Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

91–100 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#91

Earlier quoted context omitted.

Yuuuuup. We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue? He got it really quickly. I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you…

Is it removing cf as the middleman temporally such a big deal?

I think that really depends on feature usage. You can use Argo/Cloudflare tunnels to route to private backends that are normally unroutable. In such a setup, it might be quite difficult to remove Cloudflare since then you have no edge network and no ability to reach your servers without another proxy/tunnel product.

If you're using other features like page rules you may need to stand up additional infrastructure to handle things like URI rewrites.

If you're using CDN, your backend might not be powerful enough to serve static assets without Cloudflare.

If your using all of the above, you're work to temporarily disable becomes fairly complicated.

Re: Do not put your site behind Cloudflare if you don't need to

#92
post #80

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

> then your host taking your website down and then you having to run circles around their support staff to bring back the website up again These are very different situations. With a DDoS the disruption ends when the attack ends, and your site should become available without any intervention. Your host taking down your site is a whole different matter, you have to take action to have this fixed, waiting around won't…

> These are very different situations.

It is obvious those two are very different situations. I'm not sure I understand your point. Yeah, nobody will be bothered by a short 15 minute DDoS attack. I prolly wouldn't even notice it unless I'm actively checking the logs. Sure, nobody is going to be bothered by that. But what if someone's DDoSing persistently with a purpose? Maybe they're just pissed at you.

My point is... a sustained DDoS attack will just make your host drop you. So one situation directly leads to another and you are forced to deal with both situations, like it or not.

Re: Do not put your site behind Cloudflare if you don't need to

#93
I get your gripe, but the free protection that Cloudflare offers automatically often far exceeds the effort required to thwart some random script kiddie’s attacks on my client’s Wordpress site. Add easy caching, tunnels, automated certificate management, etc. to that and it’s obvious why a lot of sites use them.

Re: Do not put your site behind Cloudflare if you don't need to

#94
If you have a blog with 100 visitors per month why would you worry about being hit by an 4-8 hours outage once every year or two? I like Cloudflare because it is easy to setup and manage and because the amount of value you get for free or just a few bucks per month can’t be matched by any other company. Sure, if my income depends on my website/service uptime then I would probably consider other options. I think for most folks that’s not the case. Just chill and wait it out.

Re: Do not put your site behind Cloudflare if you don't need to

#95
We mainly use cloudflare due to the first class DNS experience. Free and super easy to work with.

Anyone have a suggestion for an alternative? I don’t want to pay per domain but I would pay an agency fee for like 100 domains for a few hundred bucks sorta think, like migadu offers for email.

Re: Do not put your site behind Cloudflare if you don't need to

#96
A couple of weeks ago my apprentice put a demo of ours behind cloudflare, I had him remove it. His explanation was interestingly "it hides our IP, if we remove it, they'll know our IP", yup, that's fine buddy, consider our IP to be a public piece of data.

And we all lived happily ever after.

Re: Do not put your site behind Cloudflare if you don't need to

#97
post #46

Earlier quoted context omitted.

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

Re: Do not put your site behind Cloudflare if you don't need to

#99

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

> Hopes and prayers do not make a valid security strategy.

True, but they are free and effortless, unlike "appropriate controls and defenses"

Re: Do not put your site behind Cloudflare if you don't need to

#100

Earlier quoted context omitted.

I was hoping you could share some of the factual evidence you apparently possess to make such bold claims, alas it seems my hopes will go unfulfilled. Have a good rest of the day!

Hey, s1mplicissimus, hope you are well! Dud(ett)e, it's a message board comment, not a scientific study. But do you really doubt that most ISPs will gladly disable your 1Gb/s home-slash-SMB connection for the rest of the month in face of an incoming 1Tb/s DDOS? Sure, they'll refund your €29,95, but... that's about it, and you should probably be happy they don't disconnect you permanently?

Hi ZeroConcerns, I'm doing fine, thanks, hope you too!

There's no but... - just claims you made that I dared to question just for fundamentals, which obviously you want to dodge. I won't go as far as questioning your intellectual honesty here, but I really have a hard time seeing it. So now for reals, good day

Post reply on HN