Hacker News new | past | comments | ask | show | jobs | submit login

Can you not just reject or ignore all connections not coming from cloud flare? Or does that still do damage during a ddos?



That doesn't help if your pipe to the Internet is full (think Gbps) or if the router/switch can't process packets fast enough (think Mpps).


Considering that the website the articles refers to is hosted on DigitalOcean, in this case the problem would be DigitalOcean's DDoS policy, which is basically null route the IP traffic for 4 hours or so when an attack is detected.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: