Live data from Hacker News

Celebrating CloudFlare's 4th Birthday

blog.cloudflare.com

31–40 of 42 posts

Re: Celebrating CloudFlare's 4th Birthday

#31
post #26

Earlier quoted context omitted.

CloudFlare will probably supply their own certificates so you won't even need to do that.

Even better! One-click cert gen and installation would be magical! StartSSL is nice because you don't need create a csr. But Cloudflare could make it simpler still, since you've already got domain-level verification through them implicitly. And if you need a better trust chain for your certs, then you can provide your own. This just got even more exciting!

StartSSL's for SSL is good but it's not great - mainly, you have to give your computer access to the SSL key and your server, as opposed to only your server storing the key (and you providing StartSSL a CSR)

Re: Celebrating CloudFlare's 4th Birthday

#32

Wonder why DDOSes have been getting worse lately? DDOS groups are putting their sites behind Cloudflare so they cannot be DDOSed off the internet by rival groups, thus their "services" become a lot more accessible, and they have grown bolder. This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare. This absolutely needs to be addre…

It is because many DDoS websites sitting behind Cloudflare are FBI run. See titaniumstresser[0] as an example. One of their sub-domain's IP address is allocated to the FBI[1]. Seems like the longest lasting sites peddling stolen info, child pornography, or malicious services are all run by feds. Hostname: direct.titaniumstresser.net IP Address: 153.31.25.12 Organization: FBI Criminal Justice Information Systems [0] h…

I could point my personal domain at the FBI in 3 seconds if I felt like it, completely legal and commonplace.

Re: Celebrating CloudFlare's 4th Birthday

#33

Wonder why DDOSes have been getting worse lately? DDOS groups are putting their sites behind Cloudflare so they cannot be DDOSed off the internet by rival groups, thus their "services" become a lot more accessible, and they have grown bolder. This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare. This absolutely needs to be addre…

Those services have existed for years before Cloudflare came around. They'll continue to exist even after they're welcome on Cloudflare.

Censorship-resistant networks are an incredibly powerful tool, for good and bad uses alike. We shouldn't criticize the tool just because some choose to use it in a way we disagree with.

Re: Celebrating CloudFlare's 4th Birthday

#34

Earlier quoted context omitted.

They offers SSL with CloudFlare-issued cert for non-free plan already. I assume they use the old method of obtaining cert. Also, I think at their scale they can get special plan from CA.

They pay GlobalSign roughly $4000 (most are 3 yrs in length, that's for all three), which is only used to power SSL for about twenty domains (this obviously varies but it's what I've seen before, and it should be able to support 50 or 100 total domains). Free SSL would not be practical with their old method.

No offence, but considering that their Pro plan which include SSL starts at $20 for first, and $5 for the rest per account. At 50*$20 it's only $1000. That doesn't sound right.

Re: Celebrating CloudFlare's 4th Birthday

#35

Earlier quoted context omitted.

They pay GlobalSign roughly $4000 (most are 3 yrs in length, that's for all three), which is only used to power SSL for about twenty domains (this obviously varies but it's what I've seen before, and it should be able to support 50 or 100 total domains). Free SSL would not be practical with their old method.

No offence, but considering that their Pro plan which include SSL starts at $20 for first, and $5 for the rest per account. At 50*$20 it's only $1000. That doesn't sound right.

It's a yearly fee! :)

Also updated my comment with a better estimate of the pricing (we've talked w/ GlobalSign about this before actually)

Re: Celebrating CloudFlare's 4th Birthday

#36

Wonder why DDOSes have been getting worse lately? DDOS groups are putting their sites behind Cloudflare so they cannot be DDOSed off the internet by rival groups, thus their "services" become a lot more accessible, and they have grown bolder. This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare. This absolutely needs to be addre…

This site has compiled an interesting collection of observations: http://crimeflare.com

Re: Celebrating CloudFlare's 4th Birthday

#37
post #26

Earlier quoted context omitted.

CloudFlare will probably supply their own certificates so you won't even need to do that.

Even better! One-click cert gen and installation would be magical! StartSSL is nice because you don't need create a csr. But Cloudflare could make it simpler still, since you've already got domain-level verification through them implicitly. And if you need a better trust chain for your certs, then you can provide your own. This just got even more exciting!

StartSSL is nice because you don't need create a csr.

You should though.

Re: Celebrating CloudFlare's 4th Birthday

#38

Earlier quoted context omitted.

It is because many DDoS websites sitting behind Cloudflare are FBI run. See titaniumstresser[0] as an example. One of their sub-domain's IP address is allocated to the FBI[1]. Seems like the longest lasting sites peddling stolen info, child pornography, or malicious services are all run by feds. Hostname: direct.titaniumstresser.net IP Address: 153.31.25.12 Organization: FBI Criminal Justice Information Systems [0] h…

LOL, that's just so someone (of a rival group) who tries to get their real IP address (to ddos them), finds that subdomain, and doesn't look closely, and goes to ddos the FBI.

Correct.

Many automated scripts script kiddies use to DDoS will do a basic check for subdomains like "direct.domain.com" and "direct-connect.domain.com" if the target domain is behind Cloudflare, and the scripts are naive and immediately assume that's the server's real IP.

Setting it to the IP of a site they dislike is also a popular choice.

Post reply on HN