Live data from Hacker News

Slashing data transfer costs in AWS

bitsand.cloud

251–260 of 268 posts

Re: Slashing data transfer costs in AWS

#251

Earlier quoted context omitted.

> Amazon does not have prove anything to anyone. True. And no one has said that they must prove anything to anyone. Amazon wants to make money, so they probably don't want to terminate the service of people who are acting in good faith. But that's just another way of saying that they probably want to determine with some certainty that someone is not acting in good faith before terminating their service. So it's not t…

In this case they are actually losing money not gaining by allowing this kind of abuse, both because the bandwidth usage costs money and also because of potential lost billing from other services which now is not billed. The Lightsail style billing model works same way shared vs leased lines works, if everyone fully used their max allocation it won't be possible to offer service at that price point. They can offer 2T…

> In this case they are actually losing money not gaining by allowing this kind of abuse, both because the bandwidth usage costs money and also because of potential lost billing from other services which now is not billed.

Your statement here is absolutely correct (we are in agreement); it is also absolutely orthogonal to what I (and others) have said.

Let me use an analogy.

Marijuana is illegal in most states of the US (and, federally, it is still a controlled substance). And yet a (relatively) recent survey[1] showed that around 7% of respondents grew marijuana at home.

How is this possible? Shouldn't that be 0%? It's almost like the DEA is slacking off or something.

... or maybe it's because they can't practicably round up each and every one these people: the DEA isn't omniscient, and given the 4th amendment they can't ransack every home within the US to catch these people. If you don't do something that gives them sufficient evidence to acquire a search warrant, there's nothing they can do about you growing pot in your domicile.

Back to Amazon. Could you, at a high level, describe a process by which they could, for a given account, determine if that account's use of LightSail is legitimate, or is instead intended to avoid incurring data fees from other services? And you must satisfy some additional, absolutely crucial qualifications: this process must not negatively impact abiding users (because they would abandon AWS, resulting in financial harm to AWS), the cost to AWS of executing this process must not be prohibitive (in terms of compute, human resources, etc), and the process must be applied across all accounts within a reasonable time frame (if it takes 1 year for AWS to comb through 1% of accounts, that means you have a mere 1/100 odds of having your service terminated for abusing LightSail for an entire year).

Something being prohibited doesn't imply that it is practicably, fully enforceable.

[1]: https://pubmed.ncbi.nlm.nih.gov/36288408/

Re: Slashing data transfer costs in AWS

#252

Earlier quoted context omitted.

Both on prem and cloud require people familiar with them and cloud-engineers are in no way cheaper. I think the real story is a bit sordid: office politics. On-prem and cloud are different skillsets. Companies that have been around for a while can end up with both on-prem and cloud experts who end up competing with each other, often on separate teams. Throw in some slick consultants from Amazon who are able to bend t…

Cloud engineers can do the job of 4-5 on-prem people. Our AWS devs don't need to be BGP or ZFS experts, they just need to be AWS experts.

2015 called and wants it's hype back.

Re: Slashing data transfer costs in AWS

#253

Earlier quoted context omitted.

I don't think you parsed their message correctly. It's not about litigation. Re-posting a bit of the service terms for easy reference: > 51.3. You may not use Amazon Lightsail in a manner intended to avoid incurring data fees from other Services [...] As you point out, they may terminate your service without any justification in a court of law. So how do they go about terminating the offenders? Well, one trivial way…

We disagree on the definition of "prove". I would not object to the claim if it had used "determine" or "detect" instead of "prove". That said, detection is easy. Look for users who spin up a Lightsail instance and use close to 100% of its bandwidth quota before spinning it down. Sort by number of such instances, and tell all users above some cutoff that in your sole discretion you believe they have violated your TOS…

I hear you.

> We disagree on the definition of "prove". I would not object to the claim if it had used "determine" or "detect" instead of "prove".

I do find that a bit odd, though. If I consult the Merriam Webster dictionary, I see precisely one entry under "prove" that says anything related to law and/or courts:

> to establish the existence, truth, or validity of (as by evidence or logic)

> "prove a theorem"

> "the charges were never proved in court"

Even there, the only mentioning of court is in the example sentence, rather than the definition itself -- naturally, we want our court system to be based in reasoning rather than whim.

Additionally, the meaning of "prove" given by this definition is exactly what the study of formal logic sets out to codify, and given that this is hacker news (where many are interested/involved in computer science and/or formal logic itself), it seems counterproductive to ascribe some legal meaning to the word "prove" here, as it would (to my mind, at least) be quite unlikely for others to do so.

Re: Slashing data transfer costs in AWS

#254
post #115

Earlier quoted context omitted.

You act like these problems are especially hard. Active-active, five nines, fault tolerance. Hard stuff. But managing on-prem is no harder. This is what we're paid for.

Managing on prem is definitely harder because you are benefiting from the economics of scale of all the management problems that you have to pay yourself, and if you don't have scale then you will be significantly overpaying to get the same type of quality, reliability, or responsiveness. Most people are not paid to manage infra, they are paid to talk to customers, ship features, fix bugs, and other "core business" i…

If you don't have scale, you don't need most of the features. Fire up PC, load application. Setup egress port open to internet. Setup application backup on cron job. Done until scale problems arise.

Re: Slashing data transfer costs in AWS

#255

Earlier quoted context omitted.

In this case they are actually losing money not gaining by allowing this kind of abuse, both because the bandwidth usage costs money and also because of potential lost billing from other services which now is not billed. The Lightsail style billing model works same way shared vs leased lines works, if everyone fully used their max allocation it won't be possible to offer service at that price point. They can offer 2T…

> In this case they are actually losing money not gaining by allowing this kind of abuse, both because the bandwidth usage costs money and also because of potential lost billing from other services which now is not billed. Your statement here is absolutely correct (we are in agreement); it is also absolutely orthogonal to what I (and others) have said. Let me use an analogy. Marijuana is illegal in most states of the…

It is pretty hard to move out of any cloud .

If your workload is just Compute or stateless with commodity or standardized API interfaces you could maybe do a move maybe.

Even for those it is fraught with problems and takes a lot of time , time you are not developing features and adding product value.

If you are using S3 or any sort of proprietary stack on AWS to the cost to migrate (retrieval + b/w or rewrite your app ) is just too prohibitive .

All cloud providers know this and plan that in their models , reason why they give out generous free tier or give a ton of money in startup programs or other hooks to get you to start .

——

AWS does not just have an all or nothing suspension policy .

From personal experience I know they do suspend your access to a single service at even single region level - our account still has SES blocked in one region because early on we handled bounces poorly and this was at least 8 years ago they even sent few warnings too, so they have pretty robust framework to handle abuse. Back then I couldn’t get it unblocked with tickets and escalations , I am sure we spending 15/20k a year then so not super small either .

These days we spend more like 250k a year on AWS and I still don’t get a proper account manager. I could perhaps get it unblocked now if I really wanted, not just worth the hassle to jump the hoops, one of the reasons why Azure is our primary cloud partner and we spend most of our money on despite subpar tech compared to AwS (GCP is 10x worse on this) .

I cannot comment on specific controls that is put on lightsail never used the service but they definitely do have a framework to suspend for every service they offer.

Just given the generous free tier, there is huge industry of using stolen credit cards to run scams or send spam on AWS which they constantly have to fight against.

Re: Slashing data transfer costs in AWS

#256
post #250

Earlier quoted context omitted.

The other companies have significantly different SLAs and drop packets far more readily. They also charge for bandwidth, in my experience, you get your 1TB/mo with your $5 VPS sure, but once you go over, you're facing per/GB charges that are very close to AWS default egress price. They're not a magnet for these services for the reasons I just described as you reach your per VPS limit very quickly, and to get more "ch…

Digital Ocean and Vultr are a fraction of AWS pricing. Vultr is $0.01/gb. Bare metal providers are often cheaper still, selling by size of pipe rather than bytes transferred. In my experience GCP and AWS are pretty unwilling to budge on bandwidth pricing unless you are very large and making a long commitment. If you are not spending six figures a month forget about it. You may be right about SLA but I run large volum…

They'll sell you the pipe without any guarantee and some include provisions that allow them to instantaneously downgrade your pipe if they decide your servers are a traffic management problem.

I can't speak to GCP, AWS is pretty generous, and they even suggest you contact them for a deal once you're in the low 5 figure range, and that's across all services in a region. If you move enough data the discount is significant and approaches overage pricing at VPS providers.

I'm sure. If I were running things that were more bandwidth heavy as opposed to integration heavy, we would have gone that route as well, and we would have gone through the extra trouble of getting some provider diversity and redundancy built in.

For smaller cases, they can avoid all that overhead and just trade those into bandwidth costs. Which, if your costs do get high, it's much easier to build an external caching network then it is to build a bunch of external dependent infrastructure with bare metal providers.

In any case, I don't think it's that AWS is taxing it's users unfairly, I think the costs are a solid reflection of where their engineering effort and variable costs are concentrated. It seems like maintaining symmetry in bandwidth is one of those.

As a customer I can use petabytes one month and then zero bytes the next month. They have link agreements with multi year terms and possible "balance payments" required if symmetry is not maintained. This type of bandwidth isn't as cheap to provide under these terms.

Re: Slashing data transfer costs in AWS

#257

Earlier quoted context omitted.

That's why I said 'virtually'. Hurricane Electric does 40gig/sec IP transit for $2k/month. Assuming you used 50% of the capacity of that link that's about 1/200th (I think, numbers are so small) of the cost of AWS for bandwidth.

> That's why I said 'virtually'. I hear you, and that is an egregious margin. Just wondering if part of their bandwidth pricing calculation is driven by a goal of constraining their infrastructure costs (or other considerations beyond profit). I'm actually wondering this exactly because it is so egregious. There is of course a thing wherein if something is free people mindlessly use it. If all AWS customers did this…

No. It's pure margin. OVH and Hertzner et al offer "realistic" bandwidth pricing and they are all fine.

I am almost certain there will be some sort of cartel investigation into this pricing between the big cloud players.

Re: Slashing data transfer costs in AWS

#258
post #250

Earlier quoted context omitted.

Digital Ocean and Vultr are a fraction of AWS pricing. Vultr is $0.01/gb. Bare metal providers are often cheaper still, selling by size of pipe rather than bytes transferred. In my experience GCP and AWS are pretty unwilling to budge on bandwidth pricing unless you are very large and making a long commitment. If you are not spending six figures a month forget about it. You may be right about SLA but I run large volum…

They'll sell you the pipe without any guarantee and some include provisions that allow them to instantaneously downgrade your pipe if they decide your servers are a traffic management problem. I can't speak to GCP, AWS is pretty generous, and they even suggest you contact them for a deal once you're in the low 5 figure range, and that's across all services in a region. If you move enough data the discount is signific…

Hahahah. I don't even know where to start. If you think a 200x markup from list price on IP transit is a fair reflection of costs from AWS then good luck to you.

Re: Slashing data transfer costs in AWS

#259
post #115

Earlier quoted context omitted.

Managing on prem is definitely harder because you are benefiting from the economics of scale of all the management problems that you have to pay yourself, and if you don't have scale then you will be significantly overpaying to get the same type of quality, reliability, or responsiveness. Most people are not paid to manage infra, they are paid to talk to customers, ship features, fix bugs, and other "core business" i…

If you don't have scale, you don't need most of the features. Fire up PC, load application. Setup egress port open to internet. Setup application backup on cron job. Done until scale problems arise.

Correct, my point absolutely doesn't apply to someone who is just doing their thing, even maybe 2 orders of magnitude more stuff than their thing.

But when your local IT goon says its going to be 8 months to procure the next set of hard drives for your next order of magnitude, it's a real problem and you have real money to invest in solving it, just not owning a data center money.

Re: Slashing data transfer costs in AWS

#260

Earlier quoted context omitted.

This is basically the logic of people who say the cloud is too expensive, you have to ignore so many things to make being on premise logical. Basically you are lying to yourself if you think you can run a datacenter cheaper and better than Amazon or Microsoft can, because if you can you are just making huge sacrifices somewhere (usually time, which is why reddit sysadmins complain about how much work they have while…

>Basically you are lying to yourself if you think you can run a datacenter cheaper and better than Amazon or Microsoft what magical things do they have? that every single reasonably sized enterprise doesn't have? it should be extremly easy for a small enterprise to beat any of the main clouds* - they make crap ton of profit from you *making an assumption that your needs are reasonably static and not MASSIVELY busting…

The "magical" thing they have is thousands and thousands of people thinking about how to improve the performance/efficiency/availability of their datacenters.

And yes, they pay the costs of those people and take a good profit margin, and yes there are in some ways diminishing returns to go from 3 nines to 6. But most enterprises can't match that depth of concentrated expertise, certainly not most small enterprises.

Post reply on HN