Ask HN: How do I handle a hacker attempting to extort me by threat of DDoS?
We have no information about him.
Already using Cloudflare, it did seem to detect some of his BotNet(~3500 instances) but not enough to stop the load he put on us. (edited)
Cloudflare Rate Limiting is just too expensive and "I'm under attack" mode just breaks the site in places anyway.
I've reached out to Cloudflare support to try identify his BotNet from the times when he took it down.
Any help would be much appreciated.