logoalt Hacker News

embedding-shapetoday at 9:42 AM1 replyview on HN

Your webserver most likely have "rate limiting" built in already, which you can configure to act based on lots of variables typically. Set a limit of 1 req/s or whatever, and you've stopped 99% of all DDoS you'll encounter on the public web. If your visitors get cranky, up it to 10 req/s and you still are preventing most of the "abusive traffic", granted your backend/website isn't completely upside down when it comes to performance and resource usage.

CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.


Replies

viraptortoday at 10:49 AM

This is not how things work and no company providing online services for money would rate limit like that. This would do nothing for real world DDoS. You're in "not even wrong" territory.

And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.

show 1 reply