Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

351–360 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#351
post #342

Earlier quoted context omitted.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

Considering there are probably near-zero MS-DOS machines online these days, I expect their attacks wouldn't cost very much.

On the other hand, based on supply v. demand I'd expect an MS-DOS attack to be pretty expensive these days :)

Re: Do not put your site behind Cloudflare if you don't need to

#352
post #167

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

It's funny because Hetzner was infamous for null routing on the slightest DoS back in the day. Have they improved?

Re: Do not put your site behind Cloudflare if you don't need to

#353

Earlier quoted context omitted.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

Off-topic, but there are six different people using the word "hoster" in this thread. I've never heard that word used instead of "host" or "hosting service" before, and yet here it's somehow prevalent. I feel like I'm having a stroke, or I just stepped into an alternate universe. Where did you all pick up that word?

That's just English being irregular. One that hosts websites should be called a hoster in principle :)

Re: Do not put your site behind Cloudflare if you don't need to

#354

Earlier quoted context omitted.

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#355

Earlier quoted context omitted.

Off-topic, but there are six different people using the word "hoster" in this thread. I've never heard that word used instead of "host" or "hosting service" before, and yet here it's somehow prevalent. I feel like I'm having a stroke, or I just stepped into an alternate universe. Where did you all pick up that word?

That's just English being irregular. One that hosts websites should be called a hoster in principle :)

Host is both a noun and a verb. (The host can host a party.)

Hoster is new to me too.

But I get it as a pattern. (If you dine at the party then you are a diner.)

Re: Do not put your site behind Cloudflare if you don't need to

#356
>"no one will burn their DDoS capabilities on you!"

You don't need to burn a DDoS capability to launch a DDoS attack. You just need to pay a few bucks to a booter service. A few minutes of searching turned up these:

https://hardstresser.org/ (this one looks like it offers a free trial)

https://stresserbox.com/

https://ip-stresser.cc/

https://stresser.sx/

https://maxstresser.com/

Re: Do not put your site behind Cloudflare if you don't need to

#357
Problem is, new adopters of digital presence do so by standardized convention set by market and market incentivise faster and efficient adoption and cloudflare is/has become that standard as what wordpress became decades ago, for bloggers. The boogeyman hackers pose uncertainity and cloudflare standard promised a solution against it, especially ddos. I usually reverse dig new companies and almost all of them are behind cloudflare. It is just a learned helplessness.

Re: Do not put your site behind Cloudflare if you don't need to

#358

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

I wish online discourses didn't feel like engaging with possible shills for corporations as it did during 2000s, or maybe it didn't. Maybe, we became too aware and critical or maybe there is absolutely no honest discourse possible when commerce, political or even ideological agendas are involved. The best stance should one that presents varied solutions to a common problem.

Re: Do not put your site behind Cloudflare if you don't need to

#359
will always champion the notion of keeping things as simple as possible. however this take seems a bit overreactive.

their stack has been some of the easiest low-hanging fruits for enhancing self-managed web stuff. almost everyone who agrees with this sentiment is also relying on someone else in the chain to keep their sites up. in my limited experience, the latter ended up being less reliable in the past decade or so.

funnily enough the site was (momentarily) not loading for me, but instantly did right after.

Re: Do not put your site behind Cloudflare if you don't need to

#360
post #94

If you have a blog with 100 visitors per month why would you worry about being hit by an 4-8 hours outage once every year or two? I like Cloudflare because it is easy to setup and manage and because the amount of value you get for free or just a few bucks per month can’t be matched by any other company. Sure, if my income depends on my website/service uptime then I would probably consider other options. I think for m…

I swear these outages always have people forgetting how uptime works.

Cloudflare went down for 5 hours this year. That’s 99.94% uptime.

For real, who cares? Get a life and take a nice walk or something.

Let the big enterprises worry about their backup plan.

Post reply on HN