by delano on 9/12/24, 8:14 PM with 6 comments
Some of you might remember us from over the years. In particular I know it's a common refrain that our encryption sucks. I can say that the reason it hasn't been improved is that our number 1 competitor is folks doing nothing. That is, not using anything at all to protect password and other sensitive info. We are working on improvements though and will get to it, but right now, we urgently need help with DDoS mitigation strategies. We've tried increasing our server capacity and implementing server-level traffic filtering, which has had limited success. The ongoing attack is overwhelming though. And definitely beyond what I would consider manageable with HAProxy ACLs and fail2ban.
This attack is obviously impacting our ability to serve our users. Any advice on immediate actions, recommended services, or long-term strategies would be immensely appreciated. I'm open to all suggestions and willing to provide more details if needed.
Thank you, HN community, for any help you can provide in this tender and critical time.
by william00179 on 9/12/24, 11:58 PM
Since from your post this looks to be a layer 7 attack your options would either be putting your service behind Cloudfront or Cloudflare and using their respective ddos mitigation tools. They also can provide support to get things configured and working effectively.
There are other similar solutions out there that I've not had experience with so can't comment on, but utilizing one of the hyperscale services will be your best bet.
by delano on 9/12/24, 8:26 PM
https://docs.onetimesecret.com/blog/2024-09-12-ddos-day-4
https://docs.onetimesecret.com/blog/2024-09-09-denial-of-ser...
by mahin on 9/12/24, 8:30 PM