Skip to content

DDoS protection on budget hosts is a placebo

Reviews by pieter_rtm 24 replies 3.8K views
8 #11

So the unnamed five are: Hostinger, RackNerd, CloudCone, BuyVM, VirMach, LetBox? That is six. Plus the OVH reseller makes seven. Hetzner makes eight. I can count.

My real question: did anyone get their money back? TOS says "best effort" but EU law says false advertising. Milan is not Rotterdam but we have the same directives.

#12
mahdifilch said:
Did anyone get their money back?

I did not ask. The test was six months, some were annual plans, the cost was acceptable as research. I am not a consumer seeking remedy, I wanted to know what actually happens.

That said, Hostinger's "DDoS Proteccion" on the invoice is now a running joke in my office. We have it printed on the wall.

Liam_funky: your point about amplification is correct. My 500kpps direct is roughly equivalent to 5-10Mpps reflected depending on protocol. These providers advertising "5Mpps protection" likely mean "we hope the amplification does not reach us."

Containers before it was cool
#13

Atlanta perspective: RackNerd's datacenter here is not actually in Atlanta, it is in Duluth which is fine, but their upstream is not. I tracerouted my own box there and it hits GTT then Cogent then sadness. No amount of "protection" helps when your upstream depeers aggressively.

I moved that workload to Vultr Atlanta proper last year. Same city, different network, completely different stability. The DDoS protection question is really an upstream question for budget hosts.

9 #14

Frankfurt perspective: I did two years in Hetzner support, left in 2021. Their DDoS protection is not magic, it is just capacity. They own the pipes, they peer heavily at DE-CIX, they can absorb. The "protection" is "we have more bandwidth than you can saturate and we do not panic."

The budget hosts panic because they lease. When your upstream is $2/Mbps committed and you sell at $5/month, 500kpps of anything is an existential threat to your margin. Null routing is the rational economic choice. The lie is pretending otherwise.

Single mode till I die 💀
#15
jane_ffm said:
The lie is pretending otherwise.

This. This is the core thesis. I do not blame a $5 host for null-routing. I blame them for advertising "protection" in bold letters on the homepage.

Updated spreadsheet:

  • Hetzner: real, keep
  • OVHcloud: real but disruptive (priya's websocket issue confirmed by others)
  • Vultr: real only with paid add-on
  • All others tested: placebo

I will publish this to r/webhosting when pieter_rtm's pcaps drop.

#16

Following. Also interested in the pcaps.

I have a LetBox storage VPS in their LA location. Never tested the protection because who attacks a storage VPS? But now I wonder if they would null-route my IP and how long recovery takes. Their control panel has no "remove from null" button, it is all tickets.

#17

Vilnius perspective: Hostinger's datacenter here is real, I have visited. The issue is not the building, it is the network design. They run everything through a single edge cluster for cost. When that cluster saturates, null route is the only tool.

I worked at a similar provider in Kaunas. We did the same thing. "DDoS protection" meant "we have a firewall rule that logs." The marketing department added the rest.

I am not defending Hostinger. I am saying the economics are universal.

#18

12ms to Frankfurt, 180ms to everywhere I actually need, and apparently 0ms to being null-routed by budget hosts.

I have Hetzner in Falkenstein and a CloudCone in LA for a side project. The CloudCone is now on my list to migrate. Not because I expect attacks, but because I now know their "protection" is a fiction and I prefer honest fiction.

Thanks pieter_rtm. Straight paths indeed.

1ms or I don't want it
#19

Same here. I have two VirMach instances from their black friday sales. One is already dead from a "network issue" that lasted three weeks. Now I understand the pattern.

This thread saved me from renewing the second one.

#20

Did anyone test OVHcloud directly? Not the reseller, the actual product. Their "Anti-DDoS" is standard on all plans and they have actual scrubbing centers. I am considering them for a project in Beauharnois but the Strasbourg fire makes me nervous about their operational discipline.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft