Ask HN: How much abuse does your web app get, how much prevention do you put in?
Background: our app is free to sign up and upload all of your content (URL is in my profile). The pay wall comes when you want all of that content to go live and be available to your users.
Example Concerns: 1. An account holder can upload unlimited content, but the common use case will only be what they have (on the order of 100MB most). 2. A user could feasibly switch their billing plan unlimited number of times. 3. The RESTful interface to the content requires no authentication and isn't throttled (it does do some header checking) and links to large media files are raw, source of request is unchecked on server end. 4. DDOS, general "script kiddie" stuff, dictionary attacks on root pw to servers (i use a non-standard port)
Everything that can be considered "harmful" would eventually be caught (woe be to my bandwidth bill) and dealt with, but possibly not before some "damage" has been done - namely a huge distraction and time sink to find and correct the issue/perpetrator.
How much "abuse" does your web app take? How aggressive are you in preventing such behaviors?