Live data from Hacker News

How I attacked myself using Google and I ramped up a $1000 bandwidth bill

behind-the-enemy-lines.com

131–140 of 152 posts

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#131
post #26

This really underscores Amazon's glaring omission of a billing cutoff on Amazon web services. How hard would it be for them to let me say, cut off my services at $100/month? This is the main reason I'd never use AWS to host anything public.

I guess that would be a nice feature to offer as an option, but most people would not want their web service cut off if they get a spike in traffic.

That's where the "option" part comes in. People who aren't worried about the cost simply don't turn it on.

Those of us who can't afford an extra £1000/month (or more if it's a dedicated attack) would love to be able to just turn it off when a threshold is hit.

Users may lose access, but at least you don't go bankrupt in the process.

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#132
post #43

This really underscores Amazon's glaring omission of a billing cutoff on Amazon web services. How hard would it be for them to let me say, cut off my services at $100/month? This is the main reason I'd never use AWS to host anything public.

Or perhaps an email saying "We're past the limit you set, approve the overage in the next X hours by clicking this link". That way you don't cut off accidentally during a spike you want, but know about it.

[deleted]

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#134

This really underscores Amazon's glaring omission of a billing cutoff on Amazon web services. How hard would it be for them to let me say, cut off my services at $100/month? This is the main reason I'd never use AWS to host anything public.

We are already testing a billing charges monitor that works through CloudWatch. Here's some more info: http://blog.bitnami.org/2011/12/monitor-your-estimated-aws-c...

Looks great! Any chance that this will become available to accounts without Premium support in the future?

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#135

Earlier quoted context omitted.

Ironically, it might be DoS in the sense that it drives app maintenance costs so high that the owner could decide to, naturally, deny the service (shut down). Otherwise, maybe it's the new type of flood attack, cost-of-service (CoS), applicable against those who use ‘invincible’ cloud infrastructure such as Amazon's.

Is that a term? "Cost of service attack" ? If not, let's coin it :) Cost-of-service-attack: Consuming bandwidth or other resources in cloud based solutions to drive up the cost of running the service. Very easy when the cost is so tightly coupled with the resource use...

OK, so now we have DoS and CoS!

I dunno though, it's all technically bandwidth flood in the end. The consequences (or goals) of flood may include immediate or eventual denial of service, high cost of service, various security attacks, or probably all at once—further classification surely is complicated.

Meanwhile, both terms DoS and CoS are a bit vague, too. Say, turning off a server or forcing providers to alter their DNS records more or less qualifies as denial of service attack (which, by Wikipedia's definition, is “an attempt to make a computer or network resource unavailable to its intended users”).

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#136
post #128

Earlier quoted context omitted.

Prices have gone down since the last time I had to deal with all of that. I remember the company I was working with paying $1.67 per Mb/sec, I've seen offers for 1 Gigabit/sec for $1000 so roughly $1.00 per Mb/sec (using 1000, not 1024), but I didn't know they would go down to $0.65 per Mb/sec! Guess the more you commit to, the better pricing you get!

Bandwidth pricing falls dramatically with bulk. Cogent offered me $0.75/meg for a 3g commit, $0.65 for a 5g commit, and $0.50 for a 10G commit. I know a guy that is getting $4.00/meg on a 100M commit on a 1000M pipe, also from Cogent. (and he chose that over going through me for $650/month for a capped full 1000M pipe) Bandwidth is also a "negotiated good" without a standard price, so what I pay may be rather differe…

At the time we were looking at a 2 gb commit...

$4 a meg sounds really expensive, at that point it is almost worth it going up, have room for future expansion and pay less for it, or do you do, and split the BW and cost.

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#137

kudos to Amazon for running time backward and letting you pull your foot out of the way. I can't help but think that if benign decisions lead to disasters like this in the cloud, how much destruction could robots wreak in the future due to similar benign choices?

"To err is human, but to really foul things up requires a computer." - Bill Vaughan

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#139

Earlier quoted context omitted.

Is that a term? "Cost of service attack" ? If not, let's coin it :) Cost-of-service-attack: Consuming bandwidth or other resources in cloud based solutions to drive up the cost of running the service. Very easy when the cost is so tightly coupled with the resource use...

OK, so now we have DoS and CoS! I dunno though, it's all technically bandwidth flood in the end. The consequences (or goals) of flood may include immediate or eventual denial of service, high cost of service, various security attacks, or probably all at once—further classification surely is complicated. Meanwhile, both terms DoS and CoS are a bit vague, too. Say, turning off a server or forcing providers to alter the…

I wold argue that "DoS" is not vague, just a broad term.

Aanyway.. You're right, it boils down to bandwidth flood (or maybe CPU..) in the end.

Maybe CoS is not really a technical term, just made more relevant by the technological changes. OP would have been charged much less had he not been using "the cloud".

Lets say I have small'ish competitor hosting their app on EC2. Using classical DoS techniques, how much can I ramp up their bill before they notice? Or can actually stop it? What if I run it on a smaller scale, "just" doubling their bandwidth bill.. Will they notice? Maybe they'll believe it's extra users ;)

Re: How I attacked myself using Google and I ramped up a $1000 bandwidth bill

#140

Earlier quoted context omitted.

Ironically, it might be DoS in the sense that it drives app maintenance costs so high that the owner could decide to, naturally, deny the service (shut down). Otherwise, maybe it's the new type of flood attack, cost-of-service (CoS), applicable against those who use ‘invincible’ cloud infrastructure such as Amazon's.

Is that a term? "Cost of service attack" ? If not, let's coin it :) Cost-of-service-attack: Consuming bandwidth or other resources in cloud based solutions to drive up the cost of running the service. Very easy when the cost is so tightly coupled with the resource use...

I believe this kind of attack is already referred to as EDoS (Economic Denial of Service/Sustainability) - basically killing of a service through bankruptcy.

This is why most cloud services have a customisable limit on how many virtual servers can be booted automatically, a solution is yet to be found for protecting S3.

Post reply on HN