13 ms·
Someone has been attempting to DDoS us for weeks and we do nothing
- ddorian43 3y agoA nice thing about modern cloud providers is their expensive bandwidth so a new vector of attack is simply downloading large files that they host. (except cloudflare)
- NKosmatos 3y agoNice one :-) “… => Thus, we build a monolith service for each app, which is easy to deploy and maintain. No Docker, no Kubernetes, no dependencies, no runtime environment - just a binary file that can be deployed on any newly created VPS. …”
- tuwtuwtuwtuw 3y agoI don't use TablePlus myself. Are they talking about their marketing website? If so, then obviously thet wouldn't need to use Kubernetes. Are they talking about their application then I wonder how there can be no dependencies - don't it store data, log things, etc?
- tux3 3y agoYou can store data by connecting to a database, and you can store logs by either sending them to the system journal and having a daemon collect them, or sending them to whatever cloud you like using a logging library. It's fine, really. Those database and logging services you can put in a docker if you like, but if you put them anywhere else it works just the same. A Postgres in k8s or a Postgres on a dedicated server is the same as far as the client is concerned.
- tuwtuwtuwtuw 3y agoBut isn't that software you download and run in your own environment? I'm mostly not following what is under a DDoS attack. Is it their web page mostly consisting of marketing material with static pages?
- gnuvince 3y ago> I'm mostly not following what is under a DDoS attack. Is it their web page mostly consisting of marketing material with static pages? Yes.
- tuwtuwtuwtuw 3y agoOkay, well then this was a waste of time.
- ortichic 3y agothey talk about storing logs and separating databases, so good question
- TheRoque 3y agoYep, I'm wondering the same thing. It seems easy to brag about using only one binary if you don't need to use another service e.g. a database.
- iamcalledrob 3y agoThis is such a fantastic benefit of Golang: spin up a VPS, apply some sensible defaults, cross compile then run your binary. Compare this to deploying python, node or php... Needless complexity. If only running (and keeping running) a database server could be this straightforward!
- binarymax 3y agoNowadays you can bundle a node app as a single binary file. It’s an underused feature, maybe it will catch on.
- enva2712 3y agoI saw that deno did this but cool to see node picked it up too. I wish there was an option to run turbofan at build to generate the instructions rather than shipping the entire engine, but i guess that would require static deps and no eval, which can’t really be statically checked with certainty
- binarymax 3y agoThe engine is actually pretty small. Something like 50-100MB if memory serves (when I was using pkg)
- dgellow 3y agoCould you share how that can be done? I spent some time this year trying to pack a node tool into a single fat binary for a specific use case where we wanted a history of versioned executables - i.e a build job that needs to run specific versions of the packed tool in a specific order determined by external factors. I tried Vercel pkg, Vercel ncc, nexe, and a few other tools I can’t remember right now. They all had issues with node v20, some dependencies, or seemed to not be maintained anymore. I ended up relying on esbuild as a compromise to get a fat script containing all sources and dependencies, tarballed with some static files we rely upon we can at least get versioned, reproducible runs (modulo the node env). Still not perfect, a single binary would be preferable
- oldpersonintx 3y ago[dead]
- tluyben2 3y agoSimilar problem and similar-ish product 0]; we get DDoSsed a lot and I don’t know why. We had to put Cloudflare botfight to stop it. That works very well, but what do you do if CF doesn’t exist? 0] https://flexlists.com https://flexlists.com
- mastermedo 3y agoI might be out of touch with reality, but billions of requests per month sounds like peanuts. Is that considered a big ddos attack?
- drewdevault 3y agoIt depends on a lot of factors. Generally people provision infrastructure according to its expected usage, and to overprovision is wasteful.
- mastermedo 3y agoI see, that makes sense. And automatic provisioning can be costly in instances like ddosing.
- anonzzzies 3y agoDepends who is paying for that? Self hosted that’s not a problem, but ‘serverless’ that’s usually costly at those levels, especially for worthless traffic.
- heythere22 3y agoYour correct. 1 billion requests per month is 380 requests per second on average which is not that high
- fragmede 3y agoassuming they're smeared equally across the whole month, that is. Eg if the majority of those requests kick off a job at midnight on the first of the month, it's a bit more to deal with.
- logtempo 3y agoit's 2.3/second not 380
- avoid3d 3y agoHow are you arriving at that number? 60 seconds per minute 60 minutes per hour 24 hours per day 30 days per month ~2.59 million seconds per month One billion requests into 2.59 million seconds is 386 requests per second.
- samyar 3y agoThis is the first time hear the word "Monolith" What is it and how can one learn about it.
- keybored 3y agoIt’s a kind of word which only makes sense as a negation to its antonym. Because if the antonym didn’t exist then it would just fade into the background as “normal”.
- doctor_eval 3y agoIt just means that there is one big binary that does everything, instead of a bunch of microservices communicating over a fabric of some kind. As someone who thinks microservices actually simplify a lot of things, especially in complex domains, the idea that a monolith is a choice makes me cringe a bit. I mean they start out simple, but ...
- robwg 3y agoThem be fighting words. Tell some others orgs I've worked at that microservices are simple and they would laugh. But yes it depends on the complexity of your domain/org.
- kryptiskt 3y agoThe idea of unnecessarily replacing nanosecond scale function calls with network communication that is five orders of magnitudes slower makes me shiver. Yeah, you can make a microservice that does one thing with a well-defined API and it's nice and clean. But you might as well make a module that does one thing with a well-defined API, and it will be so much faster because it's right there in memory with you.
- doctor_eval 3y agoIf you’re replacing nanosecond function calls with microservices, you’re doing it wrong. It’s a specious argument. In the domains in which I’ve worked, most services receive calls over the network, and go on to make database calls that also go over the network. So whether you do the routing inside or outside a monolith makes almost no difference to latency. And what’s more, with a front end like GraphQL, you can parallelise the work which reduces latency further. Microservices have a lot of benefits relative to monoliths, but they aren’t a panacea any more than monoliths are. They’re a useful architecture for certain workloads and a poor fit for certain others. But in my experience it’s quite a lot more difficult to maintain discipline over the long term with monolithic architectures, and that’s why I tend to prefer microservices attached to messaging architectures like NATS. YMMV, and that’s fine.
- ThePhysicist 3y ago4 TB per month isn't really a DDoS attack, no? 4 TB per hour might qualify as a DDoS, but 4 TB per month is just 1.5 MB / second. 6 million requests per months are just 2 requests per second. I'd say the fact they run a monolith service isn't really relevant at this scale, especially as I assume Cloudflare handles most of the requests through caching them at the CDN level.
- saagarjha 3y agoI guess that depends on how irregular the traffic is.
- ThePhysicist 3y agoSure, if every request triggers a very complex database transaction or computation, but if I understand correctly this is a simple file download endpoint that's probably cacheable.
- n4r9 3y agoI think OP means that the 6 million requests might not be evenly spread. They might only occur during 5 minutes of each day, for example. I don't know enough to know whether that's feasible.
- tbarbugli 3y agoI think its around 1TB a day, but indeed still very small.
- tutfbhuf 3y agoYes, you can rent a few dollar VPS from e.g. Hetzner (since Germany is mentioned in the blog post), and run a few wget commands in parallel in a loop on their 200MB setup file to easily reach 1TB a day. For a company, this should definitely not be something to worry about. However, if I were able to single out individual IPs that are attacking me, then I would simply block them, report them (use the abuse form from the hoster of the attacking IP), and call it a day. This way, you can at least hope that the hoster will do something about it, either by kicking the hacker off its platform or, if it is some kind of service reflection attack, inform the victim to close the security loophole on their server and remove themselves from the botnet. If your attacks originate from a vast amount of different IPs from Russia and China, consider geoblocking.
- razodactyl 3y agoI like this a lot: Why? Because the attacks are directed to someone who isn't bothered and wastes their own resources. I've been a Table Plus user for near a decade now and enjoy the simple but highly compatible software they provide.
- vdddv 3y agoIs there any way to know who's behind a DDoS attack?
- thenthenthen 3y ago[flagged]
- pknerd 3y agolol
- kopos 3y agoA bit ingenious to say we do nothing when you have CloudFlare in front of your servers. Cloudflare by itself can automatically detect and handle DDoS without explicitly activating the Under Attack mode. Also Java jar files give you the same benefit.
- vintermann 3y ago> Also Java jar files give you the same benefit. You have to explain that one a bit more.
- RedShift1 3y agoYou can compile a jar to include all dependencies (like statically compiling C code), then you can just run `java -jar myprogram.jar` and it will work as long as the Java runtime is the same major version or newer than the version you compiled for.
- diarrhea 3y agoThat’s different from the runtime-free binaries produced by Rust and Go (binaries ship with tiny runtime) though. These are truly dependency-free, requiring only that you can execute ELF files.
- cwillu 3y agoIngenious doesn't mean what I think you think it means.
- worddepress 3y agoIt is ingenious to turn a mild attack into a 100+ point HN submission!
- sethammons 3y agoI think they meant disingenuous
- 3y ago
- everybackdoor 3y ago[flagged]
- vintermann 3y ago> we’ve simplified the deployment process as much as possible. We don’t use Docker, Kubernetes, or any containers, or need to setup the enviroment. This sounds like a dream, both in the sense that it's wonderful, and that I'm not quite sure I believe it.
- zilti 3y agoIt is very easy. Why do so many people torture themselves with complex setups? Masochism?
- cess11 3y agoWhen it's time for major shareholders and investors to 'exit' they don't want to market 'we did a simple setup', they want to be able to communicate twentyfive buzzwords incomprehensible to everyone directly involved.
- ahoka 3y agoSome companies run more complex things than download buttons.
- zilti 3y agoAt least they like to think they are doing that.
- headmelted 3y agoIt’s great that this isn’t hurting them but it leaves out a lot that makes me a bit nervous about this being taken as advice. They’re advocating deploying a binary as preferable to using docker, fair enough, but what about the host running the binary? One of the reasons for using containers is to wrap your security hardening into your deployment so that anytime you do need to scale out you have confidence your security settings are identical across nodes. On that, the monolith talked about here can be hosted on a single VPS, again that’s great (and cheap!), but if it crashes or the hardware fails for any reason that’s potentially substantial downtime. The other worry I’d have is that tying everything into the monolith means losing any defence in depth in the application stack - if someone does breach your app through the frontend then they’ll be able to get right through to the backend data-store. This is one of the main reasons people put their data store behind an internal web service (so that you can security group it off in a private network away from the front-end to limit the attack surface to actions they would only have been able to perform through a web browser anyway).
- llm_trw 3y ago>They’re advocating deploying a binary as preferable to using docker, fair enough, but what about the host running the binary? One of the reasons for using containers is to wrap your security hardening into your deployment so that anytime you do need to scale out you have confidence your security settings are identical across nodes. There is no universe in which _increasing your attack surface_ increases your security.
- headmelted 3y agoI agree in principal but not in practice here. If you’re using a typical docker host, say CoreOS, following a standard production setup, then running your app as a container on top of that (using an already hardened container that’s been audited), that whole stack has gone through a lot more review than your own custom-configured VPS. It also has several layers between the application and the host that would confine the application. Docker would increase the attack surface, but a self-configured VPS would likely open a whole lot more windows and backdoors just by not being audited/reviewed.
- aaron695 3y ago[dead]
- block_dagger 3y agoReminds me of Nietchze’s Genealogy of Morals quote: I’m strong enough to allow that.
- 082349872349872 3y agoThe latin equivalent: aquila non captat muscas ("eagles don't hunt flies") Anyone have the cuneiform expression for 80/20?
- keybored 3y agoI can learn to resist anything but a flogged mare
- cess11 3y agoSyphilis is one hell of a drug.
- ur-whale 3y agoPublic boasting as a mitigation strategy, that's got to be a new one. Not entirely sure it's a wise approach given the deeply asymmetric infrastructure costs of DDoS attacks, especially if the attacker has access to a botnet. [EDIT]: in other words, there is a non-zero probability that the attacker, piqued by the boasting, might be able at the flick of a switch to increase the intensity of the attack by a factor 1M.
- PreInternet01 3y agoI'd hardly call that a DDoS attack: from the description given, the extra 8TB-or-so of monthly traffic seems to fall under "annoyingly pointless abuse of services"... As long as such abuse doesn't cause monetary or resource exhaustion concerns, it's quite OK to ignore it, but stories like "whelp, turns out that 80% of the capacity of our auto-scaling fleet is not doing anything useful" are depressingly common enough to at least keep an eye on things. My annoyance with this kind of abuse revolves mostly around logging: a majority of logs just showing the same set of hosts displaying the same pointless behavior over and over again. Again, not a huge issue if your log storage is cheap and plentiful (as it should be), but having some kind of way to automatically classify certain traffic as abusive and suppress routine handling of that is definitely a good idea. It's also a lot harder than it sounds! I can't count the number of times I've added classification logic to my inbound SMTP server that should pick up on outright, silly abuse (of which there is a lot when dealing with email), only to have it triggered by some borderline-valid scenario as well. Spending way too much time on going down successive rabbit holes is a great way not to get any real work done -- a great reason to outsource, or, if that's too much work as well or just too expensive, indeed just ignore the abuse, annoying though it is...
- Borg3 3y agoYes!! Great idea.. Keep ignoring them. So they feel more encouraged to do more fishy things. That attitude made todays internet pretty much swamp.
- PreInternet01 3y agoThe TL;DR of my comment is "I personally enjoy implementing automated solutions to relatively-low-volume abuse, but as long as it doesn't cause you any capacity concerns, I fully understand ignoring it, since it's hard" Using that as a reason to assign me responsibility for the state of the internet seems... slight hyperbole?
- Borg3 3y agoIt wasnt directed at you as person, but as an idea. Not sure if you ever did abuse report, but they are mostly ignored. Thats the problem. Everyone just waves the hand like, it doesnt make capacity issues, we can ignore it. Sure, until its too late. Maybe I am overly paranoid, but seems that old russian maxima is reasonable: Fight when they coming for cent, because when they will come to take dollar it will be too late.
- CanaryLayout 3y agoYeah Goroutines are great. Then add something like WebRTC to your project that realistically tops out at 10000 listeners, and people wonder why Twitter Spaces is so buggy...
- bun_terminator 3y agoI guess this is an ad, so I'll bite: Why is the mac download button featured so centrally, while there appear also to be downloads for other platforms, too? It's not like that's a usual default.
- troupo 3y agoTheir original product was Mac-only, and they added other platforms only recently
- filleokus 3y agoWas hoping for something more swole dog worthy when reading the headline. Even though I agree with much of the advice, being behind Cloudflare is definetly not nothing. Depending on the distribution of the traffic they might have survived well on VPS's without Cloudflare anyways, doesn't seem that large. Would be interesting to see more detailed stats of rps and how much (if any) Cloudflare stopped before they got it. Russian layer7 ddos'es that I know of targeting Swedish companies have been large enough that major providers run into capacity problems and fall over (including Verizon, Azure Frontdoor, Cloudflare, GCP's Load balancer). This strategy would absolutely not work against those volumes.
- tromp 3y ago> our setup file is approximately 200MB > we keep things as minimal as possible Wonder what's in that file that makes it need to be that large...
- speedgoose 3y agoTablePlus supports quite a few databases. It adds up.
- vasco 3y agoBragging about this has to rank up there as the worst idea in the world. If your hole argument is taunting would be attackers with your wallet - saying you're more overprovisioned than the traffic they can send, you're just threatening them with a good time. At another time in my life I'd take this post as an invitation, even, specially because the numbers shared are super low. I've had 3 situations where my place of work was under DoS attack, in the 3 cases I managed to identify an email address and reached out asking why they are doing it, and if they want to talk about our backend. In 1 case, the "attack" was a broken script by someone learning how to program, the other two were real attacks and one of them just immediately stopped once they knew we knew who they were, the other actually wanted to chat and we emailed back and forward a bit. 99.99% of the time a DoS is someone who is bored. Talking to them tends to work. Edit: there's some questions about the situations so I'll expand: - The first was not a real attack, and they were doing the network calls through their authenticated API key. This was early days of a YC startup so of course there was no rate limiting in place. In this case I exchanged 2 or 3 emails and after they sent me their python script I sent them back a patch and they finished their scraping without bringing us down. Never heard from them again - The second was at a different company, we were getting targeted to distribute email spam, because at the time we'd allow people to invite their colleagues as members of their account, and some people associated with casinos based out of Macau automated a way to spam their casinos by putting the URL in the name of the account, which went out in the email notification. I contacted one of the admin emails of one of the casinos I found and they stopped and disappeared. In this case we also locked all their accounts and prevented further logins + emailed them to reach out to support if they thought it was a mistake. - The third one was more difficult, they weren't using any account, so all we had was network. At some point on the second day though they changed how they were sending some of the calls, and by mistake or not leaked their Telegram username. I installed telegram and talked to them, they trolled me a little bit, but stopped very quickly and didn't start it again. This one was very amusing to people in my company because I had told them this approach would work but a few of the big wigs didn't want me to do it (they didnt have any reason other than "obviously won't work to just talk"). I just did it anyway. To be clear, you shouldn't reach out with some threats or how you're so good that you found them. My approach is of genuine curiosity, and my literal first message to the telegram person was: "Hello, how is it going? I work at <companyname> and we're seeing a load of requests originating from your user here on telegram. Does this make any sense to you or do you think I might have the wrong person?" That's it!
- hntddt1 3y agoIt's going to a point where that directly find out the person behind it is cheaper than fix the bug. People nowadays don't pay respect to the hard working people anymore
- pknerd 3y agooff topic but you guys have done solid SEO. You query anything related to SQL/syntax and tableplus will be in front of you.
- rs_rs_rs_rs_rs 3y agoUsing TablePlus and I would wager it's not the SEO but the quality of the tool.
- pknerd 3y agoWhat does a tool have to do when I'm purely searching for a certain MySQL/SQL syntax? TablePlus has done an awesome job of writing brief articles about different SQL syntax and its usage in TablePlus.
- oefrha 3y agoThis is just a static marketing site for a desktop app. They don’t even have a discussion forum — feedback is handled by GitHub issues. Bragging about how simple their deployment is for a static marketing site and how it’s able to handle a static file being downloaded millions of times a day is super weird. And Cloudflare is doing all the mitigation work here (if that’s even needed for such a puny amount of traffic), not them. If I were to be hit by such an "attack" myself I probably wouldn't even notice until Cloudflare sends me that monthly "X TB of data transferred, something close to 100% bandwidth saved" email. I like the app btw, can recommend.
- naiv 3y agoI like the app as well but to me it also sounds like 'ChatGPT, create an unusal marketing post', it all doesn't make sense, even less for people who have experience with real ddos attacks.
- deleted 3y ago[deleted]
- mamcx 3y ago> Bragging about how simple their deployment is To the contrary, I wish more people do this: The more people know that their overly complex infra is sub-optimal the better!
- kbar13 3y agonot really that interesting of a post. billions of requests per month is like low hundreds of requests per second. billion is a big number but so is a month when it comes to request throughput. all the grandstanding about monolith... for something that serves 2-3 requests per second, and is a static marketing site... this is so overblown.
- KingOfCoders 3y agoDoesn't look like a real DDos attack to me with the traffic numbers (of course, No true Scotsman). 4TB/200mb = 5000.
- dugmartin 3y agoIt feels like they didn't learn the root lesson - move your 200MB setup file to a subdomain. You shouldn't host large assets like this on the same domain as your marketing/app site even if there is a CDN fronting it because an attacker can simply add a random query string to bust through the CDN cache and cause the cache miss to hit your box. The subdomain should be hosted on a different box and fronted possibly with a different CDN provider so that any large scale attack doesn't affect your marketing/app site (either due to your CDN provider or upstream network provider temporarily black holing you).
- viraptor 3y ago> an attacker can simply add a random query string to bust through the CDN cache You can configure the cache so that they can't do it: https://developers.cloudflare.com/cache/troubleshooting/cache-everything-ignore-query-strings/ https://developers.cloudflare.com/cache/troubleshooting/cach... Without knowing their specific configuration, we don't have enough info to complain about that. Also the separate domain doesn't really change much with CF in front. It could be nice for a few reasons, but it's not really bad. If you have a reasonable CDN already, there's really not much point getting a different one.
- _ache_ 3y agoPeople has broken CI/CD so we do meme. Not sure if 6M/m is a lot. Looks like not that much.
- AtNightWeCode 3y agoThose numbers in the screenshot from Cloudflare represents requests to Cloudflare, not requests to the origin. It includes cache hits.
- sethammons 3y agoThat's not a noteworthy "attack"; that could be a single runaway bash script on someone's machine. 50MM requests per month "from the UK" averages out to under 20 requests per second. I would expect a single Go server to handle 250 times that request volume before optimizing much. Their advice isn't bad per se, but their numbers are not a testament to it. I expect for my Go HTTP API services to handle 5k requests per second on a small to medium VPS when there is some DB activity and some JSON formatting without doing any optimizations. This is based on deploying dozens of similar services while working at a place that got multiple billions of requests per day, spiking to over 500k rps.
- jameshart 3y agoIf you’re getting that kind of traffic hammering your API with repeated requests, but it’s all from non-sketchy locations, don’t think ‘DDoS’, think ‘did we accidentally put an infinite retry loop in our client code?’
- pheatherlite 3y agoWhy do they need an app server at all? The website, to my initial glance, seems to be a brochure for the desktop product. Surely static pages and static assets would be even more resilient against a ddos since it's just bog standard webserver streaming out the static resources. Mount a memory based fs and conventional disk latency concerns become mitigated, too.
- eknkc 3y agoI think they have a licensing server which handles device authorization and auto updates.
- sameoldtune 3y agoPet peeve of mine. “Billion requests per month” is about 370 rps. Which can be likely handled by a single well configured server. Certainly less than 10 servers. A single rogue bash script could cause that much traffic
- groestl 3y ago> can be likely handled by a single well configured server. A single core, actually, after JVM JIT kicked in.
- cjk2 3y agoThanks to microservices we need 45 kubernetes nodes to handle our 1000 requests a second!
- injuly 3y agoAssuming those requests are evenly distributed over time, yes. But in the event of an attack you would see a sudden surge in requests followed by a flatline, and still end up at 1B/month over 30 days.
- deleted 3y ago[deleted]
- andrewmackrodt 3y agoThe architecture of the app didn't seem related to the "DDoS" attack they're describing. If it's only their setup file being downloaded, I imagine their backend isn't even touched, doubly so if they're using cloudflare for caching.
- wigster 3y agoTHATS not a DDos attack! when i were a lad...
- lopkeny12ko 3y agoThis reads as extremely self-congratulatory. A "billion requests per month" is only a few hundred requests per second, which is both trivial and not a "DDOS." Also, their site is behind a CDN (Cloudflare), so I'm extra confused on how they think they did something notable from a performance perspective here. For example, there's no reasonable world where that 200 MB blob is not cached and served over CDN. I can't imagine someone would be so proud that their application server isn't reading 200 MB from disk and copying those bytes to the client on every download; it's just so obviously poor design.
- helsinkiandrew 3y agoIf the 200MB files they are referring to are the TablePlus client side app downloads (183MB for windows) at https://tableplus.com/download https://tableplus.com/download The files are indeed cached by CF: # curl -v https://files.tableplus.com/windows/5.9.2/TablePlusSetup.exec > /dev/null ... < cache-control: max-age=691200 < cf-cache-status: HIT < age: 2980
- hartator 3y agoSo, there are serving virtually zero bits from their servers.
- helsinkiandrew 3y agoTo be fair that was only one of the files they mentioned - the rest could be going to their server on every hit.
- thinkingemote 3y agoI thought cloudfare would only cache web files like html and images and not actual files? This caused problems with some of their users as seen previously on HN Or is that only with the free tier?
- tgv 3y agoIt's rarely a few hundred per second. Request density is nor uniform over time. It can regularly reach 20x the average.
- sylware 3y agoIt is like computer viruses. DDoS attacks do benefit some specific corps, for instance cloudflare. What's very important is to build DDoS resistant infrastructure without them, to rid of the incentive to shadow-hire hackers to DDoS and force some infrastructures to move there and pay them. There is too much suspicion in the digital world nowdays. Like current crypto is not mainly for shaddy ops and mafia? Really?
- ckdarby 3y agoLiterally laughed when they're talking about language choices for a billion requests per month. I've got nodejs lambda code that is doing 388B/month and only at this point have we even considered changing the language for performance because the cost savings have a net positive ROI. It took 5 years to get to this point.
- dewey 3y agoAlmost sounds like a buggy update process of their app that they shipped.
- dsign 3y ago> When using binaries, you can let Linux Systemctl handle the process “Systemctl” instead of “systemd” ? Hm, do I detect reticence to publicly admit the undeniable, vast superiority of systemd by confusingly using the name of the utility?
- PaulHoule 3y agoDownloading a setup file is not the way to bring down a site. My experience in the HDD era was that people laugh at you when you do a lot of requests like that but call the FBI on you (at least here in the States) if you insert a lot of random users into their database. (Each of those requires a transaction and each of those requires waiting for the disc to spin around unless they had a nice battery-backed write cache)
- d_burfoot 3y agoThis content was very useful to me, as I am running a small service for a few clients that I worry might be taken down by a DDoS. The main takeaway seems to be "use a CDN", but if you are running a more complex service, why can't the attackers hit endpoints that aren't CDN-cached? Is the strategy in this case simply to refuse the request very early in the process, to ensure the service doesn't waste much time processing it?
- nojvek 3y agoThe other point here was that billions of requests per month is only 2 requests per second. That can easily be done on a one core server if you use an efficient web language like go/rust/nodejs. Tableplus is a simple marketing site that serves the binary via cdn. Most of the time when a site goes down is because it is doing something very CPU intensive either at the app layer or the Database layer. E.g an expensive query. If queries are hitting indexes and app is doing simple auth, routing and sending queries to DB, it’s hard to DDOS it easily. With things like Cloudflare pages and functions, someone could hit it with billions of requests/month and you’d still be in standard $5/month tier. They could download terabytes off CDN and you’d have $0 cost. It’s pretty radical how much you can build on Cloudflare on their free tier.
- deleted 3y ago[deleted]
- b0x68 3y agoWhat does “heete” mean?
- neya 3y agoThis is the dumbest thing I've read on HN today. "We do nothing..because we can." This speaks volumes about your attitude towards security as a business. If I was your enterprise client I wouldn't really be happy reading this.
- memothon 3y agoA post like this seems kind of dangerous. Just asking someone to fire their cannon at you! Beware.
- deleted 3y ago[deleted]
- aoeusnth1 3y agoWhy is billions of request per month so exciting to the authors? That’s only ~100 QPS, which a single-core application should be able to handle easily. Wake me up when you have hundreds of millions of QPS of DOS load.
- welzel 3y agoThis is so cute. The webpage could be fully static, served from a raspberry as it is hiding behind a CDN anyway and the DDOS is not even trying. Anyhow, doing the same with a high traffic application would be a very very different animal, specially when the app has 100k+ active daily users and is doing actual stuff. The advice is not bad, but it sounds so silly. From experience every time a commercial web application was build as a monolith it became very hard or even unmaintainable in a few years, specially when 15+ Teams are constantly contribution. So pick the right hammer for the problem you have, but pretending a simple marketing webpage + payment/subscription is a good example for architecture is just a bit much.
- trickpa1 2y agoYou should try to protect yourself from it using cloudflare or something like that. here is one site which you can use to test your protection https://topstresser.net/#pricing https://topstresser.net/#pricing