Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

251–260 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#251

Earlier quoted context omitted.

Cloudflare is a relatively cheap "lite CDN" for developers who want caching without putting in any work. This becomes a gateway drug for Cloudflare's more expensive plans once you outgrow the free plan. It quickly adds up; I worked for a company that wasn't even on an enterprise plan and was spending hundreds of dollars a month on Cloudflare just because they had a lot of domains. My reservation with Cloudflare is th…

Unless you're sending all your traffic back to physical machines that you own locked into a cage in a datacenter, you are probably letting someone MITM your SSL traffic. For example if you are hosting on AWS, Amazon has access to your keys. If you are hosting on a hardware server leased from Hetzner, Hetzner has access to your keys. When a 3rd party has access to your keys, their responsibilities to you are spelled o…

There’s a difference between a VM host with the technical ability to carry out a targeted MITM attack against its customers using hardware-level access, and a provider that sells MITM as a service.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#252

Cloudflare is horrible for blind people. Screen readers, the programs that use synthesized speech to tell us what's on the screen, cannot read images. Good captchas usually have audio equivalents (which come with their own set of problems), but this one doesn't. If you're blind and flagged by Cloudflare for some reason, you're cut off from accessing half the internet, potentially critical banking/governmental/medical…

[deleted]

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#253
post #2

Interesting perspective, but it seems like this is just an ad for easyDNS and their "Proactive Nameservers," though I couldn't imagine a better time than the misstep of a behemoth of a competitor in this space. Not to detract from the more important discussion about the internet's dependence on Cloudflare overall.

> Proactive Nameservers is a patent-pending system that optimizes the nameserver delegation for your mission critical domain names.

That's a huge negative and I can't believe they think it's a good marketing point. I don't want a patent encumbered, non-standard solution for critical infrastructure.

> We must be your domain registrar for this to work.

So they're updating the domain record at the registry level to facilitate failover? That's the only scenario I can think of where they _need_ to be your registrar. Assuming that's the case...

I've always seen 24-48 hours quoted as the worst case wait when updating nameservers at the registry. I've never seen an explanation of how it works, what's allowed to be cached, how long it actually takes to update, etc.. How do they do it in a way that's suitable for failover? Do they have a special SLA with registries?

How would the registries handle a deluge of nameserver updates? Imagine a Cloudflare scale failure and corresponding registry updates. Would the registry servers be able to handle it?

I'd love to see a technical explanation of how their proactive nameservers system works.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#254

Didn't people also say the same thing about AWS a while back when that had a downtime? I guess the internet has multiple "Single-Point-Of-Failure"s.

it's a series of single points of failure on different levels, so, not multiple points of faiure, but much worse, single point after single point, which means the house of cards fails as often as any of them. The internet of 2020 is a monolith

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#255
post #72

Earlier quoted context omitted.

Read our S-1, it's all in there. https://www.sec.gov/Archives/edgar/data/1477333/000119312519...

Off topic, but any regrets on getting involved in content policing? It always sat with me as wrong and a disturbing precedent that an internet backbone service such as yourselves would make it their business to shut down unsavory yet legal speech.

Why is it a precedent? Nobody was under the illusion that it isn't technically possible for them to shut down some customer they don't like.

Nor was/is there any debate about the legality of doing so,

So the only reason for continuing to work for/with violent anti-semites was that they wanted to. Until, at some point, they changed their mind.

HN has a strange infatuation with this idea of avoiding responsibility by pretending to be powerless. But it's neither morally sound nor logically or legally coherent to pretend to be bound by some principles that are entirely of one's own making.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#256
post #249
post #179

Earlier quoted context omitted.

Yes but you don't have to sell your service to Nazi's....roads are a official service provided by the government/people's taxes, CF is not.

This misses the point to an impressive degree. No one here is disputing the current legality and I think everyone here understands the difference between government and private services. The argument is that we've come to depend on privately owned backbone infrastructure in much the same way we depend on publicly owned roads. Furthermore, the operators of that infrastructure have shown themselves to be vulnerable to…

>we've come to depend on privately owned backbone

No, you can use any other service you want. CF has no private toll roads, in fact you can make your own 'toll' road right know. But if you have your private toll road you can forbid any bumper sticker you don't want on YOUR road.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#257
post #110

Earlier quoted context omitted.

easyDNS has to be the registrar because only your registrar can change your nameserver delegation with the registry. This is, in essence, the registrar's job. To maintain your domain record and info, including nameserver delegation, with the registry. You could do it with BGP, but it is non-trivial and you need your own ASN to do that.

But you can just add multiple DNS providers yourself. I mean you can add the namservers of both easyDNS and cloudflare. EasyDNS just automates this. In theory they could simply create a few subsidiaries, let's call them saferDNS1,2,3 and have them build completely different redundant DNS architectures, and add then add the resulting nameservers. That said, it'd be good to see an actual domain that uses this "proactiv…

I'm not a DNS expert, so... It's not really that simple is it? If you have multiple nameservers I thought they get equal weight, don't they?

So if you have Cloudflare + (ex:) NS1, and you're using Cloudflare for caching, you need your NS1 records to return Cloudflare proxied IPs normally, but origin IPs under failure conditions. That's a lot of infrastructure.

It also fails completely if you're relying on Cloudflare for DDoS protection and IP obfuscation because a failure means your origin IPs get exposed. That's assuming Cloudflare DNS being down means Cloudflare proxying is down too. It might not be the case, but I think you'd have to plan for it.

Then there's also Cloudflare's detection of nameservers. I haven't tried it with more than Cloudflare's nameservers set for a domain, but if your domain doesn't actively use their nameserver they'll drop your site from their system. So, at the very least, you can't use Cloudflare as a secondary DNS provider (at least the last time I checked).

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#258
post #78

Earlier quoted context omitted.

II love cloudflare. It has really helped out with several sites/projects that I have worked on and the service is top notch. I am also an investor. I tend to invest in stuff which I use a lot or trust/respect the employees. Weirdly what made me really invest is the level of geekiness on the company. I remember seeing you guys using a lava lamp wall to generate entropy and just thought "that's awesome". I just wanted…

I work at hCaptcha, we run CF's captcha. If you're having problems in the future, popping open a debugger and capturing the results can help us figure out what's going on. But also: browser, OS, site, ...? Right now: there is an issue with Safari users on the most recent iOS and OS X, where 3rd party cookies have now been disabled by default. We're working on a solution. If that's your issue, you can fix on your side…

I'd love to see your reply to the blind person commenting on your product here.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#259
“Cloudflare apparently fat-fingered a routing update and sent all of their global traffic to a single POP, vaporizing it almost instantly.”

Made me chuckle, as it gave me the image of a large server in some massive server farm glowing red, then bursting in a massive burst of light as dozens of bearded Sysadmins run out of the building screaming.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#260
> But if you want to use a preferred DNS provider, such as Cloudflare, who use their DNS responses to optimize your website proxy. That works best most of the time, so then you want to go with an active/passive model that will step back when things are going according to plan, and then when these periodic network cataclysms do occur (and they will), they step into the breach and update your nameservers so that you at least stay up until the crisis is over.

Copy editors are cheap and your reputation shouldn't be.

Post reply on HN