Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

221–230 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#221
post #155

Earlier quoted context omitted.

My blog was constantly going down for unknown reasons, with nothing obvious in the logs. I migrated it to CloudFlare and was able to track down the root-cause of the issue. I also blocked all the AI crawlers after moving to CloudFlare and have stopped a huge amount of traffic theft with it. My website is definitely much more stable, and loads insanely faster, since moving to CloudFlare.

I need SponsorBlock for HN, this is ridiculous.

There are two companies on HN which get massive amounts of support from poster fanboys - cloudflare and tailscale.

It used to be apple.

Re: Do not put your site behind Cloudflare if you don't need to

#222
post #14
post #8

The lesson I learned is it's OK to put your site with Cloudflare. It's not ok to put your DNS on a registrar who is also on Cloudflare. We got locked out because our registrar is also on Cloudlfare, and now I can't even switch DNS to get the site back up. Keep your domain name registrar, DNS service provider and application infrastructure provider separately.

Fair point but you also get exposed if the dns provider has an outage. Self hosting will also bring its own set of problems and costs.

Use multiple DNS providers. Some secondaries have thousands of anycast nodes that are provided for free. One can also condition their user-base to know of multiple domains that are on different registrar accounts and of course a few .onion domains.

Re: Do not put your site behind Cloudflare if you don't need to

#223

Earlier quoted context omitted.

If cloudflare decides they don’t want to be your CDN, you could just move off of cloudflare, and be in the same situation you would be in if you never used them. You aren’t locked in.

> You aren’t locked in. Did you consider and discard the eventuality that all the other ISP have gone out of business because everyone just uses cloudflare? Invasive species destroy ecosystems.

I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare. You still have your own host, just the same as you would without cloudflare. You are still providing your non-cloudflare host with the same revenue you would if you didn't use cloudflare, so I am not sure how that would hurt the ecosystem.

The 'Invasive species destroy ecosystems' quote sounds good, but what exactly does it mean in this case? What is the species, and what is it invading?

Re: Do not put your site behind Cloudflare if you don't need to

#224

?? It's free, and it protects you from all sorts of nasty things. I can't think of any reason not to use cloudflare. It's _dead easy_ to set up too. I can't help but think that the author understands what cloudflare actually does, or just has a poor understanding of what goes on on the internet. Probably a bit of just being in a bad mood about cloudflare being down too.

If you use Cloudflare, your website will be inaccessible by well over half of German connections in the evening.

I instantly knew you are talking about Deutsche Telekom and their shit-tier transits.

Re: Do not put your site behind Cloudflare if you don't need to

#225
post #155

Earlier quoted context omitted.

I need SponsorBlock for HN, this is ridiculous.

I don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog. It's not because it's not a criticism that it's a sponsored post. I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without: - First…

Sure, but your post reads like an infomercial, hence the snark.

NARRATOR:

- "Has THIS ever happened to you?"

CUT TO:

Black-and-white. Some guy stares in frustration and confusion at a terminal. Output of 'cat /usr/bin/gcc | xxd' or whatever scroll by.

NARRATOR:

- "Introducing CloudFlare™!"

CUT TO:

Full color. Sunlight. The same guy now sprawled on grass at a park. Two dogs tackle him with adoration. His kids hand him ice cream.

NARRATOR:

- "Stop debugging. Start living."

Re: Do not put your site behind Cloudflare if you don't need to

#226
post #167

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

In my experience hetzner DDoS protection doesn't work

Re: Do not put your site behind Cloudflare if you don't need to

#227
post #155

Earlier quoted context omitted.

I need SponsorBlock for HN, this is ridiculous.

I don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog. It's not because it's not a criticism that it's a sponsored post. I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without: - First…

I'm quite sure something else is going on here. Adding another hop generally shouldn't improve performance, especially if you are close by to the server.

What are the response times of requests between CF and accessing them directly?

Re: Do not put your site behind Cloudflare if you don't need to

#228
post #167

Earlier quoted context omitted.

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

In my experience hetzner DDoS protection doesn't work

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

Re: Do not put your site behind Cloudflare if you don't need to

#229

Earlier quoted context omitted.

Not may area, so forgive me. How does taking the site down stop the DDOS attack? Isn't the host network still being bombarded by garbage packets, even if there isn't anything there listening? Or is routing the destination IP to /dev/null enough to blunt the attack? I know there are different kinds of attacks (e.g. some that are content based, impacting the individual server), but I thought most of them were just "leg…

Forgiveness not necessary, these are good questions. Internet packets have to travel through many routers between the source and the attack and the server they're attacking, at each step the routers usually get smaller. the smaller routers are less able to withstand the amount of traffic destined for one server, which means they can't route traffic to all the other servers that are not under attack. a common strategy…

Ok, thanks.

I was thinking more things being done to the actual machine the site was hosted on.

Re: Do not put your site behind Cloudflare if you don't need to

#230

Earlier quoted context omitted.

If everything is centralized then nobody can discuss topics that have been decided to be off limits by the moderation teams at a few large companies.

If cloudflare decides they don’t want to be your CDN, you could just move off of cloudflare, and be in the same situation you would be in if you never used them. You aren’t locked in.

If you can move off of CDNs then you're not in a world where all personal blogs are centralized.
Post reply on HN