Live data from Hacker News

The Cloudflare outage might be a good thing

gist.github.com

141–150 of 209 posts

Re: The Cloudflare outage might be a good thing

#141
post #41

Earlier quoted context omitted.

Is a little downtime such a bad thing? Trying to avoid some bumps and bruises in your business has diminishing returns.

What's "a little downtime" to you might be work ruined and day wasted for someone else.

I have a lot of bad days every year. More than I can count. It's just part of living.

Re: The Cloudflare outage might be a good thing

#142
post #121
post #75

Earlier quoted context omitted.

Genuine question - why are you spending time and effort on geofencing when you could spend it on improving your software/service? It takes time and effort for no gain in any sensible business goal. People outside of US won't need it, bad actors will spoof their location, and it might inconvenience your real customers. And if you want a secure communication just setup zero-trust network.

> bad actors will spoof their location Isn't that exactly the point? Why are North Korean hackers even allowed to connect to the service, and why is spoofing location still so easy and unverifiable? Nobody is expected to personally secure their physical location against hostile state actors. My office is not artillery proof, nor does it need to be: hostile actions against it would be an act of war and we have the mil…

> Why are North Korean hackers even allowed to connect to the service,

Asking why some group is “allowed” to use the internet is equivalent to demanding either strict verification or that we cut off some entire country where they reside from the entire internet.

Either that, or someone doesn’t understand basic fundamentals of networking and thinks there’s some magic solution to this problem.

A common variation of this comment is “why do we allow kids to access ” with demands that something be done about it. Then when something is done about it, there is shock and outrage upon realizing that you can’t filter out children without forcing identity verification upon everyone. Similar vibes here, just replace age with demographic.

Re: The Cloudflare outage might be a good thing

#143
post #10

It would be a good thing, if it would cause anything to change. It obviously won't. As if a single person reading this post wasn't aware that the Internet is centralized, and couldn't name specifically a few sources of centralization (Cloudflare, AWS, Gmail, Github). As if it's the first time this happens. As if after the last time AWS failed (or the one before that, or one before…) anybody stopped using AWS. As if a…

Same idea with the Crowdstrike bug, it seems like it didn't have much of on effect on their customers, certainly not with my company at least, and the stock quickly recovered, in fact doing very well. For me, it looks like nothing changed, no lessons learned.

Re: The Cloudflare outage might be a good thing

#145

Earlier quoted context omitted.

Have you tried that? I gave up on hosting my own email server seven or eight years ago, after it became clear that there would be an endless fight with various entities to accept my mail. Hosting a webserver without the expectation that you'll need some high powered DDOS defense seems naive, in the current day, and good luck doing that with a server or two.

I have never hosted my own email. It took me roughly a day to set it up on a vanilla FreeBSD install running on Vultr’s free tier plan and it has been running flawlessly for nearly a year. I did not use AI at all, just the FreeBSD, Postfix, and Dovecot’s handbooks. I do have a fair bit of Linux admin and development experience but all in all this has been a weirdly painless experience. If you don’t love this approach…

I ran my own mail server from 1998 through 2019, and set up a FreeBSD mail server as one of my first contract jobs in 1998 or 1999. I used Sendmail, Exim, Postfix, and qmail at various times. I switched to mail-in-a-box in 2014, and contributed a few minor fixes, then (which I'd forgotten about until I idly looked to see, just now).

Throughout 20 years of running my own mail server for companies, friends, and myself, the additional effort to get commercially-run mail servers to accept mail was both annoying and random ("oh, look, hosted Outlook has started rejecting our mail again..."), and sometimes they don't even send a standard response but just "accept" and blackhole the email. Eventually you find out that someone else in the /24 you're in at Rackspace or DigitalOcean is happily running an open relay, and that's why your IP is having problems. Or any of a dozen similar things.

In 2019, having gotten very tired of this, I gave up and moved my mail handling to Amazon Workmail and SMS, and after setting it up properly once, it's been trouble-free and maintenance-free for half a decade. Compared to some solutions, it's expensive, but not in absolute terms.

Re: The Cloudflare outage might be a good thing

#146
post #121

Earlier quoted context omitted.

> bad actors will spoof their location Isn't that exactly the point? Why are North Korean hackers even allowed to connect to the service, and why is spoofing location still so easy and unverifiable? Nobody is expected to personally secure their physical location against hostile state actors. My office is not artillery proof, nor does it need to be: hostile actions against it would be an act of war and we have the mil…

> Why are North Korean hackers even allowed to connect to the service, Asking why some group is “allowed” to use the internet is equivalent to demanding either strict verification or that we cut off some entire country where they reside from the entire internet. Either that, or someone doesn’t understand basic fundamentals of networking and thinks there’s some magic solution to this problem. A common variation of thi…

It wouldn't surprise me at all if mandatory online ID verification will become a thing within the next century or so.

Re: The Cloudflare outage might be a good thing

#147
post #34

I wonder what would life without cloudflare look like? What practices would fill the gaps if a company didn't - or wasn't allowed to -- satisfy the the concerns that cloudflare fills.

Pretty much exactly like it does now but with less captchas. Fun fact: Headless browsers can easily pass cloudflare captchas automatically. They're not actually captchaing - they're just a placebo. You just need to be coming from a residential IP address and using a real browser.

> Pretty much exactly like it does now but with less captchas.

This just isn't true. e.g. I saw a 30x increase in traffic on my forum due to AI bots that I had to use CF to block.

CF is mainly empowered by the naive ideals of the internet's design that never built-in countermeasures against bad actors. You're expected to just deal with it yourself somehow. And that means outsourcing it, especially as residential IP address botnets on unlimited ISP data plans become cheaper and cheaper.

Just ask yourself why web hosting providers themselves can't offer services at CF's level. It's because it's too hard of a problem even for them.

Re: The Cloudflare outage might be a good thing

#148
post #121

Earlier quoted context omitted.

> bad actors will spoof their location Isn't that exactly the point? Why are North Korean hackers even allowed to connect to the service, and why is spoofing location still so easy and unverifiable? Nobody is expected to personally secure their physical location against hostile state actors. My office is not artillery proof, nor does it need to be: hostile actions against it would be an act of war and we have the mil…

you can as easily get attackers from within your own networks, you're falling for fallacy that everything on the 'inside' is secure.

Just because one group of attackers is (/might be) inside your network doesn't mean you also have to let all other groups in. There is zero reason to let (say) North Koreans interact with your gas pump API, other than that the internet is set up so that it is virtually impossible to prevent unfriendly parties from contacting your servers.

Re: The Cloudflare outage might be a good thing

#149
post #10

It would be a good thing, if it would cause anything to change. It obviously won't. As if a single person reading this post wasn't aware that the Internet is centralized, and couldn't name specifically a few sources of centralization (Cloudflare, AWS, Gmail, Github). As if it's the first time this happens. As if after the last time AWS failed (or the one before that, or one before…) anybody stopped using AWS. As if a…

I’m pretty cloudflare centric. I didn’t start that way. I had services spread out for redundancy. It was a huge pain. Then bots got even more aggressive than usual. I asked why I kept doing this to myself and finally decided my time was worth recapturing.

Did everything become inaccessible the last outage? Yep. Weighed against the time it saves me throughout the year I call it a wash. No plans to move.

Re: The Cloudflare outage might be a good thing

#150
post #143
post #10

It would be a good thing, if it would cause anything to change. It obviously won't. As if a single person reading this post wasn't aware that the Internet is centralized, and couldn't name specifically a few sources of centralization (Cloudflare, AWS, Gmail, Github). As if it's the first time this happens. As if after the last time AWS failed (or the one before that, or one before…) anybody stopped using AWS. As if a…

Same idea with the Crowdstrike bug, it seems like it didn't have much of on effect on their customers, certainly not with my company at least, and the stock quickly recovered, in fact doing very well. For me, it looks like nothing changed, no lessons learned.

what do you mean no lesson learned? seems like you haven't been paying attention..there's always a lesson learned
Post reply on HN