Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

341–350 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#341

That is the problem with massive centralization even if it is market level and internally Cloudflare (or any other big fish) does decentralization/fail-over of their own. Many of these companies should have had fail-over to competitors at least for reliability. The problem with near market monopolization, oligopoly, even the singularity, the fail-case is catastrophic and may even wipe out decentralized, diffused, dis…

There is no CDN monopoly. There are several to choose from. Cloudflare is one of the new kids on the block. There is no cloud monopoly either. Customers can choose from AWS, GCP, Azure, and several others. The problem is not market concentration. There are plenty of options. The problem is customers choosing to put all their eggs in one basket.

Cloudflare has done really well in a short amount of time, but I'm sure Akamai is way bigger. Cloudflare is best known because they offer free/cheap tools for individuals and this post is targeted at developers. Most big enterprises I've worked with are on Akamai.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#343
When I was figuring out how DNS works back 10 years ago, I was told "Why don't you just use 8.8.8.8 everywhere? Why do you need your own DNS server for anyway?" every single time when I asked a very specific configuration question. Some years later 8.8.8.8 was just replaced with 1.1.1.1 with same critical counter questions instead of helping. So, it appears to me, instead of understanding DNS and routing, people and tech-bro businesses take shortcuts by using centralized infrastructure for their systems, creating dangerous configurations. Now, Cloudflare have made a mistake, and half the Internet crumbled down. See the irony?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#344
post #285

Earlier quoted context omitted.

Why not?

When you move fast you tend to break things. When half the internet relies on you you want to avoid outages.

They seem to move pretty fast when things are broken for non blind people.

Are you saying it's ok to discriminate?

I know there are varying degrees at play here, all I'm trying to do is point out your priorities are fucked.

CloudFlare is working on something right now, why not this?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#345
post #303

Earlier quoted context omitted.

In the other direction, Google thinks I'm a bot if I use complex search queries (exclusions, site:, quotes, etc.) in an attempt to find what I'm looking for. Apparently it thinks I'm too intelligent to be a human.

You’re not profitable enough. You’re insisting on finding the thing you want, instead of settling for what Google is pushing today.

I get that you meant that sardonically but it's worth pointing out that it would be even more unprofitable implementing ways to catch and redirect you.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#346

Earlier quoted context omitted.

No. The ramp needs to be built when the thing is built. Accessibility is not an afterthought.

I mean, yes, in an ideal world that's true. Yet, here we are. It's not possible for a dev to go back in time to before hcaptcha was created or when CF decided to switch to them to create said ramp, so until it's built, workarounds are the only real thing a community member can offer someone in the short term.

It's not like trying to find the Fountain of Youth or something. It's a company with billions of dollars making it impossible for certain people with disabilities to access the Internet. Let's not pretend that it just has to be this way. A world where half the Internet can't be broken by one company should be the baseline.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#347
post #78

Earlier quoted context omitted.

II love cloudflare. It has really helped out with several sites/projects that I have worked on and the service is top notch. I am also an investor. I tend to invest in stuff which I use a lot or trust/respect the employees. Weirdly what made me really invest is the level of geekiness on the company. I remember seeing you guys using a lava lamp wall to generate entropy and just thought "that's awesome". I just wanted…

It's a bit of a sad story, but maybe you'll like this read about one of the guys who laid the foundation for their tech and his sad decline: https://www.wired.com/story/lee-holloway-devastating-decline... I really liked the stories of his skill when he was in his prime. Very inspiring.

Never heard of him but I read this article in one sitting (extremely hard thing for me) and I felt some unexplained connections with this story. A Beautiful Mind is another book which I very often go back to and go through similar emotions.

In all, it was a captivating read.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#348
post #321

Earlier quoted context omitted.

Shouldn't that liability be with the operators of websites that use those captchas if they're required to be blind-accessible? If they get sued, it'll apply pressure up the supply chain.

I used to feel and think this way. But recent events, and the trajectory of the internet over the last decade has changed my mind completely. We must stop giving excuses to the massive centralization, to the enormous companies that step in and rent-seek what is supposed to be a distributed system. The most powerful tool we could have to get a proper internet back is the simple concept of accountability. If I was a ba…

This does not really make sense, it would be perfectly fine if two products existed, a cheap inaccessible captcha and a more expensive perfectly accessible one with companies offering both of them to users.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#349
post #321

Earlier quoted context omitted.

I used to feel and think this way. But recent events, and the trajectory of the internet over the last decade has changed my mind completely. We must stop giving excuses to the massive centralization, to the enormous companies that step in and rent-seek what is supposed to be a distributed system. The most powerful tool we could have to get a proper internet back is the simple concept of accountability. If I was a ba…

If we want to regulate the captcha industry there should be a law passed specifically regulating the industry. Blindsiding the industry with judgments against them when there are no laws about it will decrease confidence in the rule of law, which will hurt the economy as businesses lose confidence in their ability to predict the future.

Rules and laws are good tools and, I understand how law works in the most superficial way but, I fail to understand normalization of ignorance of some required features with the "nobody forced us to do this, so we just didn't care".

As human beings first and programmers later, we should understand that people with disabilities exist and assistive technologies need attention.

Why, as decent human beings, don't we do something nice without the push of laws, for once?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#350

Earlier quoted context omitted.

Hi! I work at hCaptcha (we handle the CF captchas), and to respond specifically: audio is inaccessible for those with visual and auditory processing issues, as well as being broken by ML techniques. Not to project, but we suspect this is why Google turns it off if your browser looks at all suspicious. Another user mentioned the Privacy Pass solution: https://news.ycombinator.com/item?id=23902870 While Privacy Pass is…

Audio captchas are considered broken completely (search for various papers over the past decade, including one from CMU), so it has limited usefulness only in a very narrow context in practice. I suspect this is a harbinger of things to come - as we close the gap on passing the Turing test, captchas are likely to get less effective, and we will need to transition to a very different solution for bot detection.

or, just let the bots be.

often it's easier to just use a website as api instead of using some broken xml nightmare that requires knowledge of the database tables.

If the concern is rate limiting then just rate limit the website. And if you don't like people operating websites with bots then I don't know, maybe stop making websites.

Post reply on HN