But with serverless you don't pay for idle time !
But with serverless you don't pay for idle time !
Before everyone gets their pitchforks out - Person from the image posted on Hacker News, CEO replied and said this charge shouldn’t have happened and they wouldn’t be charging the client anything.
Hm yes and no. The user might have angered someone with their website and it might well have been targeted.
If I were to do that I’d probably put cloudflare in front. But I wouldn’t host on a service with unlimited pricing anyway. I’d much rather see my hobby site go down than to have world-class uptime and pay 100k :P
Hell even AWS isn’t this bad. You can go in and set the maximum data you’re prepared to allow and then it’ll simply just block any connection attempt after that point and send you an alert.
You just have to be aware that you might need to keep an eye on things and be ready to increase bandwidth occasionally in case of something like Black Friday, assuming that kind of thing is relevant to your site.
The user might have angered someone with their website and it might well have been targeted to them instead of Netlify as a whole? I can imagine them using that point in a court if that was the case.
They wouldn’t really get anywhere with that claim though, even if it were true when they could find evidence, because the company claims that they actively scan for and protect against this sort of thing, and even they admit that it was a DDoS attack.
CEO said that forgiving bills for this kind of a thing is a standard practice, but how come this was the customer support’s first reaction:
We normally discount these kinds of attacks to about 20% of the cost, which would make your new bill $20,900. I’ve currently reduced it to about 5%, which is $5,225.
If the customer support has authority to give 20%/5% discounts, this seems to me like the standard practice, and the CEO is probably just doing damage control because this became public.