Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

61–70 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#61

That is the problem with massive centralization even if it is market level and internally Cloudflare (or any other big fish) does decentralization/fail-over of their own. Many of these companies should have had fail-over to competitors at least for reliability. The problem with near market monopolization, oligopoly, even the singularity, the fail-case is catastrophic and may even wipe out decentralized, diffused, dis…

The question is: Can we do better? A natural monopoly is a good thing. It just means that the natural monopoly needs to build its own redundancy. Cloudflare total failure isn't common.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#62
post #54

Earlier quoted context omitted.

The jist of my comment is why nobody else has tried the "liberal free tier" model for a CDN, as it seems to be working for CF.

Sure, but all 3 cloud providers have free tiers for this stuff, don't they?

Not that would work for a CDN use case as far as I know. The cloud providers are notorious for high egress costs.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#63

Honest question: I've never really understood the back of the napkin math of how Cloudflare functions economically, which I feel would go a long way towards my understanding of why/how they were able to become such an integral and generally positive part of the Internet. Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw…

> Did they figure something else out that nobody saw?

I may not have a full scope of the history, but my own experience with DDoS protection was quite different. Whilst providers offered anti ddos protection through GRE tunnels and dedicated machines behind DDoS appliances and a heavy null route hand, Cloudflare had a simple few-click solution that worked at the web application level making things a lot easier and, also, allowing for features like caching, and thus, CDN benefit from a global network. Further, they've maximized performance on their machines, and as a result, Cloudflare is wicked fast.

Cloudflare does what it does really well and has built additional services on their global network that make a lot of a sense and provide a lot of value.

Hats off to CF.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#64

Earlier quoted context omitted.

I think the root cause (which, IMO, you correctly point out) is lost on many modern developers. For whatever reason there's this modern idea that if a company A is paying money to company B for a service, that company B will handle all the 'hard stuff' for them. The end result is we have a lot of applications/infra built with SPOFs, in some cases known, but in many, swept under the rug and abstracted away to passing…

"Your app will go down when half the Internet goes down" is not that big of a deal to most software companies, because: 1. no one's going to blame me if my app goes down when half the Internet is also down but they are going to blame me if my custom solution to the same thing causes an outage, 2. there's no way my custom solution is going to achieve the same uptime. AWS/Cloudflare/Azure are not perfect, but whatever…

They do blame you though, most people won't be aware of the real issue, when cloudflare went down, the trending things on twitter were #spotifydown and #applemusic

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#65

What's funny about this outage is I'm sure many of of us (myself included) used this window to analyze large services and determine an increase in major Cloudflare customers and presumably, revenue. Even ISPs like T-Mobile faced issues due to the Cloudflare outage! The situation has exposed just how critical Cloudflare is. I went ahead and bought calls ahead of NET earnings next month. Cloudflare is becoming an incre…

> an increase in major Cloudflare customers and presumably, revenue. Even ISPs like T-Mobile faced issues due to the Cloudflare outage!

Careful about this methodology. Some services at my org were impacted despite not being direct CloudFlare customers. They had external dependencies that used CloudFlare.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#66

This is just an advertisement for easydns.

The more people that use anything other than Cloudflare, the better. I had this conversation with people back in ~2010 about Facebook and they all ignored it. They will again, but this time the consequences of centralization will be even worse.

It won't just be one single website that goes shitty with blockages and manipulation and censorship. It won't even be just the web. When Cloudflare achieves their goal of deep packet inspection at every peering and transit point it'll be the end of the internet as we knew it and the slow transition to just another cut apart "China-net (tm)".

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#67

That is the problem with massive centralization even if it is market level and internally Cloudflare (or any other big fish) does decentralization/fail-over of their own. Many of these companies should have had fail-over to competitors at least for reliability. The problem with near market monopolization, oligopoly, even the singularity, the fail-case is catastrophic and may even wipe out decentralized, diffused, dis…

> Many of these companies should have had fail-over to competitors at least for reliability. How would you even set such a thing up? I fear that you might get a couple of collusionary companies that bail each other out and smaller providers might just be left out to dry…

I imagine the implementation could look similar to how cell phones can use other carriers networks (for 911) when they don't have signal from their own carrier.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#68

Honest question: I've never really understood the back of the napkin math of how Cloudflare functions economically, which I feel would go a long way towards my understanding of why/how they were able to become such an integral and generally positive part of the Internet. Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw…

Cloudflare is a relatively cheap "lite CDN" for developers who want caching without putting in any work. This becomes a gateway drug for Cloudflare's more expensive plans once you outgrow the free plan. It quickly adds up; I worked for a company that wasn't even on an enterprise plan and was spending hundreds of dollars a month on Cloudflare just because they had a lot of domains.

My reservation with Cloudflare is the concept of letting a third party MitM my SSL traffic. That and it's more expensive than a cheapo CDN like Stackpath if all you really care about is CDN (and Cloudflare isn't even really a good CDN, just a quick hack to speed up small static files).

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#69
post #36
post #2

Interesting perspective, but it seems like this is just an ad for easyDNS and their "Proactive Nameservers," though I couldn't imagine a better time than the misstep of a behemoth of a competitor in this space. Not to detract from the more important discussion about the internet's dependence on Cloudflare overall.

It may be just an ad for easyDNS' Proactive Nameservers [1] product but it provides a roadmap for one possible solution to this type of problem. From a quick reading of the marketing info, the solution can be summarized as "Provision, Monitor, and Fail-Over DNS Name Servers across multiple DNS-as-a-Service providers". The question I have is whether the following constraint is artificially introduced or not: > We must…

They want to be the registrar to be able to update your NS records. But ... that's not really important nor needed (So the answer to your question yes, it's likely artificial). Just use two anycast-ed IPs/domains. (Like Cloudflare.)

The magic happens at BGP level.

I considered CF as a domain registrar, but they don't allow setting the NS records. So you must use them. (They basically use sane no-nonsense domain registration as a way to gain leads for their main product. Pretty smart actually, because it's a great high-level add-on for their main product, but they just went ahead and made that the bait for everyone.)

Anyway, ideally, if you add 2 separate sets of NS servers to your NS records then you eliminated this SPoF, great. Sure, it's your job to keep them updated, and in sync (preferably, to avoid problems like half of your users landing on a different CNAME/IP/etc).

And recursive nameservers will handle the failover.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#70

Honest question: I've never really understood the back of the napkin math of how Cloudflare functions economically, which I feel would go a long way towards my understanding of why/how they were able to become such an integral and generally positive part of the Internet. Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw…

As far as I understand it it's a freemium B2B model: If you're small you probably can get away using the free tier. Then when you get bigger you outgrow the free plan, either because you want specific features or because your bandwidth becomes too high.

That said bandwidth really isn't that expensive, at least if you're buying it at the scale that Cloudflare does. Many people seem to be used to the bandwidth prices of the large cloud hosters, which are really insane and have been marked up by a large multiplier to disincentivize people to transfer their data elsewhere for processing.

Post reply on HN