Live data from Hacker News

Thoughts on Cloudflare

xn--gckvb8fzb.com

21–30 of 88 posts

Re: Thoughts on Cloudflare

#21
I use cloudflare on my sites because my servers does not have IPv4.

If the all the ISPs can get the their networking knowledge up-to-date I can remove it.

I have set the protection level to the lowest setting to not trigger unnecessary capatchs.

Re: Thoughts on Cloudflare

#23
post #19

Very good post. Cloudflare is continuously adding services to their cloud offerings (the latest being Email delivery) in a familiar pattern of "let's make it impossible to switch".

I don’t see a problem with a company continuing to make useful products. Email delivery was a pretty logical next step for Cloudflare.

Re: Thoughts on Cloudflare

#24
post #19

Very good post. Cloudflare is continuously adding services to their cloud offerings (the latest being Email delivery) in a familiar pattern of "let's make it impossible to switch".

I don’t see a problem with a company continuing to make useful products. Email delivery was a pretty logical next step for Cloudflare.

relevant username

Re: Thoughts on Cloudflare

#25
post #5

It's pretty disappointing that the author (writing in 2025) says "perhaps to maintain its status as the world’s largest botnet operator," and links to a Spamhaus report from Q1 of 2020.[0] If you check the most recent version of the report from Spamhaus (Jan to June 2025)[1], Cloudflare is nowhere to be seen, and Digital Ocean, who they recommend as a Cloudflare alternative is listed as third largest botnet host in t…

It is sad. The post could be a paragraph of basically ending with negative attributes of oligo and mono polies. Which are what should be evaded.

Other than that, alternatives do not go far as cloudflare does. If you experience a heavy DDOS, either you bankrupt with a large invoice or you suffer heavy outage.

I do not understand why this primary service misses to be listed. Nobody in the planet offers DDOS free, especially to news agencies at their difficult times.

Re: Thoughts on Cloudflare

#26
post #7

If it wasn't on HN, being upvoted by some, I wouldn't have clicked on the link judging from the domain name. Turns out it is unicode issues. I wonder if HN will ever fix it.

[deleted]

Re: Thoughts on Cloudflare

#27

Author did a surprisingly good job hanging on to all the receipts to support his claim "cloudflare bad." But his alternatives are all CDN providers - which is not even the side of the business that makes cloudflare unique and makes them money. The piece, thorough as it may be, does not offer alternatives to products that cover the exciting parts of their business and I was looking forward to seeing what those were -…

The Internet runs at the will of the government(s). Every government (national, regional, local) has regulations that must be obeyed. Depending upon where you live, some of those regulations may be kept secret from those most affected. An entity like Cloudflare is a juicy target that can be used cooperatively, or abused uncooperatively by those enforcing the regulations. So Cloudflare has solved one problem (DDoS), w…

They already do this for Chinese traffic. They send traffic from China to Alibaba controlled infrastructure.

Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba.

And I would not be surprised if they were abusing their middlebox position to do all kinds of surveillance based on secret "warrants" in other places.

Re: Thoughts on Cloudflare

#28

> Cloudflare has become a highly attractive target for state-sponsored attacks, suffering from recurring breaches. Their sheer scale, considering that they are serving a substantial portion of the internet, means that an outage or compromise could have widespread, costly consequences. I'm unsure how much of these can actually be called "attacks" rather than "complying with local laws" that lets them operate in a lot…

“complying with local laws” isn’t always a good thing. Here’s some behaviours that you need to report in some countries in order to comply with local laws:

* someone is a homosexual * someone had sex out of wedlock * someone is a communist * someone is right-wing * someone is a Muslim * someone is _not_ a Muslim * someone spoke ill of the current ruler * someone hosted a messaging service, and didn’t ask users for a copy of their id

Re: Thoughts on Cloudflare

#29
post #19

Very good post. Cloudflare is continuously adding services to their cloud offerings (the latest being Email delivery) in a familiar pattern of "let's make it impossible to switch".

I'm currently on my Nth run of:

- I want to deploy a tiny service for personal use

- That has occasional requests (think ~10 a day)

- Needs to respond to a few daily events: a CRON job here and there, read an email, webhooks... Think a simpler Zapier

In principle this would be perfect for any of the many cloud function providers.

But AFAIK all of them have this vendor lock-in built into their business model and I just refuse to cave in.

Is there anything that I can do to not lock myself into an edge-computing ecosystem (or whatever this is called in the provider of choice) and still get the benefits? Is there any provider that supports any standard that is not tied specifically to their offering?

Re: Thoughts on Cloudflare

#30
What we really need is more IPV6 deployment so normal people can have plenty of routable addresses and we can go back to hosting more things on the edges like we used to, on computers we physically control.

There are plenty of applications where the bandwidth of PON fiber commonly deployed to homes is more than sufficient, and the extra latency is irrelevant.

Sure, it may be susceptible to DDoS attack, but if tens of millions of people were running personal and business systems from home it's debatable this would be less resistant than having a few centralized companies own us all.

Post reply on HN