Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

11–20 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#11
Fun fact: a whole bunch of local (as opposed to global: the distinction here is important) Cloudflare-related outages were caused by exactly this thinking: see https://blog.cloudflare.com/going-bgp-zombie-hunting/ and related HN discussion at https://news.ycombinator.com/item?id=45775051

But yeah, if you don't need Cloudflare, like, at all, obviously don't use them. But, who can predict whether they're going to be DDOS-ed in advance? Fact is, most sites are better off with Cloudflare than without.

Until something like this happens, of course, but even then the question of annual availability remains. I tried to ask Claude how to solve this conundrum, but it just told me to allow access to some .cloudflare.com site, so, ehhm, not sure...

Re: Do not put your site behind Cloudflare if you don't need to

#13
post #10

Cloudflare tunnels makes it dead simple these days. Like some others in the comments it seems; I'd rather Cloudflare fighting the war against hacker armies than me. Once our networks become compromised from opening our firewalls (possibly even not) our routers and IOT devices become unwillingly complicit in the army that's bringing the internet down.

Those aren't hacker armies, those are just windmills.

Re: Do not put your site behind Cloudflare if you don't need to

#14
post #8

The lesson I learned is it's OK to put your site with Cloudflare. It's not ok to put your DNS on a registrar who is also on Cloudflare. We got locked out because our registrar is also on Cloudlfare, and now I can't even switch DNS to get the site back up. Keep your domain name registrar, DNS service provider and application infrastructure provider separately.

Fair point but you also get exposed if the dns provider has an outage.

Self hosting will also bring its own set of problems and costs.

Re: Do not put your site behind Cloudflare if you don't need to

#15
post #5

I'm waiting for my first DDoS attack at which point I will hide behind Cloudflare. I have all the bits in place to make that a smooth transition but would hate every aspect of it.

Depending on who your ISP is, there may be things they can do to help.

Re: Do not put your site behind Cloudflare if you don't need to

#16
post #3

If we're talking about putting static assets (like basic websites) on their CDN, or moving your backend to Workers, (etc...) you are by definition moving _away_ from single point-of-failure. > Maybe that's the core of this message. Face your fears. Put your service on the internet. Maybe it goes down, but at least not by yet another Cloudflare outage. Well I'd rather have my website going down (along with half the in…

That's a bit like the 'nobody was fired for choosing Oracle' argument, but it does make sense.

Still a bit weird to pretend we now have cyber weather that takes our webpages down.

Re: Do not put your site behind Cloudflare if you don't need to

#17

> As they say in security, "no one will burn a zero day on you!". For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" The last I saw you can hire DDoS as a service for like $5 for a short DDoS, and many hosts will terminate clients who get DDoSed.

And many hosting platforms will fight with you the DDoS. I'd rather choose wisely my hosting company.

Re: Do not put your site behind Cloudflare if you don't need to

#19
> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!"

If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a service. Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. Speaking from experience. Very much the reason I'm posting this with a throwaway account. If your website receives DDoS, your hosts will take down your server. Nobody wants to be in this situation even if for a personal, small blog.

Re: Do not put your site behind Cloudflare if you don't need to

#20
Unless these sites are your personal pages, oftentimes these decisions to use cloudflare or not are made by the business and money and risk people, not by the operations and other technically-minded employees. They see every other site using cloudflare and ask why they aren't as well.

"No one was fired for buying IBM (or cloudflare)."

Fat chance arguing against the people holding the purse strings.

Post reply on HN