Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

241–250 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#241
post #155

Earlier quoted context omitted.

I need SponsorBlock for HN, this is ridiculous.

There are two companies on HN which get massive amounts of support from poster fanboys - cloudflare and tailscale. It used to be apple.

The tides are turning against CF it seems.. they used to have a lot of HN support, but lately every thread about them is just a mess of MITM accusations and "too much of the internet is behind them".

Re: Do not put your site behind Cloudflare if you don't need to

#243
post #237
post #235

Earlier quoted context omitted.

“Hundreds of concurrent requests…” Back in 2001/2002 my personal website was “slashdotted” several times… … which I learned about after the fact by seeing myself on slashdot. It was not noticeable as it occurred and my services were not impacted. So perhaps you need a p3-500 with 64 megabytes of ram and Apache 1.x and an old copy of cgi-lib.pl ?

Concurrent and constant. This is nothing like real traffic, nothing like the good old hug of death. It seems to find the slowest endpoints (well it does like my search and category pages, but sometimes it really hammers a single page for an hour), builds up until your site goes into its knees and instead of going slower it starts to hammer from other IP ranges until you have them all banned. This can go on for hours…

Genuinely curious: Do you run this on single tenant hardware that you own ?

Re: Do not put your site behind Cloudflare if you don't need to

#244
post #155

Earlier quoted context omitted.

I need SponsorBlock for HN, this is ridiculous.

I don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog. It's not because it's not a criticism that it's a sponsored post. I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without: - First…

There's no CF magic here. If you're improving from 0.4s to 8.9s that means you're not doing basic caching on your side and you could achieve this in your local nginx/whatever as well. The 0.3s saving on first paint is nice, but could be achieved with putting your assets in any kind of distributed provider, not just CF.

Re: Do not put your site behind Cloudflare if you don't need to

#245
post #46

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

Then who cares if your site is down for a few hours once in a blue moon because the auxiliary service in front of it is down?

Re: Do not put your site behind Cloudflare if you don't need to

#247
post #225

Earlier quoted context omitted.

I don't give a penny to CloudFlare to be clear, and I would definitely not pay for those services for my blog. It's not because it's not a criticism that it's a sponsored post. I happen to have multiple sites that use the same technology (WordPress, with the same few plugins and the same theme) running on the same server, with one behind CloudFlare and one not. Left value is with CloudFlare, right is without: - First…

Sure, but your post reads like an infomercial, hence the snark. NARRATOR: - "Has THIS ever happened to you?" CUT TO: Black-and-white. Some guy stares in frustration and confusion at a terminal. Output of 'cat /usr/bin/gcc | xxd' or whatever scroll by. NARRATOR: - "Introducing CloudFlare™!" CUT TO: Full color. Sunlight. The same guy now sprawled on grass at a park. Two dogs tackle him with adoration. His kids hand him…

That's a lot of projection. They are just sharing their experience. Anecdotes are not ads for something.

Re: Do not put your site behind Cloudflare if you don't need to

#248
post #83

Earlier quoted context omitted.

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

What’s the cost of making the internet more centralised because of sheer laziness?

The famously decentralized internet. AWS, Azure, CloudFlare, or sea cables getting damaged never impact service. Right? /s

Re: Do not put your site behind Cloudflare if you don't need to

#249

Earlier quoted context omitted.

What's the cost for someone to put their blog behind cloudflare, besides a few minutes of setup?

Remember if it costs nothing, you’re the product.

And if you pay for it, you're still the product. This false notion of Paying = Better is driven entirely by profit seeking companies who want you to pay them for access and then they want to get paid for showing you ads as well.

Re: Do not put your site behind Cloudflare if you don't need to

#250
post #167

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.
Post reply on HN