> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
Do not put your site behind Cloudflare if you don't need to
81–90 of 391 posts
Re: Do not put your site behind Cloudflare if you don't need to
#82> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?
Re: Do not put your site behind Cloudflare if you don't need to
#83Earlier quoted context omitted.
What's the actual cost to me of my blog being offline for a few hours? Basically nothing. Certainly less than the couple of bucks someone might spend on a DDoS service
What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?
Re: Do not put your site behind Cloudflare if you don't need to
#84Earlier quoted context omitted.
> total mass of sites where you consider most being better off using cloudflare? Most. A lot of simple sites are hosted at providers that will be taken down themselves by run-of-the-mill DDOS attacks. So, what will such providers do when confronted with that scenario? Nuke your simple site (and most likely the associated DNS hosting and email) from orbit. Recovering from that will take several days, if not weeks, if…
I was hoping you could share some of the factual evidence you apparently possess to make such bold claims, alas it seems my hopes will go unfulfilled. Have a good rest of the day!
Dud(ett)e, it's a message board comment, not a scientific study.
But do you really doubt that most ISPs will gladly disable your 1Gb/s home-slash-SMB connection for the rest of the month in face of an incoming 1Tb/s DDOS? Sure, they'll refund your €29,95, but... that's about it, and you should probably be happy they don't disconnect you permanently?
Re: Do not put your site behind Cloudflare if you don't need to
#85?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.
Re: Do not put your site behind Cloudflare if you don't need to
#86> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
As you say, the risk is not a temp outage for small users, the risk is your isp or host or whatever disowning you.
Re: Do not put your site behind Cloudflare if you don't need to
#87Do i need to? Definitely not. Am i going to stop using cloudflare? Also no.
When it comes to bigger sites, i think having someone to blame for an outage (especially when these big ones are effectively "the whole Internet broke") is still probably preferable to managing it all yourself.
Re: Do not put your site behind Cloudflare if you don't need to
#88> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
I haven't tried managing my own site in ages, but I get the impression that the modern Internet is pretty much just one big constant DDoS attack, punctuated by the occasional uptick in load when someone decides to do it on purpose instead of out of garden variety apathetic psychopathy.
Re: Do not put your site behind Cloudflare if you don't need to
#89Way back years ago when I used to roll my own, any problems I had to fix took extremely long and painful. Could I do it again today ? Yeah sure, but I know I couldn't do a better job than Cloudflare.
Re: Do not put your site behind Cloudflare if you don't need to
#90?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.
But of course I understand that for most users this isn't really a concern and the benefits that cf provides are much more important rather then the centralization problem.