Then we need to fix the infrastructure so that the current generation of attacks don't work. To just say, "oh, well bandwidth is limited so there's always going to be an attack" is not useful. Think of ways you can structure the infrastructure so that it can do filtering further out, or detected spoofed connections, or detect anomalous request patterns. There are solutions, we need to find them and implement them, not just tell people not to do it or claim it's a "weak" attack. It's a strong attack if it takes minimal effort to cause maximal damage. In the real world, that's what matters. There's the idea that we're playing a game and that there are behaviors that are good form or bad form. However, when it comes down to it, what works is what works.
You'd still have to pay for all the computing time to remain available during the attack. Its probably not worth it to try to stay up in that kind of storm.
mentat, I wasn't saying don't protect ourselves against this. However, harnessing a big enough bot network you can always overcome these measures. Finding an exploit is different, and especially for financial institutions inexcusable to a certain level.