There are open source tools to mitigate DDoS, but all of them will have some marginal cost to run, and they will all be significantly worse than Cloudflare as they benefit from neither Cloudflare's data moat or scale.
Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy.
This seems like a weak argument. Should we just take down anything widely accessed because it might be used by the NSA? What about AWS?
This had a high risk of getting Cloudflare's limited ipv4 addresses to a blacklist - affecting ALL of their customers.
All CF did was ask them to switch to an Enterprise plan and bring their own IP-addresses. They refused to do either and rather cried on the internet claiming CF to be bullies. It's not like the price they asked was even a fraction of the profits an online casino brings in every DAY.
If a customer's action is truly illegal, the customer's account should be terminated, either immediately or after a reasonable warning to fix things. Under no circumstances should money be sought to support the illegal activity.
CF is engaged in a pig-butchering scam whereby they lure customers, then when the customer is all fat and happy, they get asked to pay up or lose their business.
In this case, CF destroyed the customer's business as soon as CF got word that the customer was going to move to Fastly, considering that the protection money was not paid. It's an open and shut case of racketeering.
Nice.
Even if you go all out and buy a bunch of huge IP transit links, you are not gonna be able to stop the IXP 800 miles away from getting congested and blocking your customers from accessing your site anyways. You need access to a backbone to route traffic differently to avoid those kinds of issues, which is why DDoS scrubbing services will partner with a T1 ISP to do most of the work.
Or any proof of work proxy that delays the ingress traffic. If you only have one server there is very little you can do except maybe redirect to a static page or kill the DNS entries.
Cloudflare describes that policy as a commitment to content neutrality rather than extortion, and I think that's more or less sincere (since they've protected many other unpopular sites that didn't give them such a benefit, with a few high-profile exceptions). It does work out very conveniently for them, though.
But we know that's not true. Point out problems with a very controversial blogger and they'll cancel your service.
Because they are a publicly traded company
It is the same problem with email spam. What's stopping someone from sending billions of spam mails?
If we suppose that: a blockchain exists which is fast enough, cheap enough, and spread out enough on the globe (to mitigate latency), then there is no reason, for a tcp packet to not carry with it a small money transaction, in the order of a millionth of a cent. Information gets served back, only when the transaction is confirmed.
In that way, any request with no transaction gets discarded, and only requests with a small cost pass through. Suddenly by sending requests one after another and no end in sight, DDoS attacks and mail spam start to cost money. It is the serving of request that makes DDoS attacks and mail spam to be effective.
The problem however, is that no blockchain is fast enough and cheap enough as of today. But there will be one in a handful of years.
(also, you're arguably just moving the problem to DDoSing the payment processing / firewall mechanism)
These ideas indeed exist for decades.
> The big problem isn't a technological one, it's that it presupposes some "sweet spot" price (negligible for legitimate users, yet prohibitive for abusers) that has never been shown to exist in reality.
Advances in technology, software and hardware, make it easier and easier for that sweet spot to exist. That sweet spot, didn't exist in the past, certainly, but we are close right now.
One example that i think is useful here, is aluminum cans for fizzy drinks. Aluminum, a strong metal compared to cardboard or plastic or glass, is better at withstanding pressurized gases without exploding. The downside, is that it's more expensive. When manufacturing prices dropped down a lot, then it was feasible to drink half a liter of liquid and just throw away the metal. Aluminum still not free though, but the small price did worth it. Huge waste of energy as well to smelt all that metal and throw it away after 10 minutes of drinking, but it is economically viable.
One could manufacture Titanium cans, and drink even more fizzy drinks. But that's not economically viable as of today.
> you're arguably just moving the problem to DDoSing the payment processing / firewall mechanism.
Yes, the problem is moved elsewhere, that's the weak link in the scheme i described. The thing is that a flood of transactions still costs money. Blockchains cannot be flooded just with requests, they have to be flooded by transactions. Take a look at the article [1] which outlines some ideas. I don't agree with a lot of things in there, but it states the problem and gives some numbers.
The theory when it comes to blockchain deterring DDoS attacks (and other kind of attacks), is that there are not bad guys in general, just rational economic actors who use dirty tricks. When a dirty trick starts to cost money, and profit disappears from an attack, then the rational economic actor will stop the attack. The bad guy will resume the attack regardless of profit, but that's one of the axioms of the theory, that there are no bad guys.
[1] https://www.dlnews.com/articles/defi/ddos-attacks-are-an-inc...
Secondly, considering Cloudflare would MITM all traffic, it would make a data good source for the NSA, thereby violating all user privacy.
If you need PoW for every connection, it's going to end up being very expensive for an attacker to saturate the connection. And the captcha is probably a different server to the main site.
I thought a gateway would work for that purpose.
Are you sure it wouldn't? In that case there's no defending against ddos.
The filtering/dropping of packets has to be upstream of your connection to be able to protect your connection - additionally somewhere where the available bandwidth is greater than the attacker's bandwidth.