Live data from Hacker News

AWS Shield – Managed DDoS Protection

aws.amazon.com

21–30 of 79 posts

Re: AWS Shield – Managed DDoS Protection

#22
post #2

Finally. The basic offer is something a lot of other providers already have. Not sure about the advanced one. Sounds quite expensive. $3,000/month plus extra traffic costs. And I don't understand which traffic they bill. Usually AWS bills outgoing traffic, but for DDOS costs only occur ingress, or am I wrong? Can't see from the price list what they'll actually bill (ingress or egress).

> Finally. The basic offer is something a lot of other providers already have. Sure, protections like what OVH "already offers" when a DDOS attack downs their entire administrative portal? It's clear to heavy AWS users that Amazon was already providing certain DDoS protections before this announcement.

Was more thinking of ovh, in the recent attack the admin interface and network weren't affected as it seems.

Re: AWS Shield – Managed DDoS Protection

#24
post #4

I've been saying for years that AWS has secret DDOS protection. Never confirmed, but I'm pretty sure the basic level is just them admitting that they've always had that service.

I think so too. In the past, I'd get frequent DDOS attacks against my site, and the dedicated hosts I was with would null route my account, or tell me to take a hike, even though I was paying them $1k+/mo.

I switched to AWS 1.5 years ago, and all my DDOS issues magically disappeared overnight.

Re: AWS Shield – Managed DDoS Protection

#25
I have a lot of questions/problems with this. Here are two.

1.) They mention in the compare tiers "Application traffic monitoring" for Advanced. However in the FAQ: "In addition, customers can also use AWS WAF to protect against Application layer attacks". WAF is only available through CloudFront, and CloudFront charges 600 dollars a month for a custom SSL certificate with dedicated IP.

So do they have "Application traffic monitoring" outside of WAF? I'm lead to believe not.

2.) They mentioned multiple times you can call on the DRT team to help you. However buried in the FAQ is this little gem: "Response times for DRT depends on the AWS Support plan you are subscribed to".

So for 3k/mo I can't get better than 24/hr turnaround when I'm under attack without ALSO having a business/enterprise support plan?

Re: AWS Shield – Managed DDoS Protection

#26

So many new named services. AWS will soon get to a point where their product dropdown wont fit on a laptop screen. Maybe it's time to consolidate some of these services into more general products.

They did just re-organize that dropdown in AWS, it's actually much easier to search and find things. You can also pin commonly-used services to the top menu bar too.

Re: AWS Shield – Managed DDoS Protection

#27
post #25

I have a lot of questions/problems with this. Here are two. 1.) They mention in the compare tiers "Application traffic monitoring" for Advanced. However in the FAQ: "In addition, customers can also use AWS WAF to protect against Application layer attacks". WAF is only available through CloudFront, and CloudFront charges 600 dollars a month for a custom SSL certificate with dedicated IP. So do they have "Application t…

As per the pricing page, looks like you _do_ need support plan:

"AWS Shield Advanced is available to customers who are enrolled in either the Enterprise or Business Support levels of AWS Premium Support."

https://aws.amazon.com/shield/pricing/

Re: AWS Shield – Managed DDoS Protection

#28
post #17
post #14

Earlier quoted context omitted.

Not really. Now your $1K DDOS bill is a $1K AWS credit. Hardly any better. AWS desperately needs a way to turn off pay-by-use services through billing alerts. I don't believe this is possible right now.

You appear to be assuming that the credit applies after they charge your card, which is not what it reads as to me. The process sounds like "$1k line item for traffic -> $1k credit -> $0 charged to card". Additionally: you can totally set up CloudWatch Alarms for billing events, it's one of the categories they provide out-of-the-box, and alarms can trigger notifications, lambdas, SQS, etc. So you can totally wire ala…

Right, I see how I could have been wrong about that assumption. I assumed it would be after-the-fact credits.

And doing it through Lambda is possible, but the friction there almost feels deliberate. They should make it a first-class option you don't need to wire together yourself.

Re: AWS Shield – Managed DDoS Protection

#29
post #25

I have a lot of questions/problems with this. Here are two. 1.) They mention in the compare tiers "Application traffic monitoring" for Advanced. However in the FAQ: "In addition, customers can also use AWS WAF to protect against Application layer attacks". WAF is only available through CloudFront, and CloudFront charges 600 dollars a month for a custom SSL certificate with dedicated IP. So do they have "Application t…

As per the pricing page, looks like you _do_ need support plan: "AWS Shield Advanced is available to customers who are enrolled in either the Enterprise or Business Support levels of AWS Premium Support." https://aws.amazon.com/shield/pricing/

Oh wow, thanks! I hadn't noticed that yet :| So many caveats to this thing.

Look like I'd need to pony up >1k/mo on top of 3k to get access to the service then...

Re: AWS Shield – Managed DDoS Protection

#30
post #26

So many new named services. AWS will soon get to a point where their product dropdown wont fit on a laptop screen. Maybe it's time to consolidate some of these services into more general products.

They did just re-organize that dropdown in AWS, it's actually much easier to search and find things. You can also pin commonly-used services to the top menu bar too.

For someone familiar with the products, yes. But for someone new to AWS most of these options don't make sense. I'm looking at a menu with hundreds of options like Snowglobe and Beanstalk and I have no idea where to start. Are they trying to brand their trademarks as the defacto name for the service (like Kleenex and ChapStick have done)?
Post reply on HN