Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

211–220 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#212
post #155

Earlier quoted context omitted.

My blog was constantly going down for unknown reasons, with nothing obvious in the logs. I migrated it to CloudFlare and was able to track down the root-cause of the issue. I also blocked all the AI crawlers after moving to CloudFlare and have stopped a huge amount of traffic theft with it. My website is definitely much more stable, and loads insanely faster, since moving to CloudFlare.

I need SponsorBlock for HN, this is ridiculous.

I don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog.

It's not because it's not a criticism that it's a sponsored post.

I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without:

- First Contentful Paint: 0.4s - 0.7s

- Largest Contentful Paint: 0.8s - 0.9s

- Total Blocking Time: 0 ms - 0 ms

- Cumulative Layout Shift: 0 - 0

- Speed Index: 0.4s - 8.9s

The difference is quite staggering, and I'm located pretty close to my server (a Hetzner VPS), I can't imagine the difference for someone that lives across the world.

Re: Do not put your site behind Cloudflare if you don't need to

#214

Earlier quoted context omitted.

If everything is centralized then nobody can discuss topics that have been decided to be off limits by the moderation teams at a few large companies.

If cloudflare decides they don’t want to be your CDN, you could just move off of cloudflare, and be in the same situation you would be in if you never used them. You aren’t locked in.

> You aren’t locked in.

Did you consider and discard the eventuality that all the other ISP have gone out of business because everyone just uses cloudflare?

Invasive species destroy ecosystems.

Re: Do not put your site behind Cloudflare if you don't need to

#215
post #80

Earlier quoted context omitted.

> then your host taking your website down and then you having to run circles around their support staff to bring back the website up again These are very different situations. With a DDoS the disruption ends when the attack ends, and your site should become available without any intervention. Your host taking down your site is a whole different matter, you have to take action to have this fixed, waiting around won't…

> These are very different situations. It is obvious those two are very different situations. I'm not sure I understand your point. Yeah, nobody will be bothered by a short 15 minute DDoS attack. I prolly wouldn't even notice it unless I'm actively checking the logs. Sure, nobody is going to be bothered by that. But what if someone's DDoSing persistently with a purpose? Maybe they're just pissed at you. My point is..…

> a sustained DDoS attack will just make your host drop you

I'd love to see someone suing the host for damages. The contract binds them as much as it binds you.

Sounds like a good way to have your next gaming rig financed.

Re: Do not put your site behind Cloudflare if you don't need to

#216
> Most of these sites are not even that big. I expect maybe a few thousand visitors per month.

> This demonstrates again a simple fact: if you put your site behind a centralized service, then this service is a single point of failure. Even large established companies make mistakes and can go down.

I'm guessing sites with a few thousand visitors a month don't much care about single points of failure. Seems like kind of a circular argument - if they're too small to care about needing a proxy in front of their service, then they are also probably too small to care about the handful of events that cause it to go down every so often.

People talk about "single points of failure" like invoking that phrase in and of itself means something is bad. There are many areas where avoiding single points of failure is essentially impossible. It's about how much risk and impact you are willing to tolerate with those points of failure.

Re: Do not put your site behind Cloudflare if you don't need to

#218
post #46

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

It's like insurance. If you add up everyone's medical expenses, it's less than we all pay for insurance. But if you're the one getting hit, it matters a lot.

Re: Do not put your site behind Cloudflare if you don't need to

#219

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Genuinely I don't understand how people post under their own name or connect their accounts to their real identities at all. I learned early that my opinion can piss people off (even though I think I'm pretty milquetoast to be honest), and there are people with enough time and hate to make their disagreement with you impact you personally. I started using a pseudonym about the time my consulting site got taken down b…

Well, the first profile I ever had was an Xbox account that was based on my real name, and I just carried that username onto everything else. So I just ended up having a username based on my real name everywhere. And I never bothered to restart my social life to get a new one.

Re: Do not put your site behind Cloudflare if you don't need to

#220
post #113
post #97

Earlier quoted context omitted.

Starting without ddos protection and installing ddos protection IF you get attacked sounds like a reasonable strategy to me.

That’s like saying you should buy car insurance after you wreck your car

It's like saying you should buy volcano insurance after you get hit by a volcano
Post reply on HN