Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

171–180 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#171
post #118

Earlier quoted context omitted.

You think someone would DDoS you because you made a comment like this on HN? Seems a bit overly cautious.

Do providers offering VPS have a layer of protection against such attacks? It might overwhelm their routers etc too?

a little niche cuz they're primarily a game server provider but nuclearfallout is the most proactive provider i've seen to do this, on vps or dedicated hardware. there has been many times they've worked with upstream bw providers and automatically holed incoming ddos, noticed packet loss and abnormal routing etc, before even reaching end user interfaces-

been using them for decades and they've been incredible for this, at least for the US options (prem/internap)

Re: Do not put your site behind Cloudflare if you don't need to

#173
I put my personal website behind Cloudflare, and I recommend that you do too.

Why?

Pretty simple, really. My personal website, along with some other services, can run successfully from a $10/mo VPS on Digital Ocean because I can be assured that anything I post will have its traffic primarily absorbed by Cloudflare.

This lets me do things I want to do without having to consider the consequences or eating the direct cost myself, like having a gallery of my travel photography where I post nearly full-sized images that can be arbitrarily crawled. I have no concerns about my images being "stolen", because for the most part there'd be no reason to do so, but I'd have to stop doing that if I didn't have Cloudflare in front of my site because of AI crawlers and other things that will abuse the shit out of my little VPS.

Do I think I'm on the target list for a DDoS? Not at all. Do I think badly behaved crawlers and the general tom-fuckery of the Internet will destroy my little VPS and/or cause me outage bills? Absolutely. Cloudflare prevents all that, and as a bonus lets me geo-block bad actors to minimize the likelihood of even that happening.

See, my entire website is static, and for most people, so should yours be. The greatest thing about a static website is that the entire surface area is cacheable via a CDN. I /built/ my site with the idea of putting it behind Cloudflare in mind, specifically so I could do whatever I wanted (as long as it didn't need to query a database) and be entirely out of the woods.

It's worked great for over a decade, and I expect it to continue working great for a decade more. The fact it is currently down is not a big deal because I get maybe one organic visitor every week that's not my mom.

Re: Do not put your site behind Cloudflare if you don't need to

#175

I'm running a Raspberry Pi 5 at home as a lightweight web server. I put it behind `cloudflared` as to not leak my home IP address, and today I got to pay for it. Should I just stop being paranoid about "leaking my IP address" and self-host it 100%? All I fear is that my family will have to live with degraded internet experience because some script kiddie targeted me for fun.

You have other options besides leaking your home IP. You could use a VPN like Wireguard or a WG product like Tailscale, which is what I do. My Tailnet IPs are in public DNS, too, because it doesn't matter, they're not routable publicly. You could also get a cheap VPS in The Cloud and proxy requests to your home.

Re: Do not put your site behind Cloudflare if you don't need to

#177

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

> The author seems to be completely missing that it takes only a few bucks to buy DDoS as a service. Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online.

thank you. thank you. thank you.

we are tired of hot takes on the internet due to opportunism.

yeah even the small sites are being tested everday by bots. how the bots know your site just came online - I don't know. so yeah cloudflare is nice. we hate centralization on the internet - but to be naive that they're no bad actors on the internet is pure stupidity.

Re: Do not put your site behind Cloudflare if you don't need to

#179

?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.

If you use Cloudflare, your website will be inaccessible by well over half of German connections in the evening.
Post reply on HN