Earlier quoted context omitted.
Cloudflare is a relatively cheap "lite CDN" for developers who want caching without putting in any work. This becomes a gateway drug for Cloudflare's more expensive plans once you outgrow the free plan. It quickly adds up; I worked for a company that wasn't even on an enterprise plan and was spending hundreds of dollars a month on Cloudflare just because they had a lot of domains. My reservation with Cloudflare is th…
Unless you're sending all your traffic back to physical machines that you own locked into a cage in a datacenter, you are probably letting someone MITM your SSL traffic. For example if you are hosting on AWS, Amazon has access to your keys. If you are hosting on a hardware server leased from Hetzner, Hetzner has access to your keys. When a 3rd party has access to your keys, their responsibilities to you are spelled o…
Turns out half the internet has a single-point-of-failure called “Cloudflare”
251–260 of 414 posts
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#252Cloudflare is horrible for blind people. Screen readers, the programs that use synthesized speech to tell us what's on the screen, cannot read images. Good captchas usually have audio equivalents (which come with their own set of problems), but this one doesn't. If you're blind and flagged by Cloudflare for some reason, you're cut off from accessing half the internet, potentially critical banking/governmental/medical…
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#253Interesting perspective, but it seems like this is just an ad for easyDNS and their "Proactive Nameservers," though I couldn't imagine a better time than the misstep of a behemoth of a competitor in this space. Not to detract from the more important discussion about the internet's dependence on Cloudflare overall.
That's a huge negative and I can't believe they think it's a good marketing point. I don't want a patent encumbered, non-standard solution for critical infrastructure.
> We must be your domain registrar for this to work.
So they're updating the domain record at the registry level to facilitate failover? That's the only scenario I can think of where they _need_ to be your registrar. Assuming that's the case...
I've always seen 24-48 hours quoted as the worst case wait when updating nameservers at the registry. I've never seen an explanation of how it works, what's allowed to be cached, how long it actually takes to update, etc.. How do they do it in a way that's suitable for failover? Do they have a special SLA with registries?
How would the registries handle a deluge of nameserver updates? Imagine a Cloudflare scale failure and corresponding registry updates. Would the registry servers be able to handle it?
I'd love to see a technical explanation of how their proactive nameservers system works.
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#254Didn't people also say the same thing about AWS a while back when that had a downtime? I guess the internet has multiple "Single-Point-Of-Failure"s.
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#255Earlier quoted context omitted.
Read our S-1, it's all in there. https://www.sec.gov/Archives/edgar/data/1477333/000119312519...
Off topic, but any regrets on getting involved in content policing? It always sat with me as wrong and a disturbing precedent that an internet backbone service such as yourselves would make it their business to shut down unsavory yet legal speech.
Nor was/is there any debate about the legality of doing so,
So the only reason for continuing to work for/with violent anti-semites was that they wanted to. Until, at some point, they changed their mind.
HN has a strange infatuation with this idea of avoiding responsibility by pretending to be powerless. But it's neither morally sound nor logically or legally coherent to pretend to be bound by some principles that are entirely of one's own making.
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#256Earlier quoted context omitted.
Yes but you don't have to sell your service to Nazi's....roads are a official service provided by the government/people's taxes, CF is not.
This misses the point to an impressive degree. No one here is disputing the current legality and I think everyone here understands the difference between government and private services. The argument is that we've come to depend on privately owned backbone infrastructure in much the same way we depend on publicly owned roads. Furthermore, the operators of that infrastructure have shown themselves to be vulnerable to…
No, you can use any other service you want. CF has no private toll roads, in fact you can make your own 'toll' road right know. But if you have your private toll road you can forbid any bumper sticker you don't want on YOUR road.
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#257Earlier quoted context omitted.
easyDNS has to be the registrar because only your registrar can change your nameserver delegation with the registry. This is, in essence, the registrar's job. To maintain your domain record and info, including nameserver delegation, with the registry. You could do it with BGP, but it is non-trivial and you need your own ASN to do that.
But you can just add multiple DNS providers yourself. I mean you can add the namservers of both easyDNS and cloudflare. EasyDNS just automates this. In theory they could simply create a few subsidiaries, let's call them saferDNS1,2,3 and have them build completely different redundant DNS architectures, and add then add the resulting nameservers. That said, it'd be good to see an actual domain that uses this "proactiv…
So if you have Cloudflare + (ex:) NS1, and you're using Cloudflare for caching, you need your NS1 records to return Cloudflare proxied IPs normally, but origin IPs under failure conditions. That's a lot of infrastructure.
It also fails completely if you're relying on Cloudflare for DDoS protection and IP obfuscation because a failure means your origin IPs get exposed. That's assuming Cloudflare DNS being down means Cloudflare proxying is down too. It might not be the case, but I think you'd have to plan for it.
Then there's also Cloudflare's detection of nameservers. I haven't tried it with more than Cloudflare's nameservers set for a domain, but if your domain doesn't actively use their nameserver they'll drop your site from their system. So, at the very least, you can't use Cloudflare as a secondary DNS provider (at least the last time I checked).
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#258Earlier quoted context omitted.
II love cloudflare. It has really helped out with several sites/projects that I have worked on and the service is top notch. I am also an investor. I tend to invest in stuff which I use a lot or trust/respect the employees. Weirdly what made me really invest is the level of geekiness on the company. I remember seeing you guys using a lava lamp wall to generate entropy and just thought "that's awesome". I just wanted…
I work at hCaptcha, we run CF's captcha. If you're having problems in the future, popping open a debugger and capturing the results can help us figure out what's going on. But also: browser, OS, site, ...? Right now: there is an issue with Safari users on the most recent iOS and OS X, where 3rd party cookies have now been disabled by default. We're working on a solution. If that's your issue, you can fix on your side…
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#259Made me chuckle, as it gave me the image of a large server in some massive server farm glowing red, then bursting in a massive burst of light as dozens of bearded Sysadmins run out of the building screaming.
Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”
#260Copy editors are cheap and your reputation shouldn't be.