4 ms·
But the same is true of any backend. Once you know the endpoint being used by the frontend, you can blast the backend with requests and one of two things will h
by kitbrennan 11y ago
But the same is true of any backend. Once you know the endpoint being used by the frontend, you can blast the backend with requests and one of two things will happen:
* You will take down the site (a DoS attack).
* Or the victim has auto-scaling and you rack up their AWS charges.
This is hardly a unique problem to Lambda.
- michaelmior 11y agoThe question is whether or not the cost per request is higher than if you were running something similar on EC2.
- rattray 11y agoThe biggest difference is ease of rate limiting. With lambda, I imagine the best you could do would be check the IP in a Redis cache at the beginning of each request (if the SDK even includes that info) to minimize the damage. But there would be no way to fully stop an attacker without turning off the service entirely. If you run your own webserver, I think you can stop stuff like that more efficiently / without the expense, eg at the nginx level.