Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

81–90 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#81

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Agreed. I plan to continue using Cloudflare for everything because it's a phenomenal service at a great price.

Re: Do not put your site behind Cloudflare if you don't need to

#82
post #46

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

For our SaaS, the uptime probably isn't much different but the cost definitely is. If any of your stack has usage based billing, things can get very expensive quickly.

Re: Do not put your site behind Cloudflare if you don't need to

#83

Earlier quoted context omitted.

What's the actual cost to me of my blog being offline for a few hours? Basically nothing. Certainly less than the couple of bucks someone might spend on a DDoS service

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

What’s the cost of making the internet more centralised because of sheer laziness?

Re: Do not put your site behind Cloudflare if you don't need to

#84

Earlier quoted context omitted.

> total mass of sites where you consider most being better off using cloudflare? Most. A lot of simple sites are hosted at providers that will be taken down themselves by run-of-the-mill DDOS attacks. So, what will such providers do when confronted with that scenario? Nuke your simple site (and most likely the associated DNS hosting and email) from orbit. Recovering from that will take several days, if not weeks, if…

I was hoping you could share some of the factual evidence you apparently possess to make such bold claims, alas it seems my hopes will go unfulfilled. Have a good rest of the day!

Hey, s1mplicissimus, hope you are well!

Dud(ett)e, it's a message board comment, not a scientific study.

But do you really doubt that most ISPs will gladly disable your 1Gb/s home-slash-SMB connection for the rest of the month in face of an incoming 1Tb/s DDOS? Sure, they'll refund your €29,95, but... that's about it, and you should probably be happy they don't disconnect you permanently?

Re: Do not put your site behind Cloudflare if you don't need to

#85

?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.

But your site will be down for 3 hours once every 3 years!!1

Re: Do not put your site behind Cloudflare if you don't need to

#86

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Yes, to rephrase: you dont need ddos protection if you dont get ddos'd (just dont get attacked lol). Well no shit, thanks for the advice.

As you say, the risk is not a temp outage for small users, the risk is your isp or host or whatever disowning you.

Re: Do not put your site behind Cloudflare if you don't need to

#87
Counterpoint, my personal project sites aren't that important, but are self-hosted. My blog being inaccessible for for half a day is preferable, to having to figure out my own protections, and why not just use their free CDN while I'm at it.

Do i need to? Definitely not. Am i going to stop using cloudflare? Also no.

When it comes to bigger sites, i think having someone to blame for an outage (especially when these big ones are effectively "the whole Internet broke") is still probably preferable to managing it all yourself.

Re: Do not put your site behind Cloudflare if you don't need to

#88

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Meanwhile the maintainer of Bear Blog - very nearly the poster child for small blogs with 100 visitors per month - recently put up a post talking about how much extra infrastructure it takes to keep the service online in the face of the massive uptick in AI scraper bot traffic we've had over the past few years.

I haven't tried managing my own site in ages, but I get the impression that the modern Internet is pretty much just one big constant DDoS attack, punctuated by the occasional uptick in load when someone decides to do it on purpose instead of out of garden variety apathetic psychopathy.

Re: Do not put your site behind Cloudflare if you don't need to

#89
I don't use even close to all the services they offer, mostly just DNS and some web workers but the convenience of it as opposed to rolling my own is, excluding down time, an incredible free offering.

Way back years ago when I used to roll my own, any problems I had to fix took extremely long and painful. Could I do it again today ? Yeah sure, but I know I couldn't do a better job than Cloudflare.

Re: Do not put your site behind Cloudflare if you don't need to

#90

?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.

I get these arguments and I see the appeal. But should this be the primary reason to use them, this way the web is being massively centralized. Everything running through them doesn't seem that smart to me.

But of course I understand that for most users this isn't really a concern and the benefits that cf provides are much more important rather then the centralization problem.

Post reply on HN