Am I the only one who skipped rate limiting because "nobody would bother attacking us"
I used to think rate limiting was only for big companies with public APIs, so I left ours wide open for about 8 months. One Tuesday morning a guy named Dev in our own Slack sent a screenshot of a script he ran that pulled 40,000 records from our login endpoint in 12 minutes using just a free tool. That was the moment it clicked, and honestly the biggest tip-off was how easy he made it look with zero effort. We put a 60 requests per minute cap per IP that same day. Has anyone else had a teammate prove them wrong on something this basic, and did you go with per-IP or per-account limits after?
Disagree with the whole panic here. That "attack" was a teammate running a script on your own login endpoint, which is not an attack at all, that is just load testing you never asked for. Nobody external cared about your app for 8 months and nobody cares now, the free tool Dev used would work on half the internet and proves nothing about your actual risk. Rate limits mostly punish real users who type a password wrong a few times or refresh on bad wifi, and per-IP caps are easy to get around with a proxy anyway. Going from zero to 60 requests per minute per IP the same day is a knee jerk fix that will break someone's legit workflow and you will never even know it happened. You got scared by a screenshot, not by an actual breach, and now you are locked into tuning limits you did not need. So no, you were not wrong for 8 months, you were just fine.