upvote
It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service.

> and I don't think people should default to trying to prevent them.

It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.

Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)

reply
I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada:

https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...

reply
That graph is useful for the people who think DDoS is the biggest issue or even a big issue typically: https://www.bdc.ca/globalassets/digizuite/55250-canadian-sma... "Percentage of Canadian small businesses that have experienced a cybersecurity incident"

The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.

reply
What exactly are you arguing? I already said 5%. Your personal experience of DDoS being super rare doesn't seem to match the real world.
reply
Literally the graph you posted agrees with me. Most "cyber attacks" are phishing according to that graph, which I'd argue is less of an technological attack and more social engineering.

Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.

> Your personal experience of DDoS being super rare doesn't seem to match the real world.

What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.

reply
For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days.
reply
Wouldn't most udp reflection attacks be bigger than your pipe?
reply
Dozens and dozens of times. And having the bigger pipe has always saved it, along with the supporting infrastructure to churn through that traffic.

> But again, those sort of attacks seem to happen seldom

[citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.

reply