Live data from Hacker News

Why cloud bandwidth is so obscenely expensive and what you can do about that

kerkour.com

121–130 of 164 posts

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#121
> There also is Hetzner and their dedicated servers. You pay for a server with a 1Gb/s connection and all egress is free.

There's also OVH and they have things like 1 Gbit/s guaranteed, up to 5 Gbit/s (not guaranteed) EPYC 7313 servers with 25,50 or 100 Gbit/s guaranteed private (from OVH servers to OVH servers) for... 200 EUR / month.

Re-using the example from TFA, you could max the bandwith of such a server 24/7, be "downgraded" from 5 Gbit/s to 1 Gbit/s guaranteed and yet it'd cost you... 200 EUR/month.

Versus hundreds of thousands of egress bill in the cloud.

200 EUR / month vs hundred of thousands.

But yay. Go cloud!

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#122

> There also is Hetzner and their dedicated servers. You pay for a server with a 1Gb/s connection and all egress is free. There's also OVH and they have things like 1 Gbit/s guaranteed, up to 5 Gbit/s (not guaranteed) EPYC 7313 servers with 25,50 or 100 Gbit/s guaranteed private (from OVH servers to OVH servers) for... 200 EUR / month. Re-using the example from TFA, you could max the bandwith of such a server 24/7, b…

Combine the two. Set up a large nginx reverse proxy with cache on the 200 EUR/month machine in Hetzner or OVH and serve 99.9% of the traffic from this location (js, css, images, videos, etc.). Use the cloud for convenience in managing the complex parts in the backend.

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#123
post #115
post #51

I wonder is There also is Hetzner and their dedicated servers. You pay for a server with a 1Gb/s connection and all egress is free. Unfortunately, I can't recommend them as each time I've tried to create an account, their abuse detection systems banned my account even before I had the occasion to enter a payment method. related to I've myself won the jackpot in the past on Netlify where I forgot to put a sleep in a w…

> Is there some kind of blacklist if you do something like that? No; but oddly enough, the people who "do things like that" generally tend to come from certain countries — I guess countries with cultures that don't place much weight on the concept of "incurring a debt of honor" by consuming someone else's resources without them ever knowing about it. So most systems don't generally need a big, manually curated and ev…

As far as I can tell, the author is French and lives in France. I've heard plenty of stereotypes about the French, but them bit caring about debts if any kind doesn't come to mind.

Then again, I seriously doubt Netlify's cost actually reflected the damage incurred. Cloud providers inflate their bills massively, and if they did incur a loss serious enough, they'd pursue the matter in court; a couple of thousands of euros lost is worth getting your legal team involved for. Deleting your account doesn't clear your debt, not does it make you untraceable.

Most likely, Netlify noticed the large bill associated with a deleted account, concluded that the resources spent didn't incur them enough loss to care, and waived the fee. Companies like Amazon will sometimes waive huge bills due to bugs if you ask nicely anyway.

I don't think there's an international fraud registry that works for this kind of abuse. The best you can do is verify the identity of your customers and let the banks and/or legal system handle frauds.

Outside of France there are places that register debt to your name, making it hard to get loans or mortgages or even things like phone contracts exceeding a certain monthly fee. There's also the American credit score system, of course, which will bite offenders in other ways down the line.

With the popularity of services like privacy.com where you can create virtual credit cards that will just disappear when you don't want to pay your bills anymore, I think this type of abuse had been calculated into the pricing structure.

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#124
post #34

One thing to keep in mind - if you accidentally run up a bill because of a mistake, there’s a good chance you can reach out to support and they will credit your account. $5k may be a lot to an individual, but the cloud provider’s costs for that service are significantly less and they shouldn’t mind forgiving the charge. Case in point, when the author deleted his account and switched providers, the old host didn’t cha…

That’s still a lot of hopes and prayers you do not end in financial ruin. Instead, the cloud providers could offer prepaid credits/billing maximums to let individuals sleep at night. I would love to run my side project off of AWS to gain the experience, but no way I feel comfortable with a potentially unlimited liability because I configured something poorly. My joke project can take the uptime hit if it means I know…

I agree with you. I understand why a "shut down all services when this amount of money is spent" button shouldn't be enabled by default, but it should at least be an option.

This is a good reason to avoid Amazon and friends. They're set up to let you fail, and that makes them terrible companies to host your private products with.

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#125

> There also is Hetzner and their dedicated servers. You pay for a server with a 1Gb/s connection and all egress is free. There's also OVH and they have things like 1 Gbit/s guaranteed, up to 5 Gbit/s (not guaranteed) EPYC 7313 servers with 25,50 or 100 Gbit/s guaranteed private (from OVH servers to OVH servers) for... 200 EUR / month. Re-using the example from TFA, you could max the bandwith of such a server 24/7, b…

Combine the two. Set up a large nginx reverse proxy with cache on the 200 EUR/month machine in Hetzner or OVH and serve 99.9% of the traffic from this location (js, css, images, videos, etc.). Use the cloud for convenience in managing the complex parts in the backend.

Why not just go Cloudflare then? In our sites, most of what Cloudflare caches is js, cs, images, etc...

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#126
post #115

Earlier quoted context omitted.

> Is there some kind of blacklist if you do something like that? No; but oddly enough, the people who "do things like that" generally tend to come from certain countries — I guess countries with cultures that don't place much weight on the concept of "incurring a debt of honor" by consuming someone else's resources without them ever knowing about it. So most systems don't generally need a big, manually curated and ev…

As far as I can tell, the author is French and lives in France. I've heard plenty of stereotypes about the French, but them bit caring about debts if any kind doesn't come to mind. Then again, I seriously doubt Netlify's cost actually reflected the damage incurred. Cloud providers inflate their bills massively, and if they did incur a loss serious enough, they'd pursue the matter in court; a couple of thousands of eu…

> As far as I can tell, the author is French and lives in France. I've heard plenty of stereotypes about the French, but them bit caring about debts if any kind doesn't come to mind.

No, I wasn't implying anything about France; but then, the author wasn't doing the thing that most "people causing problems for hosting providers" do, which goes more like so:

1. register with a stolen credit card that validates at the time, but won't accept payment when the provider goes to collect for the month;

2. rack up billable usage doing some kind of scam; and then

3. when the account gets closed for non-payment, immediately register again, from a new (VPNed) IP, using a new (stolen) identity, with a new (stolen) card.

4. Optionally: do this "in bulk" with multiple accounts at once, perhaps even with scripted automatic bulk account registrations, account "aging" to avoid registration-recency being used as a fraud-score calculation, etc. (You're more likely to see this type of attacker on API services where the service has some kind of per-customer rate-limiting and the attacker doesn't appreciate being rate-limited — they just configure their client software to round-robin their workload across many accounts.)

If you were raised to see this as "using up someone else's resources and depriving others of those resources", then this probably sounds unethical to you, and you will avoid doing it even if it's "easy" to do. But if you weren't, then this probably just looks like an "infinite money glitch" in real life.

If you want me to be concrete about the part of the world where these fraudulent users come from: it's CIS countries. It's hard to tell which people are responsible any more specifically than that — the various CIS countries crop up pretty evenly in attack logs. This is likely because there are many VPN services run in each of these countries, that specifically serve the "other CIS countries" market, and even more specifically serve the "your country is blacklisted from service X? we got you, bro" market.

(I have been witness to posts on scammer forums over the last year or two, that specifically said something to the effect of "full identity kits [IP VPN, identity and matching credit card] for sake! Russian kits on discount because they're unlikely to be accepted pretty much anywhere useful. Ukranian kits marked up with a premium right now, because the west is a big fan of them at the moment, and so is more hesitant to ban them / write rules against them.")

> With the popularity of services like privacy.com where you can create virtual credit cards that will just disappear when you don't want to pay your bills anymore, I think this type of abuse had been calculated into the pricing structure.

There's a simple switch on pretty much every payment processor, that when enabled, rejects cards known to be prepaid/gift cards, only accepting cards that can actually carry a negative balance. Any post-paid usage-based-billing subscription service would have this switch enabled.

A paranoid provider like Hetzner, in addition, probably blocks the Privacy.com partnering card issuer's BIN numbers from being accepted at subscription time. I know our service sure does. (We block the BINs for Venmo and CashApp "cards" too.)

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#127
post #116

Earlier quoted context omitted.

You kinda pay in reduced performance. For example, civitai uses r2 for delivering the images, and it frequently doesn't load at all for me or very slowly. When your users have to use a VPN to move their traffic to another Cloudflare data center so the site actually loads, something is wrong...

Heh, this entire threat is "Fast, cheap, reliable... Pick two" where everyone wonders why all three are so much more expensive.

Not really. There is a cost to being fast and reliable, but then the biggest cloud providers slap an additional >10x increase on top because they can get people to pay it.

You can also buy high quality connections at datacenters and plug them into your own servers.

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#128

Beware of cloud providers that don't "charge for egress" but do charge on a metric that is effectively a proxy for egress. For example, a cloud streaming service that charges for video delivery by per minute streamed is just charging for egress with extra steps.

> For example, a cloud streaming service that charges for video delivery by per minute streamed is just charging for egress with extra steps.

It's even worse than paying for egress because the cloud provider gets to capture any gains in compression technology, right?

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#129
post #24

Cloud bandwidth is cheap if you commit to spending a certain amount per month. Our bandwidth is less than .001/GB with like a $1500 monthly commitment in AWS. Fastly was even cheaper (which is why we're using fastly). Call you AM and talk. It's not hard, and it'll save you a ton of money.

Is that something generally avaliable to customers? I've done some searches and can't find anything other than savings plans for EC2 etc.

On AWS you have to call and ask them. We got quotes from AWS, Fastly, and Akamai. All of them are substantially cheaper than the public rates.

Re: Why cloud bandwidth is so obscenely expensive and what you can do about that

#130
post #24

Cloud bandwidth is cheap if you commit to spending a certain amount per month. Our bandwidth is less than .001/GB with like a $1500 monthly commitment in AWS. Fastly was even cheaper (which is why we're using fastly). Call you AM and talk. It's not hard, and it'll save you a ton of money.

We had a commit that was like three orders of magnitude more and our price was 1-2c for cdn and 2c for tier1 cloud (but only “partner” networks, the rest was list). That was after us threatening to leave (and having capability to do so). So either you are mistaken or your am really really likes you.

No, it's your people suck at negotiating.

Again, we got quotes from Fastly, Akamai, and AWS. Our commit is/was $1500/month (we're on fastly now). Fastly gave us like 6 month free to switch, both bandwidth and requests.

Post reply on HN