Live data from Hacker News

Turns out half the internet has a single-point-of-failure called “Cloudflare”

easydns.com

401–410 of 414 posts

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#401
post #194

Earlier quoted context omitted.

The problem is customers choosing to put all their eggs in one basket. Until relatively recently absolutely none, and now almost none of the tooling allows effective multi-cloud or hybrid cloud/private. Basically the cloud providers work very hard to prevent the commodification of their services with special incompatible service offerings, lock-in, interdependency, deep and opaque APIs for integration, and networks o…

> Until relatively recently absolutely none, and now almost none of the tooling allows effective multi-cloud or hybrid cloud/private. Until relatively recently, the cloud didn't exist.

> Until relatively recently, the cloud didn't exist.

Depends:

> IBM and other mainframe providers conducted this kind of business in the following two decades [after 1961], often referred to as time-sharing, offering computing power and database storage to banks and other large organizations from their worldwide data centers. To facilitate this business model, mainframe operating systems evolved to include process control facilities, security, and user metering.

[…]

> In 1998, HP set up the Utility Computing Division in Mountain View, CA, assigning former Bell Labs computer scientists to begin work on a computing power plant, incorporating multiple utilities to form a software stack. Services such as "IP billing-on-tap" were marketed. HP introduced the Utility Data Center in 2001. Sun announced the Sun Cloud service to consumers in 2000.

[…]

> In spring 2006 3tera announced its AppLogic service and later that summer Amazon launched Amazon EC2 (Elastic Compute Cloud).

* https://en.wikipedia.org/wiki/Utility_computing

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#402
post #262

Earlier quoted context omitted.

> The reason why freedom of speech ... is important This view is (IMO) far too narrow. Freedom of expression, particularly political expression, is absolutely essential to the functioning of western society as it currently exists. Personally, I also see it as an ideal to be pursued in and of itself regardless of any functional need for it. Government regulation has a high potential for abuse for a number of reasons (…

You're missing the thread here. Suppose a guy walks into a grocery store with a shaved head and swastika tattoos. He wants to buy a bag of apples. The store owner doesn't like the cut of his jib and asks him to leave. That's fine, the guy goes to the grocery store across the street and buys the apples there. The store owner across the street doesn't care what kind of tattoos a man has and is willing to sell apples to…

I think you meant to reply to @ygjb?

But yep, this is pretty much my thinking as well - that being ruled by the whims of the mob is hardly desirable from a societal standpoint because it ultimately results in many of the same issues that government restrictions on expression do.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#403

Earlier quoted context omitted.

From the article: “ This question assumes the answer. A website is speech. It is not a bomb. There is no imminent danger it creates and no provider has an affirmative obligation to monitor and make determinations about the theoretically harmful nature of speech a site may contain.”

Are DDOS-for-hire sites "speech"? Their only use is to suppress speech.

Well that would depend on what the target of the DDOS is wouldn’t it? Either way the point being we want companies out of politics. They have no business in them.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#404

Earlier quoted context omitted.

This is a bad analogy. Cloudflare is not inspecting individual packets for hate speech. They are refusing to do business with an organization that negatively affects their brand (The Daily Stormer). They should have the right to make that choice as a private entity. Funny you bring up Fedex: https://www.cnn.com/2020/07/02/business/fedex-washington-red...

> They should have the right to make that choice as a private entity. The question isn't whether they should be allowed to do that, it's whether they should be forced to do that by other people.

Who forced cloudflare to do anything here?

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#405
post #293

Earlier quoted context omitted.

> Cloudflare was purely acting out of market based fear, there wasn't a hint of moral impetus. IIRC, the reason DailyStormer pissed off CloudFlare is because the users claimed (lied) about CloudFlare was somehow participating / sponsoring the site/activities. Sports teams have non-disparagement clauses; I don't see this as much different. The only thing I'm not clear about is if it was just a rando user on DS that sa…

> Common Carrier status is perhaps a closer comparison, but I think AT&T is allowed to drop a customer if they violate the AT&T ToS / contract. That would make net neutrality meaningless, surely. Just put something in the ToS that says you agree not to actually use your internet service. > Also, the CEO of CloudFlare went out of his way to publicize that this was a problem for the health of the internet and to start…

Cloudflare has a right to free speech too.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#406
post #240

Earlier quoted context omitted.

> There isn't always a line Yes there is. The line is Nazis now. There was a war, they lost. They're not welcome anymore.

Wait, so being a Nazi would be okay if they had won the war? Might makes right and censorship of political opponents was Nazi canon. I thought you were saying their ideology was defeated.

Well, they had their chance to show what they'd do while in power, and it was very very bad.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#407

Earlier quoted context omitted.

> They should have the right to make that choice as a private entity. The question isn't whether they should be allowed to do that, it's whether they should be forced to do that by other people.

Who forced cloudflare to do anything here?

Their cited reasoning for dropping them was outside pressure to not be associated with them.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#408
post #110

Earlier quoted context omitted.

But you can just add multiple DNS providers yourself. I mean you can add the namservers of both easyDNS and cloudflare. EasyDNS just automates this. In theory they could simply create a few subsidiaries, let's call them saferDNS1,2,3 and have them build completely different redundant DNS architectures, and add then add the resulting nameservers. That said, it'd be good to see an actual domain that uses this "proactiv…

I'm not a DNS expert, so... It's not really that simple is it? If you have multiple nameservers I thought they get equal weight, don't they? So if you have Cloudflare + (ex:) NS1, and you're using Cloudflare for caching, you need your NS1 records to return Cloudflare proxied IPs normally, but origin IPs under failure conditions. That's a lot of infrastructure. It also fails completely if you're relying on Cloudflare…

I was talking about just the DNS layer, but ... you can periodically check what IP Cloudflare would return and return that. (There's also the apex-CNAME record type, ALIAS or DNAME, I don't remember right now, but PowerDNS supports it, and you can set up the resolver to use CF's NS.)

Of course CF doesn't support anything like this, but it works well (because they use quasi fixed, static anycasted IPs for the HTTP(S and TCP?) proxying/load-balancing too), even if it's hacky as hell.

If they have any active verification of nameservers, and if they disable the proxies if they detect something bad, then ... it won't work obviously :)

But technically there's nothing amazing in being a registrar of a domain. So both CF and easyDNS are just stubborn in the name of user experience (consistency).

... all in all, working around any SPoF (reliably) will usually require exponentially more resources/engineering/care.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#409
post #293

Earlier quoted context omitted.

> Common Carrier status is perhaps a closer comparison, but I think AT&T is allowed to drop a customer if they violate the AT&T ToS / contract. That would make net neutrality meaningless, surely. Just put something in the ToS that says you agree not to actually use your internet service. > Also, the CEO of CloudFlare went out of his way to publicize that this was a problem for the health of the internet and to start…

Cloudflare has a right to free speech too.

When they're speaking for themselves? Sure. When they're acting as a common carrier? No. It's too bad regulation hasn't kept up with the realities of how important the Internet is.

Re: Turns out half the internet has a single-point-of-failure called “Cloudflare”

#410

Earlier quoted context omitted.

or, just let the bots be. often it's easier to just use a website as api instead of using some broken xml nightmare that requires knowledge of the database tables. If the concern is rate limiting then just rate limit the website. And if you don't like people operating websites with bots then I don't know, maybe stop making websites.

Easy proxying means rate limiting doesn’t really help all that much to defeat bots. And then if you do something like blocking or severely restricting something like Tor (the world's largest open proxy and hence, primary abusive traffic source; something which it would make sense to throw extra bot walls in front of), privacy and accessibility advocates jump down your throat. This is a no-win situation. I’m not convi…

We offer privacy pass so that we don't force our users into the false dichotomy above. For our users it's a win/win situation
Post reply on HN