Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

281–290 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#281
post #78

Earlier quoted context omitted.

II love cloudflare. It has really helped out with several sites/projects that I have worked on and the service is top notch. I am also an investor. I tend to invest in stuff which I use a lot or trust/respect the employees. Weirdly what made me really invest is the level of geekiness on the company. I remember seeing you guys using a lava lamp wall to generate entropy and just thought "that's awesome". I just wanted…

> I remember seeing you guys using a lava lamp wall to generate entropy and just thought "that's awesome". To be sure (and for the sake of internet rando completenessism), it does look like CF waited until the original SGI patent on the technique ran out. :) https://patents.google.com/patent/US5732138

> To be sure (and for the sake of internet rando completenessism), it does look like CF waited until the original SGI patent on the technique ran out. :)

That's right. See https://news.ycombinator.com/item?id=23860658

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#282
This is the 3rd DNS related outage I've seen in a week. Frountier Communications lost their DNS. Trying to recall what the 3rd one was.

My Unbound resolver round-robins DNS-over-TLS requests, between Cloudflare & Quad9. Cloudflare's outage never impacted us that I could tell.

Nevertheless, I am reminded that I ought to add a couple of DoT providers (who aren't Google). Not sure who else came online since I setup.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#283
post #245

Earlier quoted context omitted.

This is a bad analogy. Cloudflare is not inspecting individual packets for hate speech. They are refusing to do business with an organization that negatively affects their brand (The Daily Stormer). They should have the right to make that choice as a private entity. Funny you bring up Fedex: https://www.cnn.com/2020/07/02/business/fedex-washington-red...

"They should have the right to make that choice as a private entity." No they should not. And the analogy works: if you're getting filtered on the basis of your content - at the packet level or not - then it's fundamentally against Net Neutrality. Wait until the PR team at Verizon decides they don't want to publish your content because you're too vocal about BLM. Or, they will only support you if you do support BLM,…

> There is no end to the insanity otherwise; we need basic, smart and clear regulation.

I would argue that people should agree on what the right solution is before we enshrine it in law.

Also, when you think of the US Congress, do you think of "basic, smart and clear" regulations?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#284
post #272
post #268

Earlier quoted context omitted.

Thank you for sharing your experience. Cloudflare switched to using hCaptcha a couple months ago, I think and I only just noticed that they do not offer an audio-based captcha. However, hCaptcha integrates with Privacy Pass[0], and you can top up your tokens by solving a captcha at [1] and [2]. What you could do (and I realize this is far from ideal), is getting a sighted friend to solve a couple of captchas so you h…

This is such an out of touch dev response. The problem is hcaptcha, the solution is stop using hcaptcha. Not placate and evade with work arounds you wouldn't even suggest to non blind people. Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp. You don't get to take over half the internet and just ignore social responsib…

> Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp.

I agree, and I could’ve been clearer. The Privacy Pass workaround shouldn’t be necessary and we should demand Cloudflare do better.

(To avoid any doubt: I’m not affiliated with Cloudflare in any way, other than that I’m a customer on their free plan.)

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#285
post #272

Earlier quoted context omitted.

This is such an out of touch dev response. The problem is hcaptcha, the solution is stop using hcaptcha. Not placate and evade with work arounds you wouldn't even suggest to non blind people. Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp. You don't get to take over half the internet and just ignore social responsib…

Solutions can’t be implemented instantly; a work around is needed until that ramp is installed. As much as the lack of audio solution sucks, you can’t expect half the internet to just give up on a piece of technology overnight

Why not?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#286
post #272

Earlier quoted context omitted.

This is such an out of touch dev response. The problem is hcaptcha, the solution is stop using hcaptcha. Not placate and evade with work arounds you wouldn't even suggest to non blind people. Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp. You don't get to take over half the internet and just ignore social responsib…

Solutions can’t be implemented instantly; a work around is needed until that ramp is installed. As much as the lack of audio solution sucks, you can’t expect half the internet to just give up on a piece of technology overnight

> you can’t expect half the internet to just give up on a piece of technology overnight

People call for this all the time when a major security vulnerability is discovered. The difference is in how the community views it.

Cloudflare should weigh harm of blocking access to the Deaf community warrant the harm of removing a captcha that doesn't support them. They should have done it when they chose a captcha that doesn't support the Deaf community.

As technology comes to mediate every avenue of life, we need to recognize that technology only has value in its positive effects on people's lives. A security vulnerability is bad because owners may lose control, property may be lost, crimes may be committed. Usability vulnerabilities can deny services essential to their users. You're totally correct that there is no magic solution, but to say that we know which imperfect solution is preferable is incorrect.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#287

Earlier quoted context omitted.

It's a bit of a sad story, but maybe you'll like this read about one of the guys who laid the foundation for their tech and his sad decline: https://www.wired.com/story/lee-holloway-devastating-decline... I really liked the stories of his skill when he was in his prime. Very inspiring.

Wow, thanks for linking to the article. What an awful story. Makes you think about the wisdom of undertaking major elective surgery if it's not absolutely required in the short term.

His wife saw it as a turning point, but the doctors and neurologists don’t seem to think FTD is linked to surgery in any way

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#288
post #267
post #256

Earlier quoted context omitted.

>we've come to depend on privately owned backbone No, you can use any other service you want. CF has no private toll roads, in fact you can make your own 'toll' road right know. But if you have your private toll road you can forbid any bumper sticker you don't want on YOUR road.

> if you have your private toll road you can forbid any bumper sticker you don't want on YOUR road If this existed in reality somewhere in the US (or wherever you happen to live) are you seriously saying that you would be ok with it?! Do you really not see the necessity of having neutral infrastructure? > CF has no private toll roads They are largely analogous. They transport your traffic from point A to point B for…

> There is not (to the best of my knowledge) a government operated CDN or network backbone which you could make use of in order to avoid such concerns.

The line between private and public gets a bit blurry when talking about edge routing and CDNs. Especially edge routing.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#289
post #236

Earlier quoted context omitted.

Why not? It's a single thing, that if it fails, causes your app/website/whatever to fail.

Because it isn't a single thing, it is a redundant system. Redundant systems can also fail, that doesn't make it a _single_ point of failure. You can add another system in parallel as the vendor of the product suggests, or you can improve the resilience in the redundant system. To make a hyperbole: my galera cluster is failing, its a single point of failure, so I setup a cockroach cluster in parallel. In a way, it is…

That is a fair point; SPoF depends on what level you're looking at. A RAID array removes the SPoF that is a single disk, but still leaves a SPoF in the RAID controller or CPU or power supply; a ceph cluster can withstand the loss of a whole rack but could still fall to certain software bugs. Likewise, "cloud" companies are internally redundant, right up to the point where they aren't. It depends on how you scope the question.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#290

Cloudflare is horrible for blind people. Screen readers, the programs that use synthesized speech to tell us what's on the screen, cannot read images. Good captchas usually have audio equivalents (which come with their own set of problems), but this one doesn't. If you're blind and flagged by Cloudflare for some reason, you're cut off from accessing half the internet, potentially critical banking/governmental/medical…

Seems like if this issue could easily be solved, a startup would have formed to solve it. Are there any alternatives to recaptcha and hcaptcha that are effective and also accessible?
Post reply on HN