> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
Agreed. I plan to continue using Cloudflare for everything because it's a phenomenal service at a great price.
Do not put your site behind Cloudflare if you don't need to
181–190 of 391 posts
Re: Do not put your site behind Cloudflare if you don't need to
#182Earlier quoted context omitted.
> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…
> then your host taking your website down and then you having to run circles around their support staff to bring back the website up again These are very different situations. With a DDoS the disruption ends when the attack ends, and your site should become available without any intervention. Your host taking down your site is a whole different matter, you have to take action to have this fixed, waiting around won't…
How does taking the site down stop the DDOS attack?
Isn't the host network still being bombarded by garbage packets, even if there isn't anything there listening?
Or is routing the destination IP to /dev/null enough to blunt the attack?
I know there are different kinds of attacks (e.g. some that are content based, impacting the individual server), but I thought most of them were just "legit" requests storming through the door that the server can't keep up with.
Having the site taken down after the fact, as a "risk to infrastructure" that the host can't afford, that's a different issue.
Re: Do not put your site behind Cloudflare if you don't need to
#183Earlier quoted context omitted.
That’s like saying you should buy car insurance after you wreck your car
No its like saying you should buy a new battery after your battery dies. Yeah, its nice to have a spare battery around i guess but its not like your battery dying will significantly ruin your finances
You already experienced the downtime, so if not having downtime was a goal you already failed. If avoiding downtime is not important then there's no reason to add anti-downtime capability to your system. The most charitable modeling of this approach is that the downtime incident may prompt one to realize that avoiding downtime actually is an important property for their system to possess.
Re: Do not put your site behind Cloudflare if you don't need to
#184We get excited by KPIs like uptime or scale while in truth for most of us those are not the key metrics. We think like BigTech because that's the metrics they sell us. It's a mistake that is profitable for them.
Re: Do not put your site behind Cloudflare if you don't need to
#185Earlier quoted context omitted.
Yuuuuup. We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue? He got it really quickly. I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you…
Is it removing cf as the middleman temporally such a big deal?
Suddenly you're not blocking bots or malicious traffic. How many spam submissions or fake sales or other kinds of abuse are you dealing with? Is the rest of your organization ready to handle that?
Re: Do not put your site behind Cloudflare if you don't need to
#186Re: Do not put your site behind Cloudflare if you don't need to
#187Earlier quoted context omitted.
Yuuuuup. We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue? He got it really quickly. I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you…
Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.
I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.
Re: Do not put your site behind Cloudflare if you don't need to
#188I don't know if I need to, but cloudflare pages is without a doubt one of the easiest and cheapest ways to host a static personal site.
Re: Do not put your site behind Cloudflare if you don't need to
#189Earlier quoted context omitted.
Do you think a world where all the commercial websites are centralized, but personal blogs are not, is that different than a world where blogs are also centralized? What is the benefit to having small blogs be decentralized?
If everything is centralized then nobody can discuss topics that have been decided to be off limits by the moderation teams at a few large companies.
Re: Do not put your site behind Cloudflare if you don't need to
#190Earlier quoted context omitted.
Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.
That’s like saying you should buy car insurance after you wreck your car