How to protect your Vercel site from attackers

Поделиться
HTML-код
  • Опубликовано: 19 июн 2024
  • Learn how you can quickly lock down traffic and further protect against DDoS attacks by challenging requests, minimizing the chance that malicious bots get through, with Vercel's Attack Challenge Mode.
    0:00 - Introduction
    0:17 - Attack Challenge Mode
    0:49 - Demo
    1:47 - Rate Limiting
    2:05 - Spend Management
    2:35 - Conclusion
    ◆ Learn more: vercel.com/changelog/prevent-...
    ◆ Firewall: vercel.com/docs/security/verc...
    ◆ Rate Limiting: vercel.com/guides/rate-limiti...
    #vercel
  • НаукаНаука

Комментарии • 30

  • @000-way7
    @000-way7 2 месяца назад +17

    Vercel's answer to $104,000 Netlify bill on serveless horrors

  • @Nusab33
    @Nusab33 2 месяца назад +17

    To be able to set a budget and pause production deployments is very helpful for me. And I think others will like it too! :D

  • @utuberlol
    @utuberlol 2 месяца назад

    This is great to see, youre always listening to your costumers and iterating

  • @xReDxTuRtLeZx
    @xReDxTuRtLeZx 2 месяца назад

    thats awesome! really cool to see this come up so soon after that other vid where you mentioned vercel was cooking up something for this

  • @DominikSipowicz
    @DominikSipowicz 2 месяца назад +1

    As always amazing content! Thanks Lee!

  • @basketberoende
    @basketberoende 2 месяца назад

    This is why I love you guys. Making WebDev so simple

  • @philipaarseth
    @philipaarseth 2 месяца назад +10

    Would be nice to add a toggle so that you can either let it turn on automatically (and off when spike usage dies down) and notify admin OR notify admin on usage spike and ask if mode should be enabled.

    • @leerob
      @leerob 2 месяца назад +2

      Vercel automatically serves challenges (same screen) when it can detect malicious traffic. Attack Challenge Mode is when you want to manually flip it on. For notifying admin, are you thinking an email to the Team owner?

  • @zhanezar
    @zhanezar 2 месяца назад

    really great work guys, always believed you would find a way to help with these horror stories on twitter.

  • @jonoisedev
    @jonoisedev 2 месяца назад

    Great feature!

  • @rhysyw97
    @rhysyw97 2 месяца назад +2

    If the rate limiting is in the middleware, Vercel charges per-middleware invocation so you'd still incur a potential large bill if the rate limit is triggered a lot?

  • @enza9189
    @enza9189 2 месяца назад +2

    Nice

  • @ttowe
    @ttowe 2 месяца назад

    omg, love it

  • @jjrise
    @jjrise 2 месяца назад

    love it

  • @yassinesafraoui
    @yassinesafraoui 2 месяца назад

    It would be very interesting to have an option to automatically turn on this mode when the number of requests are over a certain limit or sth like that, maybe when the number of requests is greater than 3 times the avg for example, you get the drill

  • @PhiliprecordsTV
    @PhiliprecordsTV 2 месяца назад

    Will attack challenge mode block crawlers like googlebot? can it effect page rankings?

  • @julienben
    @julienben 2 месяца назад +2

    Great to have this! Quick question: Is there any way to turn it on without breaking uptime monitoring? Somehow?

  • @freakinmonkey85
    @freakinmonkey85 2 месяца назад +1

    Does attack challenge mode also protect api routes?

    • @leerob
      @leerob 2 месяца назад +4

      Yeah!

  • @cguser
    @cguser 2 месяца назад +3

    can vercel send notification when there's a vulnerability checked found?

  • @powaaaka
    @powaaaka 27 дней назад

    midudev?

  • @pranshubasak8796
    @pranshubasak8796 2 месяца назад

    Just add a button restric bill thats it , is it to much to ask

  • @JamesJGoodwin
    @JamesJGoodwin 2 месяца назад +1

    What are the advantages of Attack Challenge Mode compared to Cloudflare "I'm under attack" mode?

  • @nico0lat3
    @nico0lat3 Месяц назад

    @midudev sacaron este video gracias a ti ajajaja

  • @koko0808008
    @koko0808008 2 месяца назад

    Can we have proper CSP documentation? Nothing is working out of the box (fresh install + documentation followed)

  • @bobbymray
    @bobbymray 2 месяца назад +2

    Support Palestine

  • @zlackbiro
    @zlackbiro 2 месяца назад

    Using Vercel in 2024 in the era of cheap VPS is simply dumb.