2 hours ago
- The author describes a previous incident where they banned a user who used a 'Claude-code' user agent, leading to a conflict where the user fabricated a story about VM zeroing and OS wiping, and got media attention.
- A sustained DDoS attack began shortly after that incident, overwhelming the server's network connection with garbage traffic, forcing Linode to null-route the server for over 12 days.
- Initial mitigation attempts, including a backup server and Fastly's DDoS protection, failed due to misconfiguration, high costs, and account suspension for bandwidth abuse.
- The main site was eventually moved behind Cloudflare with 'Under Attack' mode, which successfully mitigated the attack while facing sporadic smaller HTTP-level attacks.
- The attack lasted 12 days and 16 hours, ending on September 9, with the attacker later reaching out via Telegram and Discord but being immediately blocked.
- Positive outcomes from the ordeal include improved caching, full IPv6 support, better bot blocking, VPN unblocking, and enhanced security features.
- The author plans to implement a non-Cloudflare proxy for logged-in users in the future to accommodate those who cannot use Cloudflare.