How come the forums are ddos'd to oblivion depsite Cloudflare? - For example, during July when there was a long outage

Because cloudflare doesn't do shit if the servers actual IP is known. Has been for ages. It's only useful for content caching and stopping attacks of retarded people, that attack the domain instead of the IP.
Usually the data centers offer some sort of cheap or free DDOS mitigation, but the service KF's data center uses outright refuses to peer with KF.
Thats why Null has to pay an extra 1500$ for external DDOS filtering.

From what I understood.
 
Because cloudflare doesn't do shit if the servers actual IP is known. Has been for ages. It's only useful for content caching and stopping attacks of retarded people, that attack the domain instead of the IP.
Usually the data centers offer some sort of cheap or free DDOS mitigation, but the service KF's data center uses outright refuses to peer with KF.
Thats why Null has to pay an extra 1500$ for external DDOS filtering.

From what I understood.
This, plus Cloudflare on non-enterprise plans is known to disable its reverse proxy and change server IP back to real one when reacing certain traffic threshold, so even if real IPs weren't initially known, it can be exposed if you dilate and ddos hard enough.
 
This, plus Cloudflare on non-enterprise plans is known to disable its reverse proxy and change server IP back to real one when reacing certain traffic threshold, so even if real IPs weren't initially known, it can be exposed if you dilate and ddos hard enough.
Because cloudflare doesn't do shit if the servers actual IP is known. Has been for ages. It's only useful for content caching and stopping attacks of retarded people, that attack the domain instead of the IP.
Usually the data centers offer some sort of cheap or free DDOS mitigation, but the service KF's data center uses outright refuses to peer with KF.
Thats why Null has to pay an extra 1500$ for external DDOS filtering.

From what I understood.
Hold on, are we talking about the free DDOS mitigation, or the paid one? Because if the paid one doesn't work, too, and in fact it's impossible to protect against, then how come so many sites buseniess and corporations are using it? I was under the impression it was very effective at what it does, even managing to thwart 2tbps attacks.
Are you saying those attacker(s) did the elementary mistake of targeting the domain instead of the ips?
Or to reframe it, when is Cloudflare effective / useful?
 
Hold on, are we talking about the free DDOS mitigation, or the paid one? Because if the paid one doesn't work, too, and in fact it's impossible to protect against, then how come so many sites buseniess and corporations are using it? I was under the impression it was very effective at what it does, even managing to thwart 2tbps attacks.
Are you saying those attacker(s) did the elementary mistake of targeting the domain instead of the ips?
Or to reframe it, when is Cloudflare effective / useful?
Afaik Cloudflare's Free, Pro and Business plans just act as a reverse-proxy with differing traffic limits and tools. Which means that they can be entirely bypassed, once/if the servers IP is known. Thats the case here.

I think it's only the Enterprise plan that would offer useful DDOS mitigation for KF.
Prices for that are unlisted, but likely way too expensive. Paid anually, averaging at around 5000$/month, according to a quick search.
That plan would probably protect against the 2tbps attacks that you mentioned too.

Again, as far as I understood/remember.
 
Unless you have Cloudflare's Magic Transit (which is over $10k a month I believe, when I talked to the BuyVM guys when they were considering it), Cloudflare will only protect against certain level attacks. The "rent a botnet" DDoSes probably are attacking at a higher level than what Cloudflare's free tier supports.
 
Back