Skip to content

DDoS protection on budget hosts is a placebo

Reviews by pieter_rtm 24 replies 3.8K views
#1

Hot take backed by data: DDoS "protection" on budget hosts is theater. I spent 6 months testing 8 providers under $10/month, all advertising "DDoS protection included."

Methodology:

  • Controlled traffic from my own lab (legitimate test packets, no amplification)
  • Graduated from 100kpps to 2Mpps, well below advertised thresholds
  • Monitored via provider looking glasses and my own upstream taps

Results:

  • 5 of 8 null-routed at <500kpps (advertised: 1-5Mpps)
  • 2 applied "mitigation" that dropped 40% legitimate traffic
  • 1 (Hetzner) actually held to advertised limit

To be honest, the null-routing is not surprising. As said, transit costs money. What angers me is the false advertising. I have packet captures. I have RTT graphs showing clean drops, not congestion. I will name names.

Provider lawyers may reach me at [email protected]. I am ready.

Containers before it was cool
3 #2

(I was going to make a joke about how "DDoS protection" on a $5 VPS is like a screen door on a submarine. But that's unfair to screen doors, which at least know what they are.)

Pieter_rtm, this is excellent work. The methodology is sound. The sample size is reasonable for the space. Have you considered publishing the raw pcaps? (Not the full payloads, obviously. Just headers and timing.) The community could replicate.

Also. Which of the unnamed five threatened you first? (My money is on the one with the badger mascot. They always lawyer fast.)

#3

Today I learned my "protected" vps from Hostinger is probably fake forever thanks pieter I guess I should have known when they spelled it "DDoS Proteccion" on the invoice lol but seriously tho this is why I run everything behind Vultr now at least they admit they dont protect you and charge extra for it honesty is cheaper than lawyers

#4

1. This thread is important
A) false advertising hurts everyone
B) especially small operators
2. I currently use:
A) Hetzner — based on this data, keeping them
B) RackNerd — need to test now
C) CloudCone — same
3. Pieter_rtm, questions:
A) did you test with anycast destinations?
B) was attack traffic tcp or mixed?
4. If legal action happens:
A) I will contribute to defense fund
B) others should too
5. Naming names is necessary
A) consumers have right to know
B) "best effort" is not "5Mpps guaranteed"

#5

Which 8 providers? You only named Hostinger.

#6
mahdifilch said:
Which 8 providers? You only named Hostinger.

Hetzner, Hostinger, RackNerd, CloudCone, BuyVM, VirMach, LetBox, and one reseller white-labeling OVH in Strasbourg. I will not name the reseller because their TOS has a "no benchmarking" clause and I do not need that headache. The other four are already named by others in this thread.

Raw pcaps: I am cleaning the headers now. Will post a torrent link when ready, probably next week. The lab is just three old Dell R620s in my garage pushing GRE, nothing exotic.

Containers before it was cool
#7
pieter_rtm said:
Hetzner, Hostinger, RackNerd, CloudCone, BuyVM, VirMach, LetBox

BuyVM and VirMach — that explains the null-routing. Both use ColoCrossing or similar upstreams for their cheap plans. ColoCrossing's standard response to anything spicy is automatic null for 24 hours, "mitigation" is just an email template.

I will still test my own RackNerd box because their marketing says "DDoS Protected" not "best effort." Different claim, different liability.

A) anycast — no, all single-homed
B) mixed UDP/TCP SYN, some ICMP for baseline

Your methodology is conservative. Real attackers use amplification. If they cannot handle 500kpps direct, they would vaporize under 50Mpps reflected.

#8
pieter_rtm said:
One reseller white-labeling OVH in Strasbourg

OVH in Strasbourg. There is only one thing that datacenter is famous for and it is not DDoS mitigation.

I am not touching the "no benchmarking" TOS with a ten foot pole. Those clauses are unenforceable in the UK under consumer rights law but I am not a lawyer, I just read contracts for fun. Ask me how my marriage ended.

Actually do not.

#9

I run a small Nagios setup for a fintech in Bangalore and we tested this properly last year. Hetzner held. OVHcloud held but their "vacuum" scrubbing killed our websocket connections for 90 seconds every time. Vultr with their paid protection ($10/month add-on) held without dropping legitimate traffic.

The budget Vultr instances without the add-on? Same as pieter_rtm's results. Null route at 300kpps, email saying "your IP has been automatically removed from null, please upgrade to DDoS protection."

At least Vultr is honest about the upsell. The others pretend the base product does something.

2 #10
liam_funky said:
BuyVM and VirMach — that explains the null-routing

BuyVM at least sells real protection as an add-on in Vegas. Their "standard" is garbage but the +$3/month Filtered IP actually works. I tested it with a stresser in 2022 for a client, held 800kpps no null. Not amazing but real.

VirMach is just a black hole with a website.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft