Skip to content

DDoS mitigation vendor leaked my attack data in a sales deck

Networking Locked by marchhopper 24 replies 4.2K views
This thread is locked — new replies are not accepted. (Closed: resolved)
#1

I attended a vendor webinar last Tuesday. The sales engineer presented attack data I recognized immediately. It was my own machines under DDoS in March. The graphs showed our peak traffic, our mitigation timeline, our infrastructure layout. I had signed an NDA with this provider. The contract specified confidentiality of all attack metadata. I recorded the session. I have timestamps. I am seeking counsel on precise contract language others have used to prevent this. -- Marcus

#2

This is very bad, server good friend ! The vendor is shameless ! How much cost the lawyer ? I check the NDA with the Vultr and the Leaseweb, actually the language is weak, is not specific about the data attack. ¿why not¡ we make together the template strong ?

#3

ABSOLUTELY UNACCEPTABLE! NAME THE VENDOR! BURN THEM IN THE REVIEWS! YOUR DATA IS YOUR DATA! NEVER HOSTPEERS THIS SLIDE! I HOPE YOU SUE FOR EVERYTHING!

42U and still growing
10 #4

Peak was 340 Gbps, scrubbing center in Frankfurt, 4 filtering layers. Vendor used it in sales = commercial gain. Check if your MSA has data use rider. Most don't. Anycast vs scrubbing path visibility matters here — they showed topology, not just volume. That's worse.

mitigated 800Gbps before breakfast
#5

NDA with "commercial gain" exception? I never see this clause

Vive la résistance... électrique
#6

Topology in a sales deck is way worse than volume, agreed

swimming upstream since 2019 🐟
#7

Which MSA rider, the data use one or the liability cap

POLISH SERVERS. LOUD FANS. GOOD PRICE.
#8

The data use rider. Liability cap is separate, usually 12 months fees paid. Data use rider is where they slip in "we may use aggregated telemetry for product improvement" and hope you don't notice "aggregated" is doing heavy lifting. Check if they defined aggregate as >1 customer or >100 customers. Some MSAs let them claim single-tenant data is "aggregated" because they averaged two numbers.

mitigated 800Gbps before breakfast
#9
danfra said:
Anycast vs scrubbing path visibility matters here

Frankfurt scrubbing center narrows it. How many providers have Frankfurt scrubbing? Not many. Even "anonymized" topology with Frankfurt ingress and 4 filtering layers is basically a fingerprint. I have seen two decks in my career that matched single customers this way. Both were from the same vendor.

9 #10

My German company use Leaseweb Frankfurt. The MSA say "anonymized statistics" but no definition. I ask legal, they say is standard. I think is not standard, is trap.

POLISH SERVERS. LOUD FANS. GOOD PRICE.

Thread closed

Replies are closed on this thread. Closed: resolved.