7 ms·
> The ddos attack was focused on a file on my site. Yes it’s partly my fault to put a 3.44MB size sound file on my site rather than using a third-party platform
by bArray 3y ago
> The ddos attack was focused on a file on my site. Yes it’s partly my fault to put a 3.44MB size sound file on my site rather than using a third-party platform like SoundCloud. But still this doesn’t invalidate the point of having protection against such attacks, and limit the spending.
This is extremely sad. It's like we are taking steps backward. A 3.44MB should not be an issue and if it is, the answer should not be to host it elsewhere. If there is no other lesson learned here, it's that there is no such thing as 'free'. As others have said, there should be more done to prevent such large losses without some kind of limit.
I would also like to point out that VPS's are extremely cheap [1] and extremely easy to manage. They have automatic limits.
[1] https://lowendbox.com/blog/1-vps-1-usd-vps-per-month/ https://lowendbox.com/blog/1-vps-1-usd-vps-per-month/
- cpursley 3y agoVPSs being “easy to manage” is a strong option full of assumptions.
- ies7 3y agoI remember a comment from this site. Something like: we must study how Amazon and other big cloud's marketing work so great to make this generation developers think that vps or selfhosting are hard. IMO vps was easy before and even easier now to manage.
- kikimora 3y agoPlease explain how you rotate ssh keys, store audit logs, backup (and test backup procedures), configure secure network between vpses such that your neighbor cannot eavesdrop.
- deleted 3y ago[deleted]
- bcaxis 3y ago* You don't have to rotate what doesn't get out. Limit ingress to relevant IPs reduces this surface area a lot. * SCP to a system built for storage. Not really essential for many systems - system logs are fine. * Every VPS provider comes with a backup check box. * Tailscale is really simple.
- kikimora 3y agoThis is how you protect one small server, you don't need cloud for this. But if you do use it for a small server you'll overpay a lot in relative terms and small amount in absolute terms.
- dpatterbee 3y agoI think on a $5 vps that you're using to host a small website you simply just don't do those things.
- messe 3y agoFor my personal stuff, when it comes to SSH key rotation and secure networks, I like to let Tailscale deal with both. It handles SSH authentication for you via your SSO provider, so there's no need to rotate keys. (Aside: you shouldn't really be using SSH keys to begin with at anything but a small scale. SSH certificates are much more flexible)
- troupo 3y ago1. You didn't do that on a VPS 2. Often there would be a cPanel plugin/extension/app/config value (if the hoster enabled it for you) that would just do for you what you needed.
- tlb 3y agoYou don't need to do any of that for hosting a content website. The content & config are pushed by rsync/ssh from a git repo, so there's no need for backups. I can recreate a server in half an hour. I guess I lose the webserver logs, but I rarely look at them so I don't care. A single server has plenty of bandwidth for a personal site, so there's only one EC2 instance and no secure network is needed. If I need more bandwidth, I'll use a load balancer but there's no need for secure connections between the load balancer & web servers because what's the eavesdropping threat model for a public content site? Let's Encrypt seems to deal with https key rotation without manual intervention. The cloud servers just have the usual ~cloud/.ssh/authorized_keys login setup, and I guess I rotate them every time a stronger crypto is recommended, which is 4ish times in 30 years.
- kikimora 3y agoIf it is just a content website then maybe yes. Cloud complexity probably won’t worth it. Still I can think of a corporate blog, and you have employees come and go then it became a problem even for a small website. Otherwise an angry admin can deface your website and damage your reputation. All other things like secure net won’t apply for a small website, of course.
- fabian2k 3y agoFor a simple use case this is not an issue. - you add your ssh public key to the hosting provider, so any new VM will have it automatically - you use the snapshot service of your hosting provider for backups. If you have a database, run a cronjob that dumps it so it's in the snapshots as well. Alternatively use any backup tool to backup files to somewhere else - you do not need a separate network for simple use cases. Just encrypt traffic if you have multiple servers, odds are you only have one here anyway.
- arandomusername 3y agoCloud is just merchant of complexity
- trog 3y ago> VPSs being “easy to manage” is a strong option full of assumptions. There are definitely many footguns with managing a VPS but I think the threshold to get vaguely competent with a VPS is not really that far off with getting familiar with the average cloud platform - which comes with its own dangers, like the near-total inability to put an upward cap on fees that that person found out with Netlify recently. Having a $5 VPS and knowing it's never going to cost your more than $5 might balance out a lot of things on the other side for a lot of people. (And, as a bonus, it comes with the benefit of having a better idea of what is going on on the actual computer which is running your code.) Platforms like https://coolify.io/ https://coolify.io/ (which I have not tried, but looks interesting) seem to give you some of the abstractions that you get in cloud platforms to save you having to mess with too much low level stuff and become an expert in a billion separate systems. If you have Debian with automatic updates that does most of the heavy lifting for you. The hardest problem I have is resisting the temptation to just install everything, because the cost to do it is capped at my VPS monthly fee. So yep, it comes with a lot of assumptions. But so does everything!
- 123yawaworht456 3y agoa basic bitch static website takes three commands in the terminal and a very basic nginx config file to setup on a completely fresh ubuntu VPS. you could read a guide from 2012 and it would work perfectly fine. is this harder than dealing with cloud 'platforms' and their ever-changing UIs, APIs, SDKs?
- easton 3y agomaybe? You go on Cloudflare's console, click on "pages", click on "new app", name it, drag your folder of website files in and you are done. automatic deploys are also available by linking a github account. It's probably one less click to get a droplet turned up on Digital Ocean, and then you have to configure nginx or caddy (which is like five minutes if you've done it before, 30 if you haven't). Probably worth doing if it's your livelihood and you're afraid of Cloudflare disappearing, but if it's just a mess around... eh.
- hnben 3y agowhat would be the price-tag here?
- cpursley 3y agoYes, this is harder. I don’t want to mess with maintaining or configuring nginx.
- dncornholio 3y agothen install PLESK or something, it's dead simple.
- mgkimsal 3y ago+1 vote for virtualmin
- arandomusername 3y ago`sudo apt-get install nginx` `vi /etc/nginx/sites-enabled/default` add your config, use chatgpt if you want, save `nginx -s reload` and bam! you're good to go, practically forever.
- ChrisMarshallNY 3y agoI won't run a VPS. I'm entirely capable of doing it. Badly. I'm a mediocre Linux admin, at best. The current environment is so dangerous, these days, that it's worth your life, to have your essential services run by a mediocre admin; even if I can convince myself that I'm the best (spoiler: I'm not). I'll generally run shared hosting, or managed servers.
- bArray 3y agoI can't speak for you, but it's really not too difficult to host some static content on a VPS. At the very worst, the VPS is compromised somehow, and you refresh it from the admin panel.
- ChrisMarshallNY 3y agoI'm not talking about static content. I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance. It's easy, sure. It's easy to create an insecure server, that can be pwned. I know of which I speak. I have done just that. "A man who holds a cat by the tail, learns a lesson he can learn in no other way." - Mark Twain
- bArray 3y ago> I'm not talking about static content. I think the person in the original article was, at least for the sound file. > I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance. It seems quite simple to me, you either learn security, or pay for the expertise of someone that has. You need to decide whether it's worth your time. I would suggest one thing, though - even with the likes of <big cloud>, they will only provide security in limited cases, i.e. DDoS. Nobody at <big cloud> is going to make sure your application logic works correctly - they clearly won't even make sure you use their resources within sensible bounds.
- arandomusername 3y ago
- pjc50 3y ago>> The ddos attack was focused on a file on my site. Yes it’s partly my fault to put a 3.44MB size sound file on my site rather than using a third-party platform like SoundCloud. And people wonder why there's only half a dozen websites any more and the "long tail" has vanished. You can post 3.44MB of audio to Facebook or Twitter and know that you'll never be billed for it.