking perfectly normal" for DDoS protection provider) generating tens of thousands per second in http2 streams. I'm speaking from experience of mitigating attack like this. Our DDoS provider was near-useless..
- bombcar 3y agoFor the higher layer attacks you have to have something like the "modified cryptominer in the browser" things that cloud flare and friends do now - those interstitial pages that pop up for a few seconds are doing mathematical hashing to burn processor time on your end - which greatly complicates the ability to DDoS.