Cloudflare blocks an enormous number of bad actors for me, so I quite like it.
I'm curious about the specifics because through my and my colleagues' simulation of "bad actors" (ethical hacking) I've never once gotten stopped by CF. I thought the point was anti-DDoS by just proxying your traffic through someone with bigger pipes. That they do TLS offloading to filter n-days like Heartbleed helps as well of course, but those are super rare events and it sounds like what you mean is ongoing. What…
But a layer 7 DDOS attack, when going through Cloudflare, means the malicious actor needs to have IP addresses that are at least not complete trash in terms of IP reputation. Getting access to a botnet and access to these IP addresses isn't exactly prohibitively expensive, but it's a much larger barrier to entry.
It's even harder to get taken down by a layer 7 DDOS attack on Cloudflare if you use "im under attack" mode, assuming your attacker isn't paying even more for the botnet to run something like Chromium or node to hit your website.
Finally, while Cloudflare doesn't actively do this for small-scale DDOS attacks (since it might just be a spike of users), they do have Gatebot for the larger scale ones https://blog.cloudflare.com/meet-gatebot-a-bot-that-allows-u....