Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

111–120 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#111

Earlier quoted context omitted.

I was hoping you could share some of the factual evidence you apparently possess to make such bold claims, alas it seems my hopes will go unfulfilled. Have a good rest of the day!

Hey, s1mplicissimus, hope you are well! Dud(ett)e, it's a message board comment, not a scientific study. But do you really doubt that most ISPs will gladly disable your 1Gb/s home-slash-SMB connection for the rest of the month in face of an incoming 1Tb/s DDOS? Sure, they'll refund your €29,95, but... that's about it, and you should probably be happy they don't disconnect you permanently?

It comes down to politics, if I'm hosting a weird porn website, I'm sure my host would drop me. But since I have a run of the mill SaaS website or a landing page for a business hosted. I'm sure my host would see no point in dropping my service, if I get DDosed, my neighbours got ddosed as well similarly I'm sure. Maybe they charge me extra or rate limit the connection, idk.

In fact, I expect my host to kick weird porn websites from their servers so that I don't have any bad neighbours, we're running legitimate businesses here sir.

Maybe they'd push me into upgrading my server, as a sort of way of charging me for the increased resources, which is fine. If I'm coasting on a 7$ VPS and my host tanks a DDoS like a hero, sure, let's set up a 50-100$ dedicated server man.

In business loyalty pays and it goes both ways.

I have more than 1 hosting provider though, so I can reroute if needed, and even choose not to reroute to avoid infecting other services, isolating the ddosed asset.

Re: Do not put your site behind Cloudflare if you don't need to

#112
I use Cloudflare tunnels to expose lots of small projects to the internet that I host on my home server. I don't want my home internet to be knocked offline because someone decides to hammer my network and knock me offline for a while.

Cloudflare handles caching of static resources, rate limiting, and blocking of bots with very little configuration.

Also, my ISP here in the UK doesn't provide static IP addresses, so Cloudflare allows me to avoid using a dynamic DNS service, and avoid exposing ports on my router.

Re: Do not put your site behind Cloudflare if you don't need to

#113
post #97

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

That’s like saying you should buy car insurance after you wreck your car

Re: Do not put your site behind Cloudflare if you don't need to

#115
post #97

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

This strategy requires you to be "on-call" for personal stuff. Honestly, I don't want to spend more time on pet projects than I already do. Or cutting some of it away on support instead of spending more on things I would actually be interested in.

And resulting downtime might be even bigger than that with cloudflare.

Re: Do not put your site behind Cloudflare if you don't need to

#116

Fun fact: a whole bunch of local (as opposed to global: the distinction here is important) Cloudflare-related outages were caused by exactly this thinking: see https://blog.cloudflare.com/going-bgp-zombie-hunting/ and related HN discussion at https://news.ycombinator.com/item?id=45775051 But yeah, if you don't need Cloudflare, like, at all , obviously don't use them. But, who can predict whether they're going to be D…

Stop encouraging centralization and non-private web. Cloudflare's famous mitm also puts everyone's data under their watch. Remember how cloudflare leaked secrets in 2017 on every major search engine?

Re: Do not put your site behind Cloudflare if you don't need to

#117
post #56

Earlier quoted context omitted.

What's the actual cost to me of my blog being offline for a few hours? Basically nothing. Certainly less than the couple of bucks someone might spend on a DDoS service

Cloudflare (basic option which does have DDoS protection) is free.

free spying, nice!

Re: Do not put your site behind Cloudflare if you don't need to

#118

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

You think someone would DDoS you because you made a comment like this on HN? Seems a bit overly cautious.

Re: Do not put your site behind Cloudflare if you don't need to

#119

Earlier quoted context omitted.

Hey, s1mplicissimus, hope you are well! Dud(ett)e, it's a message board comment, not a scientific study. But do you really doubt that most ISPs will gladly disable your 1Gb/s home-slash-SMB connection for the rest of the month in face of an incoming 1Tb/s DDOS? Sure, they'll refund your €29,95, but... that's about it, and you should probably be happy they don't disconnect you permanently?

Hi ZeroConcerns, I'm doing fine, thanks, hope you too! There's no but... - just claims you made that I dared to question just for fundamentals, which obviously you want to dodge. I won't go as far as questioning your intellectual honesty here, but I really have a hard time seeing it. So now for reals, good day

OK, I admit, I'm intellectually entirely dishonest. You have a great life!

Re: Do not put your site behind Cloudflare if you don't need to

#120
post #37

I get constantly attacked. Usually it's big actors like Facebook, Azure and OpenAI who bombard my servers without any respect or logic. I need to update my access rules constantly to keep them away (using Cloudflare) Sometimes it's clustered traffic, more classic DDoS, from China, Russia or America. That I could easily filter with the DDos protection from my hosting (which is cheaper than cloudflare anyway) What shou…

OpenAI bots are relentless. I used to see some random requests every time I requested LE cert for making a service public but now, it's always "gptbot"
Post reply on HN