Home
Starting Up
Case Studies DB
Products
Ideas DB
Vibe Coding Tools
Subscribe to IH+
Starting Up
Case Studies
Ideas DB
Products DB
Join
36
Likes
17
Comments
How my startup survived a DDoS attack
by
Maaike
https://www.bannerbear.com/blog/how-to-survive-a-ddos-attack/
I think that the risk of getting attacked for ransom increases for IH companies that share revenue numbers like BannerBear does. Attackers probably research and target businesses with money and sites that are more vulnerable. That said, using CloudFlare like Jon recommends may be enough to dissuade most attackers; they’ll probably move on to easier targets.
I think people should actually start with Cloudflare (which is free), otherwise they risk a random DDOS at any time. If it's already free, why not do it, is my thought process.
Cloudflare is the perfect tool to prevent DDoS attacks or at least make it easier to fight against them.
It's literally built from the ground up to deal with DDoS attacks. If they can't keep your website up, no one can. I think normally the worst DDoS attacks they've ever dealt with were dealt with within 12-hours.
I agree, but it's important to make sure to not leak the way how cloudfare access your backend. Otherwise the attacker will just bypass cloudflare.
If you are hosting your site directly on cloudflare then you don't have this risk.
What do you mean by hosting directly on Cloudflare? Does CF offer an option to deploy your app on their servers?
Yeah, I use Pages (which has a free tier) myself, which is for static content. But pretty sure they have other offerings as well.
You know you’ve made it when your SaaS is successful enough that they bother to DDoS you????
Man, every indiehacker’s nightmare! Thanks so much for sharing your story here, and giving people a bit of a playbook. I’m happy that I’ve got Cloudflare already set up, and hope that my SaaS is someday as successful as yours, but perhaps without the attacks. 😆
I really felt his experience reading that. CloudFlare is a savior indeed.
Been hearing this a lot on the indie grapevine lately. Kudos for migrating quickly and avoiding disaster. And thanks for sharing your experience and advice. Attacks are something we don't like to think about but being prepared and acting quickly is essential.
Oh this was a nice read. I have never used CF personally but one of the clients of a company I previously worked at used CF. I should probably look more into them.
The blogpost mentioned that china originated traffic was blocked. what if the ddos comes from US based ip addresses instead? Just curious how to filter that out.
Thanks for sharing this!
I thought Cloudflare was hard to set up, but if it's as simple as changing DNS and it has a free tier, it's totally worth trying it just in case.
It's may not that hard as you think. Just sign up and enter your domain name then it will tell you what to do
If you don't want to use CloudFlare, you can consider using AWS API Gateway, where you can configure network rules and request throttling configuration to avoid DDoS attacks. Ref: https://aws.amazon.com/api-gateway/
I'm saddened by the fact people do this tbh. Makes me reconsider whether sharing revenue is a good idea
This kind of thing worries me all the time. Well done on mitigating what could have been a big disaster.
This comment was deleted 4 years ago