Live data from Hacker News

Someone attacked our company

usefathom.com

1–10 of 112 posts

Re: Someone attacked our company

#6
We're going to see a lot more of such attacks (Denial of Capital?) as engineers blindly throw more and more SaaS components together without any sort of rate limiting in place, especially so when those endpoints are publicly accessible and tied to your account (e.g. Firebase or Algolia requests that are billable to your conveniently included client-side API key).

And in all honesty it's a lot easier to take a site offline through depletion of budget than trying to exhaust an infinitely-scaling service.

Re: Someone attacked our company

#7
At present, we put all incoming page views into SQS

Hmm, not the most economical of choices, but...

We had decided that we were going to simply increase our lambda concurrency limit to 8,000,000 requests per second (800,000 concurrents) and handle the spam attacks

... wait, what? If you're using Lambda functions for something as trivial as logging page views, you evidently have more money than sense.

The author is concerned about this story reading like an advert for AWS Shield, but to me it reads like a case study in when "Serverless" is a bad idea.

Re: Someone attacked our company

#8
post #7

At present, we put all incoming page views into SQS Hmm, not the most economical of choices, but... We had decided that we were going to simply increase our lambda concurrency limit to 8,000,000 requests per second (800,000 concurrents) and handle the spam attacks ... wait, what? If you're using Lambda functions for something as trivial as logging page views , you evidently have more money than sense. The author is c…

Lambda concurrency wasn't actually increased to 800,000 concurrents. It's a stupid idea that someone would think up after fighting attacks all day.

Re: Someone attacked our company

#9
post #7

At present, we put all incoming page views into SQS Hmm, not the most economical of choices, but... We had decided that we were going to simply increase our lambda concurrency limit to 8,000,000 requests per second (800,000 concurrents) and handle the spam attacks ... wait, what? If you're using Lambda functions for something as trivial as logging page views , you evidently have more money than sense. The author is c…

Lambda concurrency wasn't actually increased to 800,000 concurrents. It's a stupid idea that someone would think up after fighting attacks all day.

Regardless of what you set Lambda concurrency to: Are you seriously invoking Lambdas for every page view?

Re: Someone attacked our company

#10
post #9

Earlier quoted context omitted.

Lambda concurrency wasn't actually increased to 800,000 concurrents. It's a stupid idea that someone would think up after fighting attacks all day.

Regardless of what you set Lambda concurrency to: Are you seriously invoking Lambdas for every page view?

We are indeed. Neither of us enjoy DevOps so we pay a premium to not have to manage servers. It brings a huge mental health benefit (we are a two person company), we're profitable and our monthly Lambda cost isn't that significant. Honestly, the biggest inefficiency (in terms of cost) is our use of SQS/RDS, which we are ditching soon.
Post reply on HN