While Cloudflare may reach out and say 'you should be on enterprise' when that happens on R2, the fact they also handle DDoS and similar attacks as part of their offering means the likelihood of success is much lower (as is the final bill).
While Cloudflare may reach out and say 'you should be on enterprise' when that happens on R2, the fact they also handle DDoS and similar attacks as part of their offering means the likelihood of success is much lower (as is the final bill).
AWS made S3 as data storage, then added CloudFront for CDN purposes. The CDN is an optional addon which may or may not make sense... E.g. an internal data storage staying in AWS doesn't need the CDN.
Comparing CloudFlare to S3 is apples and oranges, in my option. Comparing CloudFlare+R2 and S3+CloudFront is more appropriate, I think.
---
Additional thoughts:
It's hard to evaluate the bias of the author.. The author clearly dislikes AWS, and while some of the plants are generally what I would agree with.. I question if the author is properly evaluating AWS in the comparison and trying to sell their book. Would the book be any better, or would it echo chamber the typical AWS perceived negatives. For instance, the author notes S3 intelligent tiering... But if you know that the data is not going to be accessed, you could likely skip the overhead of intelligent tiering and directly put it into a cheaper storage class... And in general the same with other S3 data types.
I do generally agree that AWS bandwidth charges are extortion... But I still would want less bias in a product review/comparison from something posted here on hacker news.
It should be possible to use the service, especially common ones like S3 with little knowledge of architecture and stuff.
S3’s simple setup (which denies all public access) is not flawed in the manner being discussed here. Allowing public direct access to an S3 bucket is a supported option, but for years has been both non-default and strongly recommended against.
It doesn't take anything near DDoS. If you dare to put up a website that serves images from S3, and one guy on one normal connection decides to cause you problems, they can pull down a hundred terabytes in a month.
Is serving images from S3 a crazy use case? Even if you have signed and expiring URLs it's hard to avoid someone visiting your site every half hour and then using the URL over and over.
> AWS is just charging you for how much it served, it doesn't make sense to hold them to a fault here.
Even if it's not their fault, it's still an "inherent vulnerability of S3 pricing". But since they charge so much per byte with bad controls over it, I think it does make sense to hold them to a good chunk of fault.
Do you expect DDoS protection to kick in from one person downloading a single digit number of images per second?
[0] https://aws.amazon.com/about-aws/whats-new/2024/08/amazon-s3...