Also, unavailable to most people. Yes, I suppose it was kind of nice when the internet was only available to the tech-savvy, to those who didn't mind maintaining a second job as a Unix administrator. But for people who just wanted to _write_, it was not welcoming. Yes, you can go to wordpress.com and sign up for your own blog, but then you're just on the wordpress platform, and subject to their whims. If your plan wo…
Today everyone has to use a CDN to even try to defend against such attacks; and all they do is bulk filter the attack out while degrading the end user transparency of the service. Under 'load' some websites have to load an active filter page and execute code on the clients to authenticate that it's a valid client, rather than an attacker.
The proper solution is to identify compromised devices and isolate them from the Internet. For hosts under attack to use a side channel to the ISPs routing the packets to ask them: "Please do not send anything from X to me for a bit; unless they satisfy to you that a user is in control." The request should be 'signed' by an end user key, authenticated by their ISP, and filtering should begin at the edge of that ISP. If they feel it necessary, they too can send a request to their ISP. Until this escalates to the backbones. Then it can press further back, down to the compromised node. That would allow infected end users to be quarantined, informed, allowed to download security updates and some other limited website interactions (manufacturer websites for updated firmware, some after-market firmware sites/tool sites like OpenWRT/DD-WRT/Linux distros, etc).
Fix the DDoS issue, also fix the home upload bandwidth issue, and you too can host your own family photos/videos.