4 ms·
It used to be we will take your server down. Now its we'll DDOS your serverless website and leave you a 100k bill. I'm not sure how sustainable such business m
by hamoodhabibi 3y ago
It used to be we will take your server down. Now its we'll DDOS your serverless website and leave you a 100k bill.
I'm not sure how sustainable such business model is. When you owned the server, you could unplug it. Now you have no way of knowing if somebody is going to hit your /api a million times per minute
- andrasbacsai 3y agoI also prefer to get a (decaf) coffee, listen to some music while someone DDoS'd my VPS. I prefer to pay few $ / month for my VPS instead of paying thousands and "survive" the DDoS.
- s9df898r32h 3y agoI pay $10/year for my VPS and host a WordPress Woocommerce store on it... It doesn't get much traffic, but it didn't take long to pay for itself either
- InvOfSmallC 3y agowhere?
- s9df898r32h 3y ago[dead]
- Filligree 3y agoI explicitly block everything in Russia (and China and Hong Kong) from accessing my servers, because otherwise the rate of SSH attacks is so high it actually prevents SSH from working reliably -- the connection pool fills up. Just an FYI; I don't think it's that unusual. Blocking those geoips dramatically reduced my logging volume.
- s9df898r32h 3y agoI doubt that clients block outgoing connections to Russian IPs though... so that shouldn't affect me too much.
- geek_at 3y agotrue. At what point could you say they are accomplices to the attackers
- hamoodhabibi 3y agoAh the Yelp biz model: "would be a shame if somebody read a bad review about your biz, pay us to remove it" to Netlify "would be a shame if somebody DDOS'd your serverless website, subscribe to our DDOS protection plan"
- bombcar 3y agoReminiscent of booter sites behind cloudflare.
- kikimora 3y agoAWS guarantees protection from all DDoS attacks done at level 3-4 (Google aws shield). If someone calls your api million times then there is throttling.
- gregoriol 3y agoSo instead of DDoSing someone, you could make some not-so-large amount of requests to their APIs and instead of taking down their servers, you'll just take them down by bankrupting them with a huge invoice?
- kikimora 3y agoWith default settings an attacker can run up-to 10000 req/sec on your api gw which would result in a sizable bill if left unnoticed. So with AWS you have to configure throttling and AWS protects you from low level ddos. How do you save yourself from a huge traffic bill in a VPS? AWS also has WAF to protect from DDoS , it is expensive but may save a day if you urgently need a protection.
- margorczynski 3y agoRepresentational state terrorism