Live data from Hacker News

Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

news.ycombinator.com

181–190 of 199 posts

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#181
post #38

Update: Just received an email from CF. -------------- Hello, With regard to your inquiry, we have restored the domain names in your account to active status. Please allow for normal propagation. You will need to re-add mnf90.com to your account in order to manage it. Our apologies for any inconvenience this may have caused. Kind Regards, Cloudflare Trust & Safety ------------ Not much info lol, but guess its fixed n…

You keep framing this as "how do I make sure I don't get into this situation again," but with the attention this is getting (#6 on HN) and just how bad the issue is (both functionally and PR-wise)... Cloudflare should really do a public post-mortem here. It sounds like it's their fault.

How do we get them to post a follow-up or post-mortem? I get that it might be difficult to discuss a specific case involving a customer, but there’s something seriously wrong when they first refuse to share details and claim they will not be reconsidering the decision, only to later do exactly that after the case gets attention. That’s an inexcusable procedural error that should be very worrying to any of their customers.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#182
post #82

Earlier quoted context omitted.

I have a cheap VPS, host my own email, host my own websites, never had any of the problems you are describing.

I too host my sites manually. What happens when your site that's hosted on the VPS gets noticed by a trigger happy skiddie? What happens when they start eating up all your bandwidth? Your VPS provider will be more than happy to null route you. For the websites you own, you registered your domain with someone right? What happens when that company decides to have some AI decide if you are doing something illegal? Until…

> Your VPS provider will be more than happy to null route you.

That is a lot better than deleting your domain and refusing to talk to you. If you need more bandwidth your VPS host will be more than happy to take your money. And short downtimes are not really much of a problem for personal websites and email. Losing your domain name is a much bigger concern.

> For the websites you own, you registered your domain with someone right? What happens when that company decides to have some AI decide if you are doing something illegal?

Has that EVER happened with any registrar that is not also handling other things like hosting or CDN for you? With just the domain all they could base their "AI" on would be the domain itself unless they go actively prodding third-party servers.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#184

Earlier quoted context omitted.

Gandi.net has always lived up to their (literally) no-bullshit reputation for me, and I've pretty much only heard good things about them as a registrar.

I used to have all my domains with Gandi.net One time, they had a billing issue with me. I disputed with my credit card company and got refund. So Gandi.net locked my entire account and none of the sites worked until I paid $10 they charged for disputing "their" billing issue. Only after paying $10 ransom, my account was restored. I promptly moved ALL the domains to porkbun. I also paid for 10 year renewal for my per…

> I also paid for 10 year renewal for my personal website, so someone from porkbun actually called me on the phone to confirm that it was not a mistake on my part and I truly intended to renew my personal website for 10 years.

That would annoy me - I should not have to bother with phone calls for something as sensible as making sure a domain I care about stays under my control for as long as possible. That is unless that was a vanity gTLD with particularly high renewal fees.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#185
post #113

Oh for F's sake.. I had moved my domains from Google to CF sometime ago, assuming my emails etc. are protected, and now this. Honest question: What is a good registrar? I used to use Namecheap in the past and have nothing against them. Unfortunately, unlike other things I cannot self-host a registrar. Thoughts? Suggestions? Edit: TBH, I find this wording rather rude "The suspension is permanent and we will not be mak…

> Unfortunately, unlike other things I cannot self-host a registrar Use .fi domains and you absolutely can. You really don't even need to code, run or host anything either unless you wanted to. Probably goes for some other lesser known ccTLDs too I'd assume.

Can you provide some details on what that process looks like? I assume you are actually talking about dealing with the registry directly and not just about self-hosting the nameservers the domain points to?

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#186

What services have contractual terms that prohibit them from taking arbitrary actions against their customers without prior notice? A list would be useful. For B2B use, you probably want to use only such services.

Even for B2C I'd assume.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#187
post #183

As a Cloudflare user this is quite scary and I'm not willing to put up with a shit show like this. What's a good alternative to CF? I mostly use CF because of their 'bonus' features like WAF.

The question is if you really need their WAF. After all that usually means that you are running insecure/outdated web applications or have SQL injections and while CF might filter some stuff if that's the case I wouldn't completely rely on that either.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#188
post #42

Earlier quoted context omitted.

That's really quite worrying. You'd have been screwed without HN, but not everyone has that recourse. How many other domains have been affected by "false positives" announced with a "we've banned you and we aren't telling you why; now fuck off" type email.

Very worrying. One of the reasons I'd choose a non-huge company like Cloudflare would be I'm less likely to encounter one of these "our automation banned you, we won't tell you why, fuck off" episodes. Looks like more and more companies are cargo-culting this horrible practice. Waiting for my utility company to turn off my heat: "Your house is fraud. We won't tell you how we know. Fuck off and freeze."

> one of these "our automation banned you, we won't tell you why, fuck off" episodes

More like "We can't tell you because it's AI and the (AI) won't tell us why it made that decision".

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#189
post #187
post #183

As a Cloudflare user this is quite scary and I'm not willing to put up with a shit show like this. What's a good alternative to CF? I mostly use CF because of their 'bonus' features like WAF.

The question is if you really need their WAF. After all that usually means that you are running insecure/outdated web applications or have SQL injections and while CF might filter some stuff if that's the case I wouldn't completely rely on that either.

I'm mostly running a few VPS servers to host websites. I'm not too concerned about security - i'm more interested in features such as protection from DDoS attacks which I've come to learn that are quite common nowadays.

Re: Ask HN: Has Cloudflare blocked your domain without explaining what's going on?

#190
post #54

Earlier quoted context omitted.

> More often than not it's not a mistake. So? A false positive rate of 50% is wholey unacceptable when banning people from critical online infrastructure. > Unfortunate, but the only way it's sustainable. This common talking point is just BS apologetics. There is a long history of ways to manage disputes without sending such useless explanations. These companies are just to cheap or lazy to bother.

> A false positive rate of 50% is wholey unacceptable when banning people from critical online infrastructure. Where'd you get that number? > There is a long history of ways to manage disputes without sending such useless explanations. Sure, the legal system.

> Where'd you get that number?

Your use of the phrase "more often than not" applies up to 50% and is thus meaningless given that such a false positive rate is unacceptable.

> Sure, the legal system.

It's pretty hard to file a legal claim without facts to contest...which is precisely the point.

Post reply on HN