7 ms·
> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on
by throwaway150 11mo ago
> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?
Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get.
If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run circles around their support staff to bring back the website up again, then I guess, you don't have a problem. It's nice that you don't care. (Honestly speaking. Not being sarcastic at all.)
Personally, I wouldn't mind DDoS on my personal site if the problem was just the DDoS. Unfortunately, mostly it isn't. A DDoS has other repercussions which I don't want to deal with exactly because it's a personal site. I just don't want to spend time with customer support staff to find out if and when I can bring my website back up again. DDoS on my personal website by itself isn't all that bad for me. But having to deal with the fallout is a pain in the neck.
- TZubiri 11mo agoStarting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.
- dymk 11mo agoThat’s like saying you should buy car insurance after you wreck your car
- unethical_ban 11mo agoThat's like saying my personal blog going down is as impactful to my health and finances as getting into an automobile accident. Assume a "personal" blog or site is not making money for the owner, and they have backups of the site to restore if the VM gets wiped or defaced. Why spend money on DDoS protection if it is unlikely to ever occur, much less affect someone monetarily?
- jimmydorry 11mo agoDepending on the host, you may get charged a big bill for traffic. If you're hosting at home, your ISP may blackhole all traffic to your residence (affecting your day job and being a nightmare). When it comes to DDoS, most providers are quick to blackhole, and slow to unfreeze, without getting the run around.
- bmicraft 11mo ago> If you're hosting at home, your ISP may blackhole all traffic to your residence (affecting your day job and being a nightmare). That's a very big stretch. Worst case you need to stretch to wifi tethering from you phone, which isn't much more than mildly annoying.
- variadix 11mo agoDepends on the distribution of accidents and the distribution of costs. If P(ddos) * Cost(ddos) < P(no ddos) * P(cloudflare outage) * Cost(cloudflare outage) then you would be better off not using Cloudflare. This is not considering other issues with Cloudflare, like them MITM the entire internet and effectively being an unregulated internet gatekeeper.
- thfuran 11mo agoBut you can just download a new car.
- hypeatei 11mo agoUnless your server literally starts on fire because of DDoS, no it isn't. Your things will be just fine after an attack, it isn't that serious.
- shortrounddev2 11mo agoNo its like saying you should buy a new battery after your battery dies. Yeah, its nice to have a spare battery around i guess but its not like your battery dying will significantly ruin your finances
- c22 11mo agoIt's more like buying the plug-in version after the battery dies... You already experienced the downtime, so if not having downtime was a goal you already failed. If avoiding downtime is not important then there's no reason to add anti-downtime capability to your system. The most charitable modeling of this approach is that the downtime incident may prompt one to realize that avoiding downtime actually is an important property for their system to possess.
- Dylan16807 11mo agoThe actual charitable model is that you expect close to zero attacks, but if you actually get hit your expected rate of future attacks goes up by an order of magnitude or two. And it's that change in expectations that gets you to buy protection. You don't care about going down once, you do care about frequent outages. And you know this from the start, you don't realize it later.
- c22 11mo agoI'm not so sure. The risk of future attacks hasn't actually increased, your initial risk assessment was just incorrect.
- Dylan16807 11mo agoYes, the original assessment was wrong. Such things happen all the time to reasonable people. The person you were describing in your "most charitable" version above was not being reasonable. They didn't just underestimate the petty anger of the internet, they were being fundamentally foolish about their own desires. That's why I replied, to show you a different way someone could end up in this position.
- alwa 11mo agoHow? Isn’t it more like the difference between carrying an umbrella every day and ducking into the corner shop to buy one when you notice it’s raining?
- Johnny555 11mo agoThat's a good analogy since the corner shop is going to be sold out of their small stock of umbrellas during the rain storm so you won't be able to buy one until the rainstorm is over but at least you'll have protection for the next storm. If staying dry is important to you, you should buy the umbrella before the rain.
- nmz 11mo agoNot if you live in a desert, which most blogs do.
- Johnny555 11mo agoThat continues the analogy -- it doesn't rain often in the desert, but almost all deserts receive rain. And since it rains so rarely, you're certainly not going to find an umbrella during the rainstorm. So again, if staying dry in the rain is important to you, buy an umbrella before the rain, if you don't care about getting wet from time to time, then no need for the umbrella. While the personal blog owner may not care about DDoS related downtime, he may face extra usage charges due to higher bandwidth, CPU usage, etc that he'd like to avoid.
- nmz 11mo agoThe people you see in a desert with umbrellas are not using it for the rain, but for shade, the rain is the least of their problems.
- Johnny555 11mo agoEven in a desert, people still use umbrellas for protection from the rain: https://lasvegassun.com/news/2016/jan/19/fast-moving-storm-brings-rain-across-the-valley/ https://lasvegassun.com/news/2016/jan/19/fast-moving-storm-b... And the rain still causes problems, even (or maybe especially in) a desert: https://nypost.com/2022/07/29/las-vegas-braces-for-more-rain-after-city-punished-by-floods/ https://nypost.com/2022/07/29/las-vegas-braces-for-more-rain...
- phyzome 11mo agoMy site being down for a couple days is not an unacceptably large loss, unlike an uninsured car being wrecked. It also isn't a good analogy because insurance doesn't apply retroactively to wrecks that happened before start of term, and is event-based rather than providing continuous value.
- Johnny555 11mo agoI thought that's why it's a good analogy - DDoS protection doesn't apply retroactively to prior attacks (or even current attacks, it's hard to apply DDoS protection while your site is down due to DDoS). If you want protection from DDoS, you need it before the DDoS. If you want to insure your car in case of accident, you need to insure it before the accident.
- bmicraft 11mo agoIf the incident lasts for more than a few hours you could still set up ddos protection and rotate ips though.
- integralid 11mo ago>or even current attacks, it's hard to apply DDoS protection while your site is down due to DDoS Why? with cloudflare it's very easy, just put your site behind a reverse proxy, change the dns and disable direct access. Am I missing something?
- deleted 11mo ago[deleted]
- grayhatter 11mo agoSounds reasonable if the car insurance could magically and near instantly fix your car, undo all the property damage and no one could get injured. Insurance for physical things is different for services, they don't map as an analogy. A better one would be, Because you buy a new car every hour, it's like buying insurance for every car after someone steals your 700th car. That prevents your car from getting stolen.
- iso1631 11mo agoIt's like saying you should buy volcano insurance after you get hit by a volcano
- OkayPhysicist 11mo agoInsurance protects you from big expenses. What's the big expense here? Oh, my site's down for a bit.
- k4rnaj1k 11mo agoThis strategy requires you to be "on-call" for personal stuff. Honestly, I don't want to spend more time on pet projects than I already do. Or cutting some of it away on support instead of spending more on things I would actually be interested in. And resulting downtime might be even bigger than that with cloudflare.
- deleted 11mo ago[deleted]
- benmmurphy 11mo agoin the cloud you should be able to turnkey this quite easily. i think in a DC this can be a bit more tricky because you will still be getting traffic from the DOS to your network interface after you have flipped the switch to cloudflare. This traffic will cause both you and your provider a problem. but i think the idea is you would have two sets of IPs one for the normal public hosting, and one for cloudflare proxy then when you become under DOS attack you have a process in place for BGP to stop advertising the normal public hosting IPs and you switch to cloudflare. i presume if BGP stops advertising the IPs then eventually you will stop getting the DOS traffic.
- HumanOstrich 11mo ago> When you become under DOS attack you have a process in place for BGP to stop advertising the normal public hosting IPs and you switch to cloudflare. You think people hosting personal sites are going to even have the access to manage their IPs with BGP? It's not something I've seen offered at that scale / pricing.
- close04 11mo ago> then your host taking your website down and then you having to run circles around their support staff to bring back the website up again These are very different situations. With a DDoS the disruption ends when the attack ends, and your site should become available without any intervention. Your host taking down your site is a whole different matter, you have to take action to have this fixed, waiting around won't cut it.
- throwaway150 11mo ago> These are very different situations. It is obvious those two are very different situations. I'm not sure I understand your point. Yeah, nobody will be bothered by a short 15 minute DDoS attack. I prolly wouldn't even notice it unless I'm actively checking the logs. Sure, nobody is going to be bothered by that. But what if someone's DDoSing persistently with a purpose? Maybe they're just pissed at you. My point is... a sustained DDoS attack will just make your host drop you. So one situation directly leads to another and you are forced to deal with both situations, like it or not.
- close04 11mo ago> It is obvious those two are very different situations. I'm not sure I understand point. Your host taking down the site and forgetting to bring it back up after a DDoS attack isn't a common thing with any host, unless it's the kind that does this routinely even without a DDoS. And then you should look long and hard at your choice of hosting. Either you suffer from a DDoS attack and come back when it's over, or you have a host that occasionally brings your site down and fails to bring it up until you chase them. But one does not follow the other without a lot of twisting.
- NewJazz 11mo agoDDoS attacks are frequently shorting than 15 minutes. We've seen plenty of attacks last less than a minute.
- blueflow 11mo ago> a sustained DDoS attack will just make your host drop you I'd love to see someone suing the host for damages. The contract binds them as much as it binds you. Sounds like a good way to have your next gaming rig financed.
- wpm 11mo agoIf I wasn’t running my own personal site at home on a proxmox vm, why would I choose a hosting provider that doesn’t do DDOS protection themselves?
- samtheprogram 11mo agoYou keep saying stuff like "the fallout" and "the repercussions" but then the only example you can provide is talking to customer service to bring your stuff back online. Is that it? Honestly speaking, not being sarcastic at all.
- RijilV 11mo agoSo the internet is a series of pipes, or tubes, whatever. This quintessential personal blog website is hosted somewhere in this inter connected mess of things. There’s a hierarchy of these pipes/tubes, and they all have some ever diminishing capacity as they head from a mythical center to the personal blog website. When the bad guys want to DDoS the personal blog website they don’t go and figure out the correct amount they need to send to fill up that pipe/tube that directly connects the personal blog website, they just throw roughly one metric fton at it. This causes the pipes/tubes before the personal blog website to fill up too, and has the effect of disrupting all the other pipes/tubes downstream. The result is your hosting provider is pissed because their infrastructure just got pummeled, or if you’re hosting that on your home/business ISP they also are pissed. In both cases they probably want to fire you now.
- q3k 11mo agoThis is incorrect. Any decent host/ISP will instead (automatically, sometimes) emit a blackhole request for the given target IP address to their upstreams, causing the traffic to be filtered there (at the 'larger pipe'). In turn, these upstreams can also pass on the same blackhole request further up if necessary. This means the target is down from the point of view of the Internet, but there is no collateral damage. See: BGP Blackhole Community (usually 65535:666).
- ralferoo 11mo agoInteresting, I didn't realise blackholes were special-cased to allow BGP announcements of /32 instead of the usual /24 or larger. I'd just assumed (like the GP) that the traffic ended up on the target's closest network to the source and only then was it filtered.
- tcfhgj 11mo agoMy hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz https://www.hetzner.com/unternehmen/ddos-schutz
- internetter 11mo agoIn my experience hetzner DDoS protection doesn't work
- mananaysiempre 11mo agoAs long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.
- internetter 11mo agoYeah I suppose by "doesn't work" I should clarify that maybe it is doing something and preventing some attacks, and that it doesn't take down my server. With that being said, it has certainly failed to mitigate attacks on numerous occasions that cf would've.
- amy_petrik 11mo agoI'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal
- axelthegerman 11mo agoThis!! Everyone seems to "really need" that unlimited scalability of AWS & Co - but they'll happily scale your compute and the bill for you. Sure maybe you'll get lucky and they waive it. But sometimes going down is a feature if you're not a multi m/billion dollar business
- eurleif 11mo ago
- nalekberov 11mo agoThis is mostly scaremongering, not all hosting providers take your site down just because someone you pissed off decided to DDoS you. In Russia (I have nothing against Russia - I just know this info about “Дождь ТВ”), some news websites have been targeted by state-baked DDoS attacks, but I highly doubt most people are in this category.
- immibis 11mo agoDid they put it back up when the DDoS ended? If so, they're not hurting you since it's no worse than the DDoS itself, and they're actually helping you by preventing themselves from having a reason to ban you to save the rest of their sites.
- RandomBacon 11mo agoA forum I manage was DDoSed, but I think it was by (AI) content scrapers as no one expressed any issues or anger towards the forum. I temporarily got around it by blocking the subnet of their IPs. I have since put it behind Cloudflare.