
DEF CON 33 - Defending Reddit at Scale - Pratik Lotia & Spencer Koch
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 26:26
Reddit's security team shares their approach to defending against 1.3 trillion weekly requests through a multi-layered DDoS prevention strategy using signals and rate limiting at both edge and application layers 0:30.
Key Takeaways:
• Reddit uses a hierarchy of signals starting with foundational (IP, user agent) progressing to TLS fingerprints and request header fingerprints to identify malicious traffic 3:15-7:52
• They implement rate limiting at both edge (using Fastly/Cloudflare) for cost efficiency and application layer for user-specific context 11:39-13:00
• Advanced signals like network request timing patterns help distinguish human users from automated scripts 8:51-10:07
Their approach evolved from reactive "whack-a-mole" to a dedicated transport team and traffic management system 2:13-3:11.
Sources:
- 0:30 Overview of what the talk covers about rate limiting
- 3:15-7:52 Explanation of signals hierarchy from IP to advanced fingerprints
- 8:51-10:07 Network request timing as an advanced signal
- 11:39-13:00 Edge vs application rate limiting strategies
- 2:13-3:11 Evolution of Reddit's DDoS prevention team
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Uh so let's get started. So I'm Spencer Ko. I'm a principal security engineer at Reddit and I'm joined by Pratik. Uh he's a senior engineer, senior security engineer at Reddit as well. And we're on the security team. Uh and so thank you to the the DOS village for having us be up here and we sponsored him too. So like we're great to see that advance. Um and I know we've got some uh moral support in the back as well. So thanks for coming out and we're going to be talking about DOS stuff. Um, so in terms of context, and I'm I'll try to read the top of the slide as you attempt to follow me through my slides that are online. Um, so what are you going to get from this talk? So hopefully we should be able go through a an architecture, how do we think about rate limiting and so the the way that we…