This was posted in another thread, but thought it could use its own post to make this more visible.
Just to clear up some confusion I am seeing, the DDoS is hitting an L4 bottleneck. This is not something that we have direct control over or any access to implement things like whitelists or custom scrubbing. These attacks are not related to how our server runs, and there are no exploits that make a DDoS more effective they are simply flooding our L4 bottleneck until it collapses.
Because we have unique traffic patterns (game traffic is different than most web traffic, especially our game traffic) and are unable to compromise on our anonymity, our options for 3rd party solutions are extremely limited. We still have no timeline from FlokiNet on the delivery date of our new server hardware, but the order was placed on August 16th (before the DDoS attacks began) so we expect it to be online SOONtm. We have requested a more specific timeline from them but have not heard back and understand they themselves are dependent on external vendors who may not be providing timelines.
There are absolutely some sacrifices and trade offs involved with hosting a project anonymously, and we are feeling the pain of those right now. We hope that you all see the value in these trade offs like we do. We have faith that these trade offs will allow our project to thrive for years to come once these DDoSes are resolved.