We're going to need default hard budget caps on pretty much everything
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
We're going to need default hard budget caps on pretty much everything
Unofficial Hacker News client; not affiliated with Y Combinator.
chrismarlow9 · · focus · HN ↗
I actually think network ACL triggers based on billing might be the only way to really enforce this.
I witnessed a DDoS attack once that changed how I think about billing. It was locally provisioned hardware and the attackers had saturated the switches. Naively I said "just block the CIDRs" but the problem was the incoming ram is so saturated that it can't even get to the point of "deny" in the firmware.
So from a technical perspective if there's an internal DDoS at AWS what do you do? Do you turn off the endpoint? Do you drop the sources from hitting it at the router? And even that costs money. Anyway that incident gave me a different level of appreciation for this challenge.
Edit: this is mainly targeted at the people complaining why this took so long. At some point in scaling even telling you "no sorry" in a nice way is expensive. I'm sure recruiters can sympathize with this nowdays.
literalAardvark · · focus · HN ↗
The fancy alternative is to anycast that network and do distributed filtering so that the flood is manageable.
The first can be done by your ISP but it does lead to the temporary loss of traffic via that IP.
The second one is what DDoS mitigation services do and AWS has a basic one built in ( AWS Shield ) and several additional services you can get.