Hacker Newsnew | past | comments | ask | show | jobs | submit | xslvrxslwt's commentslogin

Hetzner has long been affordable due to its subpar latency and protection, making this price increase very questionable. No one has real reason to choose hetzner if it is not affordable. OVH ends it, one Romanian provider as well.


Can you tell more about their subpar latency?

I've been using Hetzner for many years, both personally and for business use, and I've not seen any noticeable issues regarding the latency.

Granted, my use cases are webapps/backends that are not particularly latency sensitive, and are primarily used from a few European countries.

For what's worth, I've seen cases where download speeds from Hetzner are considerably higher than from AWS eu-central-1.


Good for him.


If he was doing what he said in the README, perhaps. But the sort of monetization he's doing is a lot slimier than that. https://news.ycombinator.com/item?id=47724010


The reason Hetzner was cheap was bad latency and Arbor.


They're using Arbor, they were cheap for that exact reason.

Now that people don't care about Anti DDoS - this happens.

In the past everyone was leaving Hetzner for the OVH/Voxility due to terrible latency and nonexistent protection.


> Now that people don't care about Anti DDoS - this happens.

Could I prod why that is? I'm dealing with a ovh server and using their anti-ddos detection for an issue currently so this topic I'd like to learn about.


Literally specific to "did I make this skid angry or not", it takes $5 to DDoS a website (bypassing cloudflare included)


Anyone that has $5.


I've also got €5, but I see greater return on investment in spending them on a lottery ticket than in DDoS'ing arbitrary small businesses.


I know, but people love the feel of "power", especially when it's cheap or even free


Because of 2018 operation "Power OFF" but it's still pretty easy to take anything down.

Hetzner has the WEAKEST DDoS protection out of ANYTHING out there - Arbor sucks.

Send me your website url and I'll keep it down for DAYS and whenever you cry to hetzner I'll just fry it again, it's that easy and that's why they're the cheapest - because everyone ran away from them back then.


So, are you an Internet bully? how would you define yourself?


Nah, I'm just talking about the possibilities


No but because all of us were arrested in 2018 for running DDoS-4-hire services. Bypassing cloudflare is very easy and I still can fry any of your websites (if i wanted to, just like any other skid)


I was arrested by Interpol in 2018 because of warrants issued by the NCA, DOJ, FBI, J-CAT, and several other agencies, all due to my involvement in running a DDoS-for-hire website. Honestly, anyone can bypass Cloudflare, and anyone that want to take your website down - will take it down. It's just that luckily for all of us most of the DDoS-4-hire websites are down nowadays but there are still many botnets out there that will get past basically any protection and you can get access to them for basically $5.


One minute, what? Can you elaborate on that. I have loads of questions. What exactly were you doing? What consequences did you face? How come you are talking about it?


because I'm from Serbia so I was released immediately instead of actually being jailed like my friend from Croatia ~


> anyone can bypass Cloudflare

How?


It depends how you wanna bypass it. (https://roundproxies.com/blog/bypass-cloudflare/) e.g. I found out that they track TLS, HTTP headers and Javascript JS fingerprinting. There are def some ways, personally using browsers but yeah. maybe take a look at that guide above foudn that helpful as a good starting point tho


Plenty of ways to leak the original server IP address if it isn't really well hardened against that (and most aren't).


Like? Aside from scanning DNS records (assuming the protected IP is in there somewhere) or scanning the entire IPv4 (assuming the server responds to non CloudFlare requests), I can't think of any. And both methods are simple to protect against.


Some of it is tradecraft, but have two: SSRF bugs/features and chatty email headers.


Right. Still a far cry from "anyone can bypass CloudFlare" though.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: