Skip to content

Comment on Website hosted on a 24 year old Linux serverparent

Comments

I think it's a reasonably good precaution to take with a 24 year old server. I'd imagine on hardware that old you could easily get DOSed by a single mean client (or a web scraper bot with bad behavior), so a ddos isn't even needed.

Also this is available on Cloudflare's free plan so it's much safer to take the precaution in case you might need it down the line, rather than get taken down and have to fiddle with setting up Cloudflare on the spot.

You can also kill my server with a single client. Nobody has for the ~15 years that I've hosted on old laptops now. I've run game servers, a wiki mirror, file upload sites, a Tor exit node, torrent seeding, recently a VM image for a malware analysis course, all sorts of random tools and scripts, you name it; various different audiences but most with some technical know-how, yet nobody has felt the need.

People have messed with things and found bugs (so far always reported more-or-less ethically), and lots of scanners go across the Internet daily, but I've never seen a deliberate take-down effort. (Kind of wondering whether I'm calling that upon myself now, but so be it. Let's see what happens.)

This fear of having to react to a DoS attack by knocking on big brother's door and thus preemptively knocking, it's so anti self hosting mentality, but is also pervasive throughout the self hosting community, I really don't understand it.

The chance that someone wants to connect to your ancient server from an ancient client that can't pass Cloudflare's DDOS protection is probably way higher than someone wanting to DDOS it. (For example, most people may not realize that Cloudflare DDOS basically makes the website inaccessible via TOR for many people.)

Preemptive protection against attacks that never come makes the internet worse for everyone.

This old chestnut again, really? You can whitelist Tor without any issues on CloudFlare. It's one of the first things most people do. Read the documentation.

And service owners go out of their way to check the CF settings and opt in to the darknet... how often exactly?

It's implied with CF that you block people they can't track and prove to be innocent. Hence this old chestnut still existing: it's no joke.

It's gotten somewhat better now that CF is using proof-of-work DDOS protection vs the older captchabullshit, but if you browse the web on Tor you will find LARGE numbers of sites that are CF blocking you.

(Props to HN, it works over tor)

You can even serve up websites via the Tor network instead of using exit nodes: https://developers.cloudflare.com/support/firewall/learn-mor...

If users choose to use a non-standard method to access a service that's not actively supported by the service provider, that's on the user.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.