Author

Topic: 502 Bad Gateway (Read 367 times)

administrator
Activity: 5166
Merit: 12850
July 02, 2019, 01:04:11 PM
#19
Incapsula is better than CloudFlare, no idea why he didn't give another try.

I've looked into them. They're at least 10x more expensive, they offer roughly the same tech as Cloudflare, and I was very unimpressed with the people I talked with there. Also, I've tended to be more annoyed with Incapsula sites as an end-user. They seem to be even more anti-Tor than Cloudflare.
copper member
Activity: 2828
Merit: 4065
Top Crypto Casino
July 02, 2019, 12:47:27 PM
#18
Incapsula is better than CloudFlare, no idea why he didn't give another try. He may have had some problems when he tried, but it's worth a try another time. It's not like he has to do it every month or week.
And using CF, the site still needs to remove stats, disable Viewing all members, etc Cry

Quote
Not sure which things might be changed in the future, with the forum, and coming Epochtalk forum too.
What do you want to change? The theme?  Cheesy

copper member
Activity: 2142
Merit: 1305
Limited in number. Limitless in potential.
July 02, 2019, 12:41:08 PM
#17
The ~entire internet went down.
Nope, it only happened with sites that integrate Cloudflare, not all sites down. Not sure which things might be changed in the future, with the forum, and coming Epochtalk forum too.
I'm so sure that you didn't get (the sarcasm of the post) why he said the ~entire internet.
copper member
Activity: 2870
Merit: 2298
July 02, 2019, 12:13:52 PM
#16
You would be surprised as to how much of the internet uses CF. Perhaps “~entire” was an exaggeration however many major websites use CF
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
July 02, 2019, 11:54:32 AM
#15
The ~entire internet went down.
Nope, it only happened with sites that integrate Cloudflare, not all sites down. Not sure which things might be changed in the future, with the forum, and coming Epochtalk forum too.
With regret, I am (for now) admitting defeat on the DDoS front, and we will soon be using using Cloudflare to protect against DDoS attacks. This change is in progress, and will take ~24 hours for everyone to see.

I really don't believe in willingly putting a man-in-the-middle in your HTTPS like this, but my homebrew DDoS mitigation has been one of my biggest time sinks for the last 6 months or so, and the necessary servers are still pretty expensive. If I had more manpower, then I would prioritize maintaining our own DDoS protection, but with me as the only sysadmin and current-software developer, it's become unsustainable.

I especially dislike Cloudflare, which I'm almost certain is basically owned by US intelligence agencies. I considered several alternatives to Cloudflare, but the smaller ones (eg. Stackpath and OVH) didn't strike me as reputable/competent enough, and the enterprise-targeted ones like Incapsula and Akamai are around $3500/month. Even though $3500/month seems absolutely ridiculous to me, I was seriously considering Incapsula due to its pretty good reputation, but then they were having all sorts of technical issues while I was trying to set it up. So I gave up for now and went with Cloudflare.

The Internet is seriously flawed if everyone needs to huddle behind these huge centralized anti-DDoS companies in order to survive...

The security implications are that Cloudflare can read everything you send to or receive from the server, including your cleartext password and any PMs you send or look at. They can't access the database arbitrarily, though: they can only see data that passes over the Internet.

Tor users and benevolent-bot operators: please wait a couple of days for the current DDoS to subside, and then post your complaints here. I am able and willing to tune Cloudflare to be minimally annoying. Not every Cloudflare site has to do that "Using Tor? Here's an impossible captcha" thing.

The Internet is fundamentally broken. We need DDoS protection at the network layer, or else you're going to continue seeing 99% of the Internet hiding behind a few centralized third-parties. It's absolutely ridiculous. Realize also that Cloudflare can see all traffic unencrypted. They're almost certainly an NSA honeypot already, but even if not, their many screwups make them unworthy of this kind of trust. (Their Argo tunnel doesn't fix this trust issue at all, BTW.) However, since the Internet is broken fundamentally, mitigating it is too difficult for it to be a good idea for me to devote resources to it at this time.

I don't have time to work on this at all, but if someone created a non-profit dedicated to producing decentralized anti-DDoS solutions, I'd donate to it. On github I see two very immature projects in this area:
 - gatekeeper is intended for large organizations, and blocks attacks at the network/transport layer. However, I've found that SYNPROXY gateways plus upstream UDP blocking is sufficient for this on bitcointalk.org's scale, and gatekeeper also requires access to BGP, which isn't common unless you're pretty big.
 - AntiDDOS works at layer 7, which is where my homebrew DDoS protection broke down. But it doesn't have a good IP classification system, and it's based on (and assumes the existence of) a single final application server.

(BTW, this problem is an example of centralization being used as an ever-increasing crutch for systems that are technologically flawed. It has parallels to scaling of cryptocurrencies and other supposed-to-be-decentralized systems.)
legendary
Activity: 2044
Merit: 1981
Marketing Campaign Manager |Telegram ID- @LT_Mouse
July 02, 2019, 10:38:42 AM
#14
Not only bitcointalk, I faced this in another site too. This is problem from cloudfare. I checked bitcointalk earlier and wasn't able to browse at all.
legendary
Activity: 1932
Merit: 1737
"Common rogue from Russia with a bare ass."
July 02, 2019, 10:34:52 AM
#13

legendary
Activity: 1876
Merit: 1308
Get your game girl
July 02, 2019, 10:33:31 AM
#12
Websites should get rid off Cloudflare already. The time out happened when I was purchasing a course on Udemy and now my money is deducted but no course is added to my account. I've to bother customer care to get it fixed. Worst mitigation solution ever! Cloudflare legit can turn down the banks and stock exchanges if such outages happen on that level.

copper member
Activity: 2044
Merit: 793
July 02, 2019, 10:28:10 AM
#11
Initially, I thought this was a problem from my network provider/browser until I switched between two networks. Bitcointalk was unresponsive some mintues before the 502 Gateway error started coming up.
legendary
Activity: 2660
Merit: 1017
Join the world-leading crypto sportsbook NOW!
July 02, 2019, 10:25:03 AM
#10
It's not only Bitcointalk get down a few sites i try before get this thing too. I try many times to refresh the page until it's work.
legendary
Activity: 3080
Merit: 1144
July 02, 2019, 10:23:29 AM
#9
Yes, same problem before, it's cloudfair issue again... but it seems it's back up again, this time is faster compared to the last time.  Smiley
legendary
Activity: 2632
Merit: 1094
July 02, 2019, 10:23:05 AM
#8
All cloudfare sites were down for about 5 minutes. Not any DDoS attack. However, other sites came online faster than BTC forum.
copper member
Activity: 2870
Merit: 2298
July 02, 2019, 10:21:07 AM
#7
The ~entire internet went down.
sr. member
Activity: 2044
Merit: 323
July 02, 2019, 10:20:37 AM
#6
YES! Bitcointalk down for everyone! Since Cloudfare is down, it's certain and to be expected that it wasn’t simply you or me. I'm certain it will be fixed shortly. Any sites hosted on cloudflare was down. From my part it's working nicely!
legendary
Activity: 2282
Merit: 1435
July 02, 2019, 10:18:31 AM
#5
Ohhh... At first I thought I was the only one having 502 Bad Gateaway error...
hero member
Activity: 2002
Merit: 578
July 02, 2019, 10:16:56 AM
#4
I thought we hit a DDOS Cheesy , seems it is different from the other day. Does Cloudflare updating their system seems this frequently happen.
copper member
Activity: 1960
Merit: 1638
Top Crypto Casino
July 02, 2019, 10:16:12 AM
#3
I have been getting the error too and some very painful slow loading time.
Do you think it could have been a DDoS attack of sorts?
legendary
Activity: 1288
Merit: 1043
:^)
July 02, 2019, 10:13:49 AM
#2
it was cloudflare again. a bunch of my services / webpages using cloudflare stopped working all at once.
hero member
Activity: 1484
Merit: 595
July 02, 2019, 10:12:36 AM
#1
Anyone else getting the same problem? I'm getting the error repeatedly and the site is also slow if the error doesn't show.
Jump to: