Live data from Hacker News

CloudFlare and Google Cloud Platform

cloudflare.com

111–120 of 133 posts

Re: CloudFlare and Google Cloud Platform

#111
post #51
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

What problem does CloudFlare really solve except for DDOS?

SSL. SSL is easy on a single server, but gets complex/expensive very fast on cloud platforms. Cloudflare have an incredibly easy solution (branded "flexible SSL") where they handle the SSL between the client and their CDN, and the CDN does un-encrypted requests to your platform.

Yes, this is a security shambles - Cloudflare is officially MITM-ing your traffic. But given the HTTPS-only movement this is a perfectly valid solution for public websites. And this announcement actually makes a big difference because if your platform is Google Cloud, then the un-encrypted portion is now over a private Cloudflare-Google interconnect.

FWIW, I've been using Cloudflare for 6 months and haven't seen any drop-outs. It's improved latency, and the only issue I've had was it mangling email addresses in transit, to prevent scrapers. It took 3 minutes to find the setting and switch it off, so I'm OK with that. Although I would prefer things that modify your HTML should be off by default.

Re: CloudFlare and Google Cloud Platform

#112

Earlier quoted context omitted.

CloudFlare pipes all traffic through an interception proxy and delegates signing of SSL certificates to their own infrastructure. A domain behind CloudFlare can be monitored (they see everything in plaintext), the content tampered with, or the origin completely changed without a single notification to the outside world anything has been altered. If you're sitting back in your evil chair, this is the perfect vantage p…

The point between cloudflare and your app doesn't need to be unencrypted, the lack of privacy is that cloudflare is a massive MITM and thus has access to all the data between you and your app. Thus the evil guy sitting back in their chair is cloudflare or it's you for not configuring https between your app and them.

And this announcement means that if your app is on Google Cloud, you don't need to encrypt between CF and your app. It's now going down a private interconnect, and I bet that interconnect is encrypted (like all Google's internal data pipes).

Re: CloudFlare and Google Cloud Platform

#113
post #52

Earlier quoted context omitted.

pretty neat from a routing standpoint and devastating to user privacy on the whole I'm interested. Please expand on the privacy point. I thought the general move to CloudFlare was a good thing for privacy, as it provides an easy mechanism for getting sites onto HTTPS without having every site to worry about managing certificates.

Setting up HTTPS is not hard. Getting a certificate is not hard.

...for a single server. HTTPS on a cloud platform is significantly more difficult and expensive.

We use Google Appengine, and although they have an SSL solution, it was an order of magnitude cheaper and easier to use Cloudflare's SSL.

I'll qualify this by saying our site is public, so we only need SSL because of the HTTPS-only crusade. If you are serving sensitive data, you do need to spend that magnitude more money and time to set up your own SSL.

Re: CloudFlare and Google Cloud Platform

#114
post #91

Earlier quoted context omitted.

>Shouldn't you also be upset over all the other service providers including your own ISP that also doesn't block those sites? I would argue that the moral dilemma is different if you choose to allow ISIS traffic to pass through you, vs have them as a client.

It might, but the business model Cloudflare is on makes the distinction less clear. For example with their free plans would they need to identify all clients, scan their content and judge accordingly? For paid clients, I might be more sympathetic to the argument, but even then the (moral?) rules (for nonbusiness) are incredibly tricky to figure out and keep consistent. Selective enforcement is bad for everyone in the…

>For example with their free plans would they need to identify all clients, scan their content and judge accordingly?

Ever heard of this little thing called abuse reports?

Re: CloudFlare and Google Cloud Platform

#115
post #78

Side question, does anybody have any experience with their RailGun feature, is it worth it? We recently switched to CF and mostly use them as a CDN and we're quite happy, good value for the money.

I use railgun on a few sites, it does make noticeable difference in page load times.

Re: CloudFlare and Google Cloud Platform

#116

Earlier quoted context omitted.

Interesting. This is the first I have heard of this and CloudFlare's reputation has just gone up my eyes because of it. Is ISIS dangerous and deplorable? Sure. Are there ideas so dangerous that they do not deserve to be exposed to public discourse and judged on their merits? I don't think so.

I don't follow; CloudFlare is not the government, therefore freedom of expression isn't really the issue here. Who they choose to give a voice to says a lot about them. I would oppose the government censoring ISIS; however, I would be proud of any company that refused to to business with them.

CloudFlare isn't the government, and so they are under no legal obligation to allow certain content. But their hands-off approach is precisely what gives them the rational standing not to censor any website any group finds distasteful. Furthermore, the threat of censorship does not only come from governments. I don't want to live in a world where a handful of corporations can decide what speech is allowed to be disseminated. Opinions like yours lead us head first to such a world.

Re: CloudFlare and Google Cloud Platform

#117
post #35

Earlier quoted context omitted.

This makes it unsuitable for gfx outsourcing work. In my last job (gamedev) people were starting to use more and more of the profiles built-in the image formats we were exporting (we settled on .tiff, but also supported .png, and few others). Though I remember that sometimes previews (or was it layers) saved in the .tiff were making it 10x, 20x (not kidding) times bigger, so a special "save" plugin was done to filter…

So, if you are in that situation don't enable our "Polish" service and the images will be passed/cached untouched.

Oh, I see - I was just basing my comment on what I've read above, without even reading any CloudFlare docs. Sorry about that!

Re: CloudFlare and Google Cloud Platform

#118
post #56

Earlier quoted context omitted.

I'm curious if you think ISPs should block ISIS websites, domains, and IP addresses.

It should be entirely up to the ISP. Consequently, the ISP's customers can judge (with their spending) whether they approve of such blocking.

In many many places, especially in the states there is no such thing as being able to judge with their spending because of monopolies.

Re: CloudFlare and Google Cloud Platform

#119
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

I tried their enterprise tier out about 9 months ago and was entirely unimpressed. Moving a site from Akamai -> CF increased page load times dramatically. We ended up quickly switching back. CloudFlare's complicity with ISIS, however, was what turned me off permanently. For those unaware, CloudFlare was providing proxy shielding of ISIS's propaganda websites. The CF CEO publicly refused to discontinue their service,…

ISIS, for all we know, could become a legitimate government in a context where legitimacy is clearly unclear. Why do we want CloudFlare to be involved in international politics and middle eastern wars?

Should an American business have an opinion on what Muslims, and other interested parties, ought to be viewing over the web with respect to ISIS? I would hope not. CloudFlare should not be in the business of judging whether Muslims and others are vulnerable to brainwashing from ISIS and need the protection of CloudFlare censorship, lest their fragile worldviews become corrupted.

Let the people of that region judge for themselves the future of their land.

Re: CloudFlare and Google Cloud Platform

#120
post #32

Earlier quoted context omitted.

What are you talking about?

This: https://moz.com/blog/how-to-stop-spam-bots-from-ruining-your... And this: https://blog.sucuri.net/2015/07/malicious-google-analytics-r... I and others that I know get this kind of referral spam on every single domain we have with cloudflare. I know DNS records are public, but is there something cloudflare and other public DNS hosting services can do to prevent this?

I see this on so many sites, including those not on Cloudflare.
Post reply on HN