7 ms·
> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core arg
by throwaway150 11mo ago
> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!"
If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a service. Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. Speaking from experience. Very much the reason I'm posting this with a throwaway account. If your website receives DDoS, your hosts will take down your server. Nobody wants to be in this situation even if for a personal, small blog.
- phyzome 11mo agoIf you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?
- throwaway150 11mo ago> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run circles around their support staff to bring back the website up again, then I guess, you don't have a problem. It's nice that you don't care. (Honestly speaking. Not being sarcastic at all.) Personally, I wouldn't mind DDoS on my personal site if the problem was just the DDoS. Unfortunately, mostly it isn't. A DDoS has other repercussions which I don't want to deal with exactly because it's a personal site. I just don't want to spend time with customer support staff to find out if and when I can bring my website back up again. DDoS on my personal website by itself isn't all that bad for me. But having to deal with the fallout is a pain in the neck.
- TZubiri 11mo agoStarting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.
- dymk 11mo agoThat’s like saying you should buy car insurance after you wreck your car
- unethical_ban 11mo agoThat's like saying my personal blog going down is as impactful to my health and finances as getting into an automobile accident. Assume a "personal" blog or site is not making money for the owner, and they have backups of the site to restore if the VM gets wiped or defaced. Why spend money on DDoS protection if it is unlikely to ever occur, much less affect someone monetarily?
- jimmydorry 11mo agoDepending on the host, you may get charged a big bill for traffic. If you're hosting at home, your ISP may blackhole all traffic to your residence (affecting your day job and being a nightmare). When it comes to DDoS, most providers are quick to blackhole, and slow to unfreeze, without getting the run around.
- bmicraft 11mo ago> If you're hosting at home, your ISP may blackhole all traffic to your residence (affecting your day job and being a nightmare). That's a very big stretch. Worst case you need to stretch to wifi tethering from you phone, which isn't much more than mildly annoying.
- variadix 11mo agoDepends on the distribution of accidents and the distribution of costs. If P(ddos) * Cost(ddos) < P(no ddos) * P(cloudflare outage) * Cost(cloudflare outage) then you would be better off not using Cloudflare. This is not considering other issues with Cloudflare, like them MITM the entire internet and effectively being an unregulated internet gatekeeper.
- graeme 11mo agoIt sounds like OP is describing a situation where someone persistently DDOS's them as long as it works. In which case DDOS time trivially dominates cloudflare outage time. Note that OP is posting, even now, from an anon account. This is a good essay: https://inoticeiamconfused.substack.com/p/ive-never-had-a-real-adversary https://inoticeiamconfused.substack.com/p/ive-never-had-a-re...
- huijzer 11mo ago> Note that OP is posting, even now, from an anon account. Lol I didn't even notice that my submission reached the front page. What is your evidence for that claim?
- graeme 11mo agoOh sorry, not you. The OP in the chat thread, they were DDOS'ed by someone and are commenting anonymously. Maybe grandparent is the correct word for it, in any event this is the comment I was referring to when I said OP, not your article: https://news.ycombinator.com/item?id=45966683 https://news.ycombinator.com/item?id=45966683
- MallocVoidstar 11mo ago> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Your host, assuming you're hosting your site on a VPS. Many of them have a policy of terminating clients who get DDoSed.
- woodrowbarlow 11mo agoand if you're hosting on your home network, a DDoS means connectivity problems for your home.
- bluGill 11mo agoNot just your home, it means connectivity problems for your neighbors. In turn your ISP will shut you down if they figure out what is happening.
- dpoloncsak 11mo agoI have my personal site behind CF because I'm hosting it locally. Wouldn't a DDoS like....affect my internet?
- nijave 11mo agoFor our SaaS, the uptime probably isn't much different but the cost definitely is. If any of your stack has usage based billing, things can get very expensive quickly.
- iLoveOncall 11mo agoMy blog was constantly going down for unknown reasons, with nothing obvious in the logs. I migrated it to CloudFlare and was able to track down the root-cause of the issue. I also blocked all the AI crawlers after moving to CloudFlare and have stopped a huge amount of traffic theft with it. My website is definitely much more stable, and loads insanely faster, since moving to CloudFlare.
- encom 11mo agoI need SponsorBlock for HN, this is ridiculous.
- iLoveOncall 11mo agoI don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog. It's not because it's not a criticism that it's a sponsored post. I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without: - First Contentful Paint: 0.4s - 0.7s - Largest Contentful Paint: 0.8s - 0.9s - Total Blocking Time: 0 ms - 0 ms - Cumulative Layout Shift: 0 - 0 - Speed Index: 0.4s - 8.9s The difference is quite staggering, and I'm located pretty close to my server (a Hetzner VPS), I can't imagine the difference for someone that lives across the world.
- encom 11mo agoSure, but your post reads like an infomercial, hence the snark. NARRATOR: - "Has THIS ever happened to you?" CUT TO: Black-and-white. Some guy stares in frustration and confusion at a terminal. Output of 'cat /usr/bin/gcc | xxd' or whatever scroll by. NARRATOR: - "Introducing CloudFlare™!" CUT TO: Full color. Sunlight. The same guy now sprawled on grass at a park. Two dogs tackle him with adoration. His kids hand him ice cream. NARRATOR: - "Stop debugging. Start living."
- jajuuka 11mo ago
- odie5533 11mo agoIt's like insurance. If you add up everyone's medical expenses, it's less than we all pay for insurance. But if you're the one getting hit, it matters a lot.
- wsatb 11mo agoThen who cares if your site is down for a few hours once in a blue moon because the auxiliary service in front of it is down?
- giancarlostoro 11mo agoI mean I'm not worried about it either, but I've been on the internet long enough that I know some of the people I used to know will probably do it just to do it. Gamers can be quite toxic.
- rcxdude 11mo agoThe downtime cause by DDoS. It's now an endemic problem in the modern internet. Even relatively tiny communities suffer from it, because it's so damn easy to do.
- swiftcoder 11mo agoWhat's the actual cost to me of my blog being offline for a few hours? Basically nothing. Certainly less than the couple of bucks someone might spend on a DDoS service
- hrimfaxi 11mo agoWhat's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?
- blibble 11mo agothey (and whoever they have hiding in the shadows behind them) can intercept or directly man-in-the-middle attack anything you or your customers do less reliable (more hops -> less reliable) dependence on the US regime
- superkuh 11mo agoWell, if you do that than human people like myself won't be able to load your blog behind cloudflare for as long as it's behind cloudflare. A much longer and more insidious denial of service targeted to those who cloudflare doesn't think are profitable.
- sph 11mo agoWhat’s the cost of making the internet more centralised because of sheer laziness?
- cortesoft 11mo agoDo you think a world where all the commercial websites are centralized, but personal blogs are not, is that different than a world where blogs are also centralized? What is the benefit to having small blogs be decentralized?
- wat10000 11mo agoIf everything is centralized then nobody can discuss topics that have been decided to be off limits by the moderation teams at a few large companies.
- superkuh 11mo ago>a valid security strategy Here's your confusion: personal sites don't need a valid security strategy. They don't need nine nines uptime. They don't need CDN, and ability to deploy, etc, etc. That's all (and forgive the origins of the expression but it is the most accurate description) cargo culting. There's no issue if they're down for a couple days. Laugh it off. Whereas if you put your site behind a defaults of a cloudflare denial of service wall then real human people won't be able to access your site for as long as you use cloudflare. That's much longer and many more actual humans blocked than any DDoS from some script kiddie. Cloudflare is the ultimate denial of service to everyone that doesn't use Chrome or some other corporate browser. And forget about hosting feeds on your website if you're behind cloudflare. CF doesn't allow feed readers because they're not bleeding edge JS virtual machines.
- deleted 11mo ago[deleted]
- AndroTux 11mo agoAdd to that, once an attacker has your server's IP (because it wasn't behind a CDN in the first place), it's basically impossible to fend off the attack unless the attacker is not very bright, or you swap your server's IP.
- brightball 11mo agoAgreed. I plan to continue using Cloudflare for everything because it's a phenomenal service at a great price.
- deleted 11mo ago[deleted]
- kryogen1c 11mo agoYes, to rephrase: you dont need ddos protection if you dont get ddos'd (just dont get attacked lol). Well no shit, thanks for the advice. As you say, the risk is not a temp outage for small users, the risk is your isp or host or whatever disowning you.
- bunderbunder 11mo agoMeanwhile the maintainer of Bear Blog - very nearly the poster child for small blogs with 100 visitors per month - recently put up a post talking about how much extra infrastructure it takes to keep the service online in the face of the massive uptick in AI scraper bot traffic we've had over the past few years. I haven't tried managing my own site in ages, but I get the impression that the modern Internet is pretty much just one big constant DDoS attack, punctuated by the occasional uptick in load when someone decides to do it on purpose instead of out of garden variety apathetic psychopathy.
- MattSayar 11mo agoMy small personal blog with tens of readers a month gets thousands of hits a day from bots. The ROI there must be worthwhile for those bots but not for me to self-host
- terminalshort 11mo agoAlways has been... https://www.fourmilab.ch/documents/netslum/ https://www.fourmilab.ch/documents/netslum/ [2004] But, yeah, it's gotten way worse to the point where you can't even run legitimate services because sometimes you will be blocked just for not being a known entity. e.g. try running your own email server and sending mail to any major email provider.
- immibis 11mo agoThe AI DDoS, in my experience, is a few requests per second. You can just serve them.
- tjwebbnorfolk 11mo ago> Hopes and prayers do not make a valid security strategy. True, but they are free and effortless, unlike "appropriate controls and defenses"
- udev4096 11mo agoWhich is why you mirror your small blog across multiple networks. Use Tor, I2P, etc. Most blogs are git repos so it's very easy to distribute it
- elAhmo 11mo agoYou think someone would DDoS you because you made a comment like this on HN? Seems a bit overly cautious.
- kopirgan 11mo agoDo providers offering VPS have a layer of protection against such attacks? It might overwhelm their routers etc too?
- bombcar 11mo agoSome do, and it depends on what layer the attacks are coming in on. Low-level attacks most or all providers have some protection against (to protect their network itself) but that may include black holing your IP at the border routers. Few offer higher level DDoS protection that isn't rewrapped cloud flare or competitor.
- sitzkrieg 11mo agoa little niche cuz they're primarily a game server provider but nuclearfallout is the most proactive provider i've seen to do this, on vps or dedicated hardware. there has been many times they've worked with upstream bw providers and automatically holed incoming ddos, noticed packet loss and abnormal routing etc, before even reaching end user interfaces- been using them for decades and they've been incredible for this, at least for the US options (prem/internap)
- Dma54rhs 11mo agomany VPS providers want to get rid of you if you're on receiving end of the attacks as well. since you threaten the stability of their operations.
- kopirgan 11mo agoThanks.. Trying to understand the issue bit better if you can bear with me.. Let's say you manage to install some cloudfare equivalent in your Vps so your hands are clean. That still exposes the provider systems up to that point, eating up resources? Or they'll still knock you off and ban your IP at the first point of entry itself.. Cos where that leads us is subscribing to cloudfare type service almost becomes inevitable.. You can't get around it with some free software running in your own box.
- lxgr 11mo ago> Nobody wants to be in this situation even if for a personal, small blog. I would gladly be in this situation if it otherwise lets me remove a large source of complexity, avoid paying a few bucks, and increasing the avoidable centralization of the Internet on my personal, small blog. Maybe I'd change my mind if it continues happening, or if I didn't have unlimited traffic (which is a very bad idea for many reasons other than DDoSes for personal sites), but otherwise, enabling Cloudflare for a hypothetical without consequences seems like pretty extreme premature optimization.
- theodric 11mo agoI'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)
- lxgr 11mo agoOk, this is definitely even cooler than self-hosting a blog on Hetzner :) How are you using Cloudflare for this? Via Cloudflare Tunnel? I'm currently unfortunately also behind double NAT, and my home server has been unreachable ever since as a result. I've been torn between using Tailscale Funnel, Cloudflare Tunnel, possibly a VPN with public IPs, or rolling my own thing based on reverse SSH forwarding to a Linux server with a public IP.
- theodric 11mo agoYes, local nginx http server in a Debian container on a Raspberry Pi, and Cloudflare DNS and argo tunnel providing public IP and SSL.
- wat10000 11mo agoDDoS is not a security issue for a small blog. It's a reliability issue, and reliability probably isn't that important. And to the extent that it is important, it's not at all obvious which choice is going to get me better reliability. I'm not going to YOLO an actual security issue and, say, use my zip code as the password on a publicly-facing ssh service or something. But DDoS protection? Meh.
- dzonga 11mo ago> The author seems to be completely missing that it takes only a few bucks to buy DDoS as a service. Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. thank you. thank you. thank you. we are tired of hot takes on the internet due to opportunism. yeah even the small sites are being tested everday by bots. how the bots know your site just came online - I don't know. so yeah cloudflare is nice. we hate centralization on the internet - but to be naive that they're no bad actors on the internet is pure stupidity.
- Loughla 11mo agoGenuinely I don't understand how people post under their own name or connect their accounts to their real identities at all. I learned early that my opinion can piss people off (even though I think I'm pretty milquetoast to be honest), and there are people with enough time and hate to make their disagreement with you impact you personally. I started using a pseudonym about the time my consulting site got taken down by a DDoS attack because I voiced an opinion about a presidential candidate who's name rhymes with Meorge Mush Munior. People are awful.
- LoganDark 11mo agoWell, the first profile I ever had was an Xbox account that was based on my real name, and I just carried that username onto everything else. So I just ended up having a username based on my real name everywhere. And I never bothered to restart my social life to get a new one.
- mmmlinux 11mo agoA DDoS back then was what, one guy banging F5 on his keyboard for a while?
- duxup 11mo agoAnd if my blog with a few hundred visitors goes down because of a Clourdflare outage ... so what? People act as if outages are some solvable problem and each outage should never have happened and we need to act (cloud no cloud, firewall rules, and so on) each time. Rather I think history has shown this stuff happens and if the impact is terrible ... fine.
- deleted 11mo ago[deleted]
- pclmulqdq 11mo agoWhy would AWS take down a VPS over a DDoS?
- huijzer 11mo ago> Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. People come with that argument so often. But then one day I was completely done with something and I put out a rant on Reddit in my real name. Hundreds op people disagreed and told me "Why do you do that under your own name?! Are you crazy? This will lead to many problems." Guess what. This was months ago and nothing happened. Nada. Zero. Null. I have many servers running and nothing was taking down. Maybe one day it will. If that happens then I'll find a fix. It will probably not be a nice day, but it is what it is. The world will keep spinning. I'm done giving in to the fear. "I must not fear. Fear is the mind-killer. Fear is the little-death that brings total obliteration. I will face my fear. I will permit it to pass over me and through me." -Frank Herbert, Dune
- throwaway150 11mo ago> Guess what. This was months ago and nothing happened. Nada. Zero. Null. Just because it didn't happen to you does not mean that it doesn't happen to others. You can see a few anecdotes in this thread itself where people commented that they did get attacked for pissing people off. Like check this: https://news.ycombinator.com/item?id=45968219 https://news.ycombinator.com/item?id=45968219
- eduction 11mo ago> Hopes and prayers do not make a valid security strategy It’s not “hopes and prayers” to actively decide a particular attack vector is unlikely enough that the the costs and risks are not worth it. My local cafes and bars do not employ bouncers, but the local concert venues and nightclubs do. All these places want to keep out outside food and drink and avoid violence among patrons. The local cafes and bars decided it’s not worth having a bouncer for that. That’s a valid decision.
- wmedrano 11mo ago"valid security strategy" Did you mean reliability? At this point I don't care if my server gets DDoS, but may be more convinced by security practices.
- troupo 11mo agoAlso: AI scrapers. Which have already been documented to basically DDOS sites.
- arp242 11mo ago> Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. I've received death threats. Do I engage in charged political commentary on my site? Not really. Just vaguely left-of-centre stuff in a way that I feel moves the discussion forward (and not even that often). The internet is fun: you're instantly connected to every unhinged asshole lunatic in the world.
- axelthegerman 11mo agoCDN is not the same as DDoS protection. Cloudflare does both but some providers do one or the other. You can use any CDN no matter if you use Cloudflare or not (shout-out to Bunny CDN btw, very happy with them - they do one thing and do it well)
- jesuswasjew 11mo agoI wish online discourses didn't feel like engaging with possible shills for corporations as it did during 2000s, or maybe it didn't. Maybe, we became too aware and critical or maybe there is absolutely no honest discourse possible when commerce, political or even ideological agendas are involved. The best stance should one that presents varied solutions to a common problem.