I'm wondering what the implications of DDOS are for website owners. What if you're on EC2 for example, will you be charged for the 300 TB of traffic? If so that would be an easy way to bankrupt a startup.
The implications for website owners are that their web sites were temporary unavailable.
Traffic simply does not reach the web site. Even normal traffic.
For example, you type in your browser www.mywebsite.com.
DNSMadeEasy would normally resolve it to your IP address (e.g. 111.222.123.12). But because of the DDoS attach -- mywebsite.com cannot be resolved into any IP address and you cannot open www.mywebsite.com at all.
That's the implication is there is a DDoS attack on your DNS provider, but I think FooBarWidget was inquiring about the implications of a DDoS attack on your website, and specifically if you would be charged for the bandwidth consumed by the attack.
You can - but not everywhere - negotiate that the service you pay for includes protection against DDOS attacks and that it's up to your provider to protect you. You'll pay a larger fee per mbit because they'll need to do more work for you in case you get hit but it might be worth it.
My policy for this is to simply lock the doors and hide for an hour if my network traffic averages over 2 Mbps for 5 minutes. I would also send myself an email. So far this has never happened.
get akamized. you can also build traffic limits into your web stack or OS or network gear if you're afraid of traffic ramps hurting your wallet. like tptacek said, a good DDOS looks like normal traffic, so this could happen if you got slashdotted by 10 different news sites.