‹ BackHN Continuity

Thread

August 27 TCRF DDoS Attack Postmortem

34 points · 14 comments · panic

  1. ndiddy · · focus · HN ↗
    It's kind of sad that we've gotten to the point where if someone decides they want to fuck with you, there's nothing you can do besides using a service like Cloudflare. I wonder how much cumulative time the "Checking your browser..." screen has wasted.
    1. toast0 · · focus · HN ↗
      Cloudflare or similar services are certainly convenient.

      Depending on the scale of the volumetric attack, you do have other options. There's plenty of low end hosts selling 'unmetered' 10G severs. I'd bet most attacks are smaller than that. It may take some tuning to drop garbage that fast, but it's doable on 10 year old hardware. My bet is most of these unmetered servers are using for outbound, and the inbound directly is underutilized... so the host probably won't mind as long as the volume isn't too big... If you consistently get DDoSed, maybe it helps your host have balanced in and out and that may qualify them to peer with networks that have a lot of botted hosts.

      If you get more than 10G inbound garbage, you can try renting multiple servers and round robin DNS...

      DIY options beyond that are going to be spendy. You'd need to get an ASN, an IP allocation, and BGP privileges... Start advertising your IP range from all your 10G servers and that will distribute the garbage at least a little.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.