| ▲ | embedding-shape 43 minutes ago | |||||||
> Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe. Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai. But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first. | ||||||||
| ▲ | viraptor 5 minutes ago | parent | next [-] | |||||||
It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service. > and I don't think people should default to trying to prevent them. It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands. | ||||||||
| ▲ | cbg0 10 minutes ago | parent | prev | next [-] | |||||||
I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada: https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small... | ||||||||
| ||||||||
| ▲ | pocksuppet 18 minutes ago | parent | prev [-] | |||||||
For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days. | ||||||||