Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

181–190 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#181

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Agreed. I plan to continue using Cloudflare for everything because it's a phenomenal service at a great price.

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#182
post #80

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

> then your host taking your website down and then you having to run circles around their support staff to bring back the website up again These are very different situations. With a DDoS the disruption ends when the attack ends, and your site should become available without any intervention. Your host taking down your site is a whole different matter, you have to take action to have this fixed, waiting around won't…

Not may area, so forgive me.

How does taking the site down stop the DDOS attack?

Isn't the host network still being bombarded by garbage packets, even if there isn't anything there listening?

Or is routing the destination IP to /dev/null enough to blunt the attack?

I know there are different kinds of attacks (e.g. some that are content based, impacting the individual server), but I thought most of them were just "legit" requests storming through the door that the server can't keep up with.

Having the site taken down after the fact, as a "risk to infrastructure" that the host can't afford, that's a different issue.

Re: Do not put your site behind Cloudflare if you don't need to

#183
post #113

Earlier quoted context omitted.

That’s like saying you should buy car insurance after you wreck your car

No its like saying you should buy a new battery after your battery dies. Yeah, its nice to have a spare battery around i guess but its not like your battery dying will significantly ruin your finances

It's more like buying the plug-in version after the battery dies...

You already experienced the downtime, so if not having downtime was a goal you already failed. If avoiding downtime is not important then there's no reason to add anti-downtime capability to your system. The most charitable modeling of this approach is that the downtime incident may prompt one to realize that avoiding downtime actually is an important property for their system to possess.

Re: Do not put your site behind Cloudflare if you don't need to

#184
Yep, my websites are up and running. No AWS, no CloudFlare, no problem.

We get excited by KPIs like uptime or scale while in truth for most of us those are not the key metrics. We think like BigTech because that's the metrics they sell us. It's a mistake that is profitable for them.

Re: Do not put your site behind Cloudflare if you don't need to

#185

Earlier quoted context omitted.

Yuuuuup. We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue? He got it really quickly. I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you…

Is it removing cf as the middleman temporally such a big deal?

It depends. The site is up, but now you're pumping 10x/100x the traffic. What are you scaling up?

Suddenly you're not blocking bots or malicious traffic. How many spam submissions or fake sales or other kinds of abuse are you dealing with? Is the rest of your organization ready to handle that?

Re: Do not put your site behind Cloudflare if you don't need to

#187

Earlier quoted context omitted.

Yuuuuup. We once had a cloudflare outage. My CEO asked "mitigate it" I hit him back with, okay, but that'll take me weeks/months potentially, since we're tiny, do you really want to take away that many resources just to mitigate a once every few years half the internet is down issue? He got it really quickly. I did mitigate certain issues that were just too common not to, but when it comes to this sort of thing, you…

Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.

> Cloudflare is mostly used for anonymity and privacy, not for scale

I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.

Re: Do not put your site behind Cloudflare if you don't need to

#188

I don't know if I need to, but cloudflare pages is without a doubt one of the easiest and cheapest ways to host a static personal site.

That's where I host my site. It really is massively simple, a few clicks to create a new deployment, push to git to update, done.

Re: Do not put your site behind Cloudflare if you don't need to

#189

Earlier quoted context omitted.

Do you think a world where all the commercial websites are centralized, but personal blogs are not, is that different than a world where blogs are also centralized? What is the benefit to having small blogs be decentralized?

If everything is centralized then nobody can discuss topics that have been decided to be off limits by the moderation teams at a few large companies.

If cloudflare decides they don’t want to be your CDN, you could just move off of cloudflare, and be in the same situation you would be in if you never used them. You aren’t locked in.

Re: Do not put your site behind Cloudflare if you don't need to

#190
post #113
post #97

Earlier quoted context omitted.

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

That’s like saying you should buy car insurance after you wreck your car

How? Isn’t it more like the difference between carrying an umbrella every day and ducking into the corner shop to buy one when you notice it’s raining?
Post reply on HN