Live data from Hacker News

Cloudflare Adaptive DDoS Protection

blog.cloudflare.com

21–27 of 27 posts

Re: Cloudflare Adaptive DDoS Protection

#21
post #7
post #6

Earlier quoted context omitted.

I am running quite a different browser setup from most regular web users. I am using Firefox with multi-account containers and uBlock Origin enabled, and I also have an OpenVPN client running, the amount of captchas and distrust I receive from Cloudflare (and their customers, unknowingly I suppose) feels disproportionate. It's funny to me that these companies most likely spends a lot of time and energy on how to opti…

CAPTCHAs are going away: https://blog.cloudflare.com/end-cloudflare-captcha/

They have struggled with credential stuffing, captchas were the only way to stop our login pages from being bombarded at one time. They are getting better with it though but I would rather not lose a tool of last resort.

Re: Cloudflare Adaptive DDoS Protection

#22
post #4

Oh good, a new way to break things; sure hope nobody using this expands into new markets or gets a surge of traffic outside of their usual viewers!

Sigh. You don't have to use this. Large companies that want super tailored DDoS protection can. Everyone else can just use our standard DDoS protection which is included with every plan and works: https://blog.cloudflare.com/26m-rps-ddos/

Of course I'm not using it myself. But the other half of that problem is that this will inevitably be another way that cloudflare breaks my experience as a user and I can't opt out of that.

Re: Cloudflare Adaptive DDoS Protection

#25
post #24

These days instead of just spamming data at a site to ddos it, you just spam the twitter account of cloudflare and they drop your site.

What? I don't follow, how do you spam the CloudFlare Twitter account?

The current playbook for when you want to take a site down is to sign up to it and post something illegal like a bomb threat. Then immediately screenshot it and post to Twitter. Have all of your followers retweet the screenshot to the cloudflare twitter account and the company will take down the site quickly.

Doesn’t matter how quickly the sites moderators take your post down. Small site owners are expected to react within seconds while big tech is allowed days.

Re: Cloudflare Adaptive DDoS Protection

#26

These days instead of just spamming data at a site to ddos it, you just spam the twitter account of cloudflare and they drop your site.

Useful contribution, defending a cesspit of hate like Kiwifarm. Or Stormfront. Cloudflares stance is extremely admirable but there should always be a limit. Things like Kiwifarm don't need protection.

Re: Cloudflare Adaptive DDoS Protection

#27
post #26

These days instead of just spamming data at a site to ddos it, you just spam the twitter account of cloudflare and they drop your site.

Useful contribution, defending a cesspit of hate like Kiwifarm. Or Stormfront. Cloudflares stance is extremely admirable but there should always be a limit. Things like Kiwifarm don't need protection.

Infrastructure platforms shouldn't be the deciders of what gets hosted online. Sure, those sites aren't nice places. But I'd much rather have governments take action on them if they are illegal than have CEOs in mega corps decide in combination with the court of twitter.

Services like domain name providers and ddos protection are so essential for putting content online that they should be regulated as utilities. It would be absurd for a power or water company to cut service because they decided something legal but undesirable was happening at a building just because enough people tweeted at them.

There are some services that should be allowed to pick and choose what to provide. A forum like HN or reddit for example is perfectly justified removing whatever they want. If you don't like it, go somewhere else. But once you get to the point where your domain name and phone number are getting canceled, its no longer possible.

Post reply on HN