6 ms·
We're going to see a lot more of such attacks (Denial of Capital?) as engineers blindly throw more and more SaaS components together without any sort of rate li
by altdatathrow 6y ago
We're going to see a lot more of such attacks (Denial of Capital?) as engineers blindly throw more and more SaaS components together without any sort of rate limiting in place, especially so when those endpoints are publicly accessible and tied to your account (e.g. Firebase or Algolia requests that are billable to your conveniently included client-side API key).
And in all honesty it's a lot easier to take a site offline through depletion of budget than trying to exhaust an infinitely-scaling service.
- eat_veggies 6y agoCloudflare at least will refund any extra costs incurred from their serverless product if you get DDOSed
- JackWritesCode 6y agoSame with AWS Shield Advanced :)
- Scramblejams 6y agoWhat is that, $3k/mo?
- JackWritesCode 6y agoYup with a minimum 1 year commitment.
- Aeolun 6y agoNeed to have some pretty solid expectation you are going to be hit again at that price point. That said, it’d be a no brainer at enterprise level.