Hot take backed by data: DDoS "protection" on budget hosts is theater. I spent 6 months testing 8 providers under $10/month, all advertising "DDoS protection included."
Methodology:
- Controlled traffic from my own lab (legitimate test packets, no amplification)
- Graduated from 100kpps to 2Mpps, well below advertised thresholds
- Monitored via provider looking glasses and my own upstream taps
Results:
- 5 of 8 null-routed at <500kpps (advertised: 1-5Mpps)
- 2 applied "mitigation" that dropped 40% legitimate traffic
- 1 (Hetzner) actually held to advertised limit
To be honest, the null-routing is not surprising. As said, transit costs money. What angers me is the false advertising. I have packet captures. I have RTT graphs showing clean drops, not congestion. I will name names.
Provider lawyers may reach me at [email protected]. I am ready.