Live data from Hacker News

The Cloudflare outage might be a good thing

gist.github.com

131–140 of 209 posts

Re: The Cloudflare outage might be a good thing

#131

I don't know how many times I need to say this, but I will die on this hill. Centralized services don't decrease redundancy. They're usually far more redundant than whatever homegrown solution you can come up with. The difference between centralized and homegrown is mostly psychological. We notice the outages of centralized systems more often, as they affect everything at the same time instead of different systems at…

In my experience services aren't failing due to a lack of redundancy but due to an excess of complexity. With the move to the cloud we are continually increasing both redundancy and complexity and this is making the problem worse.

I have a cheap VPS that has run reliably for a decade except for a planned hour of downtime. Which was in the middle of the night when no-one cared. Amazon is more reliable in theory. My cheap VPS is more reliable in practice.

Re: The Cloudflare outage might be a good thing

#132
post #74

Earlier quoted context omitted.

Is a little downtime such a bad thing? Trying to avoid some bumps and bruises in your business has diminishing returns.

Even more so when most of the internet is also down. What are customers going to do? Go to competitor that's also down? It is extremely annoying, will ruin your day, but as movie quote goes - if everyone is special, no one is.

I think you’re viewing the issue from an office worker’s perspective. For us, downtime might just mean heading to the coffee machine and taking a break.

But if a restaurant loses access to its POS system (which has happened), or you’re unable to purchase a train ticket, the consequences are very real. Outages like these have tangible impacts on everyday life. That’s why there’s definitely room for competitors who can offer reliable backup strategies to keep services running.

Re: The Cloudflare outage might be a good thing

#133

Earlier quoted context omitted.

The cynic in me wonders how much blame the world's leading vendor of DDoS prevention might share in the creation of that particularly problem

They provide free services to DDoS-for-hire services and do not terminate the services when reported.

Not that I doubt examples exist (I've yet to be at a large place with 0 failures on responding to such issues over the years), but it'd be nice if you'd share the specific examples you have in mind if you're going to bother commenting about it. It helps people understand how much is a systemic problem to be interested in vs having a comment which more easily falls into many other buckets instead. I'd try to build trust off the user profile as well, but it proclaims you're shadowbanned for two different reasons - despite me seeing your comment.

One related topic I've seen brought up is Workers abuse https://www.fortra.com/blog/cloudflare-pages-workers-domains..., but that goes against this claim they do nothing when reported.

Re: The Cloudflare outage might be a good thing

#134
post #121
post #75

Earlier quoted context omitted.

Genuine question - why are you spending time and effort on geofencing when you could spend it on improving your software/service? It takes time and effort for no gain in any sensible business goal. People outside of US won't need it, bad actors will spoof their location, and it might inconvenience your real customers. And if you want a secure communication just setup zero-trust network.

> bad actors will spoof their location Isn't that exactly the point? Why are North Korean hackers even allowed to connect to the service, and why is spoofing location still so easy and unverifiable? Nobody is expected to personally secure their physical location against hostile state actors. My office is not artillery proof, nor does it need to be: hostile actions against it would be an act of war and we have the mil…

you can as easily get attackers from within your own networks, you're falling for fallacy that everything on the 'inside' is secure.

Re: The Cloudflare outage might be a good thing

#135
post #26

Earlier quoted context omitted.

the root cause is customers refusing to punish these downtime. Checkout how hard customers punish blackouts from the grid - both via wallet, but also via voting/gov't. It's why they are now more reliable. So unless the backbone infrastructure gets the same flak, nothing is going to change. After all, any change is expensive, and the cost of that change needs to be worth it.

> Checkout how hard customers punish blackouts from the grid - both via wallet, but also via voting/gov't. What? Since when has anyone ever been free to just up and stop paying for power from the grid? Are you going to pay $10,000 - $100,000 to have another power company install lines? Do you even have another power company in the area? State? Country? Do you even have permission for that to happen near your building…

The hyperscalers definitely vote with their wallets.

Re: The Cloudflare outage might be a good thing

#136
post #74

Earlier quoted context omitted.

Even more so when most of the internet is also down. What are customers going to do? Go to competitor that's also down? It is extremely annoying, will ruin your day, but as movie quote goes - if everyone is special, no one is.

I think you’re viewing the issue from an office worker’s perspective. For us, downtime might just mean heading to the coffee machine and taking a break. But if a restaurant loses access to its POS system (which has happened), or you’re unable to purchase a train ticket, the consequences are very real. Outages like these have tangible impacts on everyday life. That’s why there’s definitely room for competitors who can…

Those are examples where they shouldn't be using public cloud in the first place. Should build those services to be local-first.

Using a different, smaller cloud provider doesn't improve reliability (likely makes it worse) if the architecture itself wrong.

Re: The Cloudflare outage might be a good thing

#137
post #74

Earlier quoted context omitted.

Even more so when most of the internet is also down. What are customers going to do? Go to competitor that's also down? It is extremely annoying, will ruin your day, but as movie quote goes - if everyone is special, no one is.

I think you’re viewing the issue from an office worker’s perspective. For us, downtime might just mean heading to the coffee machine and taking a break. But if a restaurant loses access to its POS system (which has happened), or you’re unable to purchase a train ticket, the consequences are very real. Outages like these have tangible impacts on everyday life. That’s why there’s definitely room for competitors who can…

Do any of those competitors actually have meaningfully better uptime?

From a societal level, having everything shut down at once is an issue. But if you only have one POS system targeting only one backend URL (and that backend has to be online for the POS to work) then cloudflare seems like one of the best choices

If the uptime provided by cloudflare isn't enough then the solution isn't a cloudflare competitor, it's the ability to operate offline (which many POS have, including for card purchases) or at least multiple backends with different DNS, CDN, server location etc.

Re: The Cloudflare outage might be a good thing

#138
post #116

I don't know how many times I need to say this, but I will die on this hill. Centralized services don't decrease redundancy. They're usually far more redundant than whatever homegrown solution you can come up with. The difference between centralized and homegrown is mostly psychological. We notice the outages of centralized systems more often, as they affect everything at the same time instead of different systems at…

> Centralized services don't decrease redundancy Alright, but it creates a failure correlation where previously there was none

Have you ever heard of the "sendmail worm", aka Morris Worm ?

https://en.wikipedia.org/wiki/Morris_worm

You can definitely have failure correlation without having centralized services.

Re: The Cloudflare outage might be a good thing

#139

I don't know how many times I need to say this, but I will die on this hill. Centralized services don't decrease redundancy. They're usually far more redundant than whatever homegrown solution you can come up with. The difference between centralized and homegrown is mostly psychological. We notice the outages of centralized systems more often, as they affect everything at the same time instead of different systems at…

"redundancy" might not be there correct word. If we had a single worldwide mega-entity serving 100% of the internet it would be both a monopoly and would have tons of redundant infrastructure.

But it would also be quite unified; the system, while full of redundancies, as a whole is a unique one operated the same way end to end; by virtue of it being a single system handled in a uniform way, a single glitch could bring it all down. There is no diversity in the system's implementation, the monoculture itself makes it vulnerable.

Re: The Cloudflare outage might be a good thing

#140
post #51

Earlier quoted context omitted.

> and I only want people in the US to be able to access it. That simple task is literally impossible with what we have allowed the internet to become. Is anyone else as confused as I am about how common anti-openness and anti-freedom comments are becoming on HN? I don’t even understand what this comment wants: Banning VPNs? Walling off the rest of the world from US internet? Strict government identity and citizenship…

> Is anyone else as confused as I am about how common anti-openness and anti-freedom comments are becoming on HN? In this specific case I don't think it's about being anti-open? It's that a business with only physical presence in one country selling a service that is only accessible physically inside the country.... doesn't.... have any need for selling compressed air to someone who isn't like 15 minutes away from on…

> In this specific case I don't think it's about being anti-open?

The anti-open part was the mention of “allowed to become”, as if we needed to disallow something to achieve this unstated goal.

Post reply on HN