Hacker News new | ask | show | jobs
by parliament32 1928 days ago
The magic of 3rd party anti-DDOS providers is rarely the software/methods: it's just about having bigger pipes. Everyone can figure out how to block volumetric attacks with iptables or whatever, the problem is if you have a 1 gig pipe from your transit provider, it's going to get saturated even before you can do any blocking. The 3rd parties can afford to have multiple 100g pipes with 10gbps commits in multiple DCs -- you share this cost with other customers for when you get attacked. That's kinda the entire point of 3rd party anti-DDOS providers, and not much else.