Earlier quoted context omitted.
So the internet is a series of pipes, or tubes, whatever. This quintessential personal blog website is hosted somewhere in this inter connected mess of things. There’s a hierarchy of these pipes/tubes, and they all have some ever diminishing capacity as they head from a mythical center to the personal blog website. When the bad guys want to DDoS the personal blog website they don’t go and figure out the correct amoun…
This is incorrect. Any decent host/ISP will instead (automatically, sometimes) emit a blackhole request for the given target IP address to their upstreams, causing the traffic to be filtered there (at the 'larger pipe'). In turn, these upstreams can also pass on the same blackhole request further up if necessary. This means the target is down from the point of view of the Internet, but there is no collateral damage.…
Do not put your site behind Cloudflare if you don't need to
281–290 of 391 posts
Re: Do not put your site behind Cloudflare if you don't need to
#282Earlier quoted context omitted.
> I am suggesting you host your website on your own server somewhere, and then you put it behind cloudflare I'd rather advocate for a solution that doesn't induce centralization. Because that still does. It's a weird suggestion to pay twice. I'm assuming in your hypothetical, cloudflare not only doesn't ever go down, but also absorbs only malicious traffic, and not any organic? Why should cloudflare do that and not m…
> I'd rather advocate for a solution that doesn't induce centralization. Because that still does. It's a weird suggestion to pay twice. I'm assuming in your hypothetical, cloudflare not only doesn't ever go down, but also absorbs only malicious traffic, and not any organic? Why should cloudflare do that and not my primary host? I'll assume I have XX to spend on hosting, you don't see how if I have to also allocate so…
I object to centralization and consolidation of power, how is this not both?
I'll duplicate my follow up question, from a sister thread.
If I actually start using the DDoS protection or other services... will cloudflare cut me off unless I pay? Will that charge be exorbitant? Does that behavior feel like extortion? Have they done that before?
Re: Do not put your site behind Cloudflare if you don't need to
#283Earlier quoted context omitted.
No it really doesn't. How are you the product when Cloudflare gives you free tier access? That's not their business model. You aren't the product, but you are an upsell lead for the sales team.
Sales teams don't pay for leads? If you keep me around, exclusively because the sales team wants to show me something... I'm the product. Follow up question, if I actually start using the DDoS protection or other services... will cloudflare cut me off unless I pay? Will that charge be exorbitant? Does that behavior feel like extortion? Have they done that before?
I have only used CF at the enterprise level so IDK if DDoS protection is free tier. Surprise billing like that is bad behavior, but it's not "you are the product" behavior.
Re: Do not put your site behind Cloudflare if you don't need to
#284> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
Did you mean reliability? At this point I don't care if my server gets DDoS, but may be more convinced by security practices.
Re: Do not put your site behind Cloudflare if you don't need to
#285I get it... but you can pry my cloudflare-tunnel from my cold dead hands. I'm no stranger to hosting things 'the hard way', but I am not going back from my happy casual hosting where I just spin up a docker container, and point the cloudflare tunnel at the local port and opt out of worrying over DDOS, SSL termination and certs, and everything else that goes with it. With tailscale, I don't even keep port 22 open to t…
Re: Do not put your site behind Cloudflare if you don't need to
#286Cloudflare is still down and now its been 5+ hours. Having said that, the thing about "if you don't need to" is not that simple. FOr personal sites/blogs, I can agree but then it really doesnt matter for those. For a real business, the value of cloudflare (As centralized as it gets) is the proxy especially against attacks. The other stuff like CDN/Caching etc are bonus on top. Unless there is a better option, just as…
5+ hours. It's amusing to reflect on all the "leaders" I've seen jumping on people's heads because a single feature of some unknown product was unavailable for 30 minutes.
Re: Do not put your site behind Cloudflare if you don't need to
#287Earlier quoted context omitted.
Sales teams don't pay for leads? If you keep me around, exclusively because the sales team wants to show me something... I'm the product. Follow up question, if I actually start using the DDoS protection or other services... will cloudflare cut me off unless I pay? Will that charge be exorbitant? Does that behavior feel like extortion? Have they done that before?
If the Cloudflare free tier TOS allows them to sell your data then I would agree that "you are the product". IDK if it does, but I would put my money on no. I have only used CF at the enterprise level so IDK if DDoS protection is free tier. Surprise billing like that is bad behavior, but it's not "you are the product" behavior.
> [...] but it's not "you are the product" behavior.
Discarding the context for the thread, probably. But if we're discarding context, "you're removed when you start to consume resources" isn't you're the customer behavior either.
Maybe, it's you're the patsy behavior?
Re: Do not put your site behind Cloudflare if you don't need to
#288sure there are botnets, infected devices, etc that would conform to this but where does the sheer power of a big ddos attack come from? including those who sell it as a service. they have to have some infrastructure in some datacenter right?
make a law that forces every edge router of a datacenter to check for source IP and you would eliminate a very big portion of DDoS as we know it.
until then, the only real and effective method of mitigating a DDoS attack is with even more bandwidth. you are basically a black hole to the attack, which cloudflare basically is.
Re: Do not put your site behind Cloudflare if you don't need to
#289Which is more likely, a DDOS attack on your site or a Cloudflare outage? I think that for most sites the DDOS attack is more likely.
https://hn.algolia.com/?q=cloudflare+outage
Cloudflare apparently has outages every 1-2 years or so.
Re: Do not put your site behind Cloudflare if you don't need to
#290> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
> Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online. People come with that argument so often. But then one day I was completely done with something and I put out a rant on Reddit in my real name. Hundreds op people disagreed and told me "Why do you do that under your own name?! Are you crazy? This will lead to many problems." Guess what. This was mon…
Just because it didn't happen to you does not mean that it doesn't happen to others. You can see a few anecdotes in this thread itself where people commented that they did get attacked for pissing people off. Like check this: https://news.ycombinator.com/item?id=45968219