Live data from Hacker News

Cloudflare S-1

sec.gov

211–220 of 366 posts

Re: Cloudflare S-1

#211
post #202

Earlier quoted context omitted.

My guess: new development-intensive products like the 1.1.1 DNS, Wireguard, WAF etc plus general scaling and growth on one side, and increased competition from established cloud services on the other. After all, if you are already on eg AWS, just using Cloudfront is temptingly easy. (even if bad from a redundancy perspective)

> just using Cloudfront is temptingly easy IMO this is giving way too much credit to AWS

Assuming you’re already integrated on AWS, just using Cloudfront is a lot easier than Cloudflare. You’re likely already using S3, maybe use CloudFormation as well. Then it’s often much more straightforward to use AWS services rather than a third party provider.

Re: Cloudflare S-1

#212
post #149

Earlier quoted context omitted.

Advocation of violence has been unprotected speech since 1940. Have we been living in a dystopia this whole time? People who intentionally oversimplify free-speech endanger it, just like people who intentionally oversimplify capitalism endanger it. There is no hardline ideal, in any context, that works. Ideas must be flexible to the real world, or perish.

It's not that hate speech and violent rhetoric should be tolerated, it's that using the fact that some people say bad things does not justify monitoring all of the internet. Free speech is a right in the US and having an overlord listening to everything you say is obviously dampening on that right.

I think whether "hate speech" falls into that category is a more complicated question, mostly because the term can be applied so broadly, but a handful of specific things have been illegal enough to get pulled from the public internet by law enforcement from the beginning, and I think it's naive to suggest that we don't need a category like that at all. Also, it doesn't require man-in-the-middle attacks or weakening of encryption to find public websites that host illegal content.

Re: Cloudflare S-1

#213
post #65

Finally an IPO I want to buy into. Technical fundamentals matter. Edit: I mean that in the software/service way, not the economical way, in case there was any confusion.

> Technical fundamentals matter. Centralization of the entire internet behind a single entity is a _bad_ thing for people who care about technical fundamentals.

> the entire internet behind a single entity

You're giving CF too much credit. They are very small fish, as it seems from the S-1. But still dangerous because they MITM while operating for free at loss, so don't reuse passwords and logins between sites.

Re: Cloudflare S-1

#214

Earlier quoted context omitted.

Exactly! I don't why Internet folks fall into this trap time and time again! It's probably simply because it is an easy and quick way to tell your boss your website is protected consequences be damned. I can imagine the next Edward Snowden will reveal the intelligence community's direct line into the traffic running over Cloudflare's infrastructure. Cloudflare is providing DNS and HTTPS services on a massive scale wh…

It depends on the topic of discussion. If we are discussing the viability of a company, and trying to project long term success, then this is all good news. If you are discussing whats best for society and how these businesses impact those things, then this could be alarming news.

There's a big shift towards privacy happening now. If Cloudflare came out a decade ago I'd also be in their camp. But the risks are too high and developers are starting to recognize that Cloudflare is far from free and comes with long terms consequences for the health and resiliency of the internet.

I appreciate how they pushed HTTPs widely. But now that's Let's encrypt exists there's no excuse.

Ill also never forgive them for making Tor completely unusable for accessing any normal website. It's almost impossible to pass the security checks and if you do another one is coming once you switch IP. I understand Tor is a niche product but it's an important one for activists and other persecuted people. And it will only continue to grow in importance as the dictators all learn how to do NSA style mass surveillance.

The DDOS stuff if the harder problem to solve and I don't know enough about it to judge the competition's ability to offer it safely and privacy friendly way.

Re: Cloudflare S-1

#215
post #146

Earlier quoted context omitted.

DNS is far from centralized and DDoS protection is something that small websites would have no ability to do on their own. It isn't just a convenience thing, it's a literally-impossible-without-scale thing.

DNS for sites protected by cloudflare are on cloudflare's DNS afaik.

Right but there are plenty of other options for DNS providers.

Re: Cloudflare S-1

#216
post #197
post #181

Earlier quoted context omitted.

DDoS protection is something that small websites should not need. Current circumstances are a sad and unfortunate state of the internet.

Not only that, Cloudflare has helped to ensure that DDoS protection is something that every website needs. Under normal circumstances, all the shady DDoS-as-a-service providers would DDoS each other off the internet and leave everyone else in relative peace. However, Cloudflare kindly provided them all with free, world-class, no-questions-asked DDoS protection to ensure that they could continue operating their busine…

This doesn't make any sense at all. What are you basing it on?

Re: Cloudflare S-1

#217

The free tier of Cloudflare has been really amazing for small to medium websites. It gives you a basically unlimited CDN, SSL, HTTP/2, DDos protection and fast DNS servers with almost 0 effort... for free ... Thus increasing the stability and speed of many web properties that otherwise wouldn't pay for it. I'm afraid this could easily change once the company is public and is under the pressures that come along with i…

You forgot the API! I have my own dynamic DNS with a raspberry and the cloudflare API for instance, it's very useful.

Re: Cloudflare S-1

#218

Earlier quoted context omitted.

Growth will also give return on investment. I'd rather see Cloudflare invest in growth and R&D than give a dividend. They are nowhere near finished growing.

What more would you expect from them? Not looking for an argument, honest question.

They’re getting into some sort of “accelerator VPN” market. They clearly have ambitions to Be The Internet.

Re: Cloudflare S-1

#220
post #216
post #197

Earlier quoted context omitted.

Not only that, Cloudflare has helped to ensure that DDoS protection is something that every website needs. Under normal circumstances, all the shady DDoS-as-a-service providers would DDoS each other off the internet and leave everyone else in relative peace. However, Cloudflare kindly provided them all with free, world-class, no-questions-asked DDoS protection to ensure that they could continue operating their busine…

This doesn't make any sense at all. What are you basing it on?

See for instance https://krebsonsecurity.com/2015/01/spreading-the-disease-an... or more recently https://www.secureworldexpo.com/industry-news/does-cloudflar... - this has been going on for years and is officially permitted by Cloudflare policy. (The reason why these booter services need such good DDoS protection is that knocking the competition offline makes for good business - it's a great demonstration of effectiveness and cuts off their business at the same time. In the pre-Cloudflare era those services were locked in an almost continual war against each other.)
Post reply on HN