Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

141–150 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#141

Earlier quoted context omitted.

What's the actual cost to me of my blog being offline for a few hours? Basically nothing. Certainly less than the couple of bucks someone might spend on a DDoS service

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

Remember if it costs nothing, you’re the product.

Re: Do not put your site behind Cloudflare if you don't need to

#143

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Your host, assuming you're hosting your site on a VPS. Many of them have a policy of terminating clients who get DDoSed.

and if you're hosting on your home network, a DDoS means connectivity problems for your home.

Not just your home, it means connectivity problems for your neighbors. In turn your ISP will shut you down if they figure out what is happening.

Re: Do not put your site behind Cloudflare if you don't need to

#144
These threads always make me think what percentage of the commenters are commenting due to FUD, and how many are shilling. "My home ip address might leak", "hacker armies will attack me", "only cloud flare with its billion dollar engineers can protect you on the internet", "if the attacker gets your server ip it's GAME OVER", "rampant run of the mill ddos attacks that will make your provider NUKE YOU FROM ORBIT".

Meanwhile CF is closing in on monopolizing the internet.

Re: Do not put your site behind Cloudflare if you don't need to

#145
post #6

I don't consider Cloudflare part of the "real" internet anymore, instead it's a private intranet that got too big.

This is my worry. What is cloudflare exactly? What regulations are they under? Am I and my privacy protected? How much of my privacy do I need to give up for whats essentially part of a protection racket, be it intentional or not. What happens when I use their SSL, can they sniff my packets? What intelligence and law enforcement do they work with? As someone with vulnerable and targeted identities its a lot harder to…

Cloudflair is what happens when a platonic idea of the internet clashes with market realities. All the questions posed are very important but most websites are run by businesses with motives about as pure as Cloudflair’s.

As for people… A programming club I attended is filled with people who run homelabs, use Linux and generally dislike anything corporate. The project to switch communication of discord is now more than a year old. I do feel sometimes that resistance against corporate internet is futile.

Re: Do not put your site behind Cloudflare if you don't need to

#146

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

>a valid security strategy Here's your confusion: personal sites don't need a valid security strategy. They don't need nine nines uptime. They don't need CDN, and ability to deploy, etc, etc. That's all (and forgive the origins of the expression but it is the most accurate description) cargo culting. There's no issue if they're down for a couple days. Laugh it off. Whereas if you put your site behind a defaults of a…

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#147
post #46

Earlier quoted context omitted.

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

You keep saying stuff like "the fallout" and "the repercussions" but then the only example you can provide is talking to customer service to bring your stuff back online. Is that it? Honestly speaking, not being sarcastic at all.

Re: Do not put your site behind Cloudflare if you don't need to

#148
Lets solve the problem. Why should some IP address be on the internet when it is being used for malicious activity. Everyone seems to assume there is no fix for this. Really?

The discussion is here is sort of which way do you want to let DDos sites damage you? By signing up for Cloudflare or not signing up for Cloudflare. In both case normal users suffer harm.

Why? This is a serious question.

Re: Do not put your site behind Cloudflare if you don't need to

#149
post #97

Earlier quoted context omitted.

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

This strategy requires you to be "on-call" for personal stuff. Honestly, I don't want to spend more time on pet projects than I already do. Or cutting some of it away on support instead of spending more on things I would actually be interested in. And resulting downtime might be even bigger than that with cloudflare.

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#150
post #3

If we're talking about putting static assets (like basic websites) on their CDN, or moving your backend to Workers, (etc...) you are by definition moving _away_ from single point-of-failure. > Maybe that's the core of this message. Face your fears. Put your service on the internet. Maybe it goes down, but at least not by yet another Cloudflare outage. Well I'd rather have my website going down (along with half the in…

That's a bit like the 'nobody was fired for choosing Oracle' argument, but it does make sense. Still a bit weird to pretend we now have cyber weather that takes our webpages down.

Definitely has similarities. I think we do not realize how most top websites and services rarely go down anymore, and we use them 100 times more than we did 20 years ago. Building your own networking, compute, storage, CDN, or database solutions to avoid dependencies on AWS or Cloudflare would almost certainly lead to more service downtime than relying on highly sophisticated third parties.

But now, when one of these services breaks, everything on the internet goes down. And it is a lot easier to explain to your director of engineering that the whole internet is down than to say that your custom home-rolled storage system fell over, or whatever esoteric infrastructure failure you may run into doing it yourself.

Post reply on HN