6 ms·
> He followed our run book and triggered a FINT — which stands for "Fail Internal" — directing traffic from the site directly back to its origin rather than pas
by _wmd 7y ago
> He followed our run book and triggered a FINT — which stands for "Fail Internal" — directing traffic from the site directly back to its origin rather than passing through Cloudflare's protective edge. Instantly the site was overwhelmed by the attack and, effectively, fell off the Internet.
So if I'm understanding this correctly, free users have their backend servers and hosting provider information exposed to an attacker right when that information needs to be kept secret the most? This is nuts. Can someone clarify whether CloudFlare still do this? I can think of 100 scenarios where it would be better to just pull the zone (or similar) and let the site go down instead
- xxdesmus 7y agoHas not been the case for several years now.
- jgrahamc 7y agoWe do not. See: https://blog.cloudflare.com/unmetered-mitigation/ https://blog.cloudflare.com/unmetered-mitigation/
- judge2020 7y agoThis stopped being the norm as Cloudflare's footprint grew, and formally stopped with this blog post https://blog.cloudflare.com/unmetered-mitigation/ https://blog.cloudflare.com/unmetered-mitigation/.
- 292355744930110 7y agoAfter reading that, I'm not sure what Galileo provides considering that don't FINT anyone.
- eastdakota 7y agoThere are a lot more controls and features for our higher tier security services that Galileo participants get for free. And there are a lot of security threats we help protect them from that go beyond DDoS. But, you're correct, the experience of dealing with the nation state-level attacks that Galileo participants face on a regular basis was a big part of what encouraged us that we could make Unmetered DDoS Mitigation free to all Cloudflare users approximately 18 months ago.
- twunde 7y agoThis was standard operating procedure for most colos/shared hosting companies even for paying customers. If the company didn't have enough resources to combat DDOS attacks, they'd shut you down to protect the rest of their customers. I think this is rarer now since there are a number of DDOS protection vendors that are relatively cheap