Skip to content

DDoS protection on budget hosts is placebo

General Discussion by blogfranck 25 replies 3.6K views
#11
hades1995 said:
You can see it in the traceroute

Exactly. HostHatch doesn't advertise protection, but look at the path: GTT, NTT, Telia, actual diversity. When the Minecraft kid came back, traffic found routes around congestion. No scrubbing needed because the pipe is fat enough and the network is sane.

The honest providers are the ones who say "we have bandwidth" not "we have magic." Though HostHatch's Stockholm location did melt my wallet.

https://hosthatch.com

works on my bench ¯\_(ツ)_/¯
#12

Same here with a host in Brazil. "Protection DDoS" but the attack was 150Mbps and they null-routed me for 14 hours. In Buenos Aires my home fiber is 300Mbps symmetrical. The host had less courage than my ISP.

Now I run a dedi at HostHatch Amsterdam. No "protection." Survived a 1.2Gbps attack last month because the pipe is 10Gbps and I run nftables with connection tracking limits. The upstream did not care. The traffic arrived, I dropped it, life continued.

The marketing is the real attack.

hot air, steady hand, magic smoke
#13
sofialund said:
The marketing is the real attack.

Voilà. This is what I am saying. They sell you fear and then sell you the fake cure.

I am lucky, I have OVH in France. Their Anti-DDoS is real, included, no extra. Not perfect but the IP stays up. The budget hosts in US cannot compete because OVH owns the fiber and the scrubbing centers. Vertical integration.

But OVH is not $3/month. The price floor is real.

#14

OVH is also a nightmare to get support from. Real protection, real pain.

#15
blogfranck said:
OVH is not $3/month

And this is the arithmetic nobody wants to do. A scrubbing center costs: real estate, power, transit contracts with clean pipe return, engineers who understand BGP flowspec. Spread across customers at $3/month with 80% oversell? The math is insulting.

I have 14 status pages. Three of them are on "protected" budget hosts. Two went dark during advertised maintenance windows that smelled like unplanned mitigation events. The providers never admitted it.

My HostHatch Zurich instance — https://hosthatch.com — zero "protection" label, zero unplanned downtime in 11 months.

436 days. reboot is surrender.
#16
uma said:
80% oversell

More like 95% on OpenVZ nodes. The DDoS "protection" is also oversold: one Voxility port, 500 customers paying $2 each, all thinking they have 10Gbps mitigation. The port saturates, everyone null-routed, provider still collects the $2.

KVM at least lets you fail gracefully. OpenVZ you just die and cannot even see why.

#17

What about BuyVM? They have actual DDoS protection, no?

#18
alpha26 said:
BuyVM

BuyVM uses Path.net, which is real but limited. Their $3.50 slices get 500Mbps mitigation, not infinite. The difference: they state the limit clearly, no "up to 10Gbps" fantasy. This is honest overselling if you want to call it that.

The pathology is the gap between promise and mechanism. Path.net has scrubbing in Las Vegas and New York. BuyVM tells you this. Budget hosts with mystery upstreams tell you nothing because the answer is embarrassing.

virsh list --all | wc -l: 47
#19

This thread convinced me to check my own host. "10Gbps DDoS protection included." Traceroute shows... single Cogent path, no return diversity. Asking support what their upstream scrubbing centers are. Will update.

Expecting a copy-paste about "multi-layered protection" that names no layers.

https://bgp.tools

#20

Following for bird's update.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft