Ok that went viral. I have two comments regarding the most frequent replies.
1. Yes, cloudflare is a short term solution, but the real solution can't be that we all need to book services at company A to protect against company B. The result would be a huge monopoly battle.
2. Stop suggesting to poison them with huge amounts of fake data. That would only further increase the waste of resources on all sites.
@leah Without knowing all the details myself, do you think HAProxy IP based rate limiting could have a chance for mitigation? IIRC the evaluation window for the rate limiting can be quite short.