Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

251–260 of 483 posts

Re: Cloudflare took down our website

#251

Earlier quoted context omitted.

She did say that she didn't bring in any customers...

She did say she was around for only 6 months and enterprise sales cycles can last 12+. Though I guess if you’re engaging in scammy behavior it can be much less… maybe she wasn’t willing to do that.

Sorry, but if you‘re onboarded in a Sales Team you‘re at first getting small fry customers to get used to your Job. Cloudflare is massive and a complete no-brainer for 95% of companies. Not only that, she couldn‘t even land a single enterprise upcharge. Cold calls are hard, but upsells are much easier because companies are pretty much vendor locked with CF.

If you can‘t land a single customer in 6 months under these circumstances, you‘re likely just not a good fit.

Re: Cloudflare took down our website

#252
post #189

Can any1 explain how HN algo works that this post, which at time of writing has 355p, 180comments while being posted 1 hour ago, isn't even on first page (ranked 31)???

if you check sites that track HN's rankings, it was ranked #1 for a while, then it suddenly dropped to #27 and continued declining https://hnrankings.info/40481808/

Re: Cloudflare took down our website

#253

I will remind HNers: is Cloudflare not the company that leaked sensitive data through cache files that were indexed by at least Google, and when the tech community were up in arms about the massive leakage of sensitive data, the CEO’s strategy was to turn up here and criticise Google for not deindexing quickly enough? You get what you pay for.

I remember them criticising Google for not being faster at removing cached files. I don't remember them blaming Google for their screw up. And let's be honest, if a big provider wants to offer cached versions of pages, they probably should have a way to purge those files in case there's a problem (eg: malware).

> I don't remember them blaming Google for their screw up.

You're putting words into my mouth.

Re: Cloudflare took down our website

#254
post #108

From personal experience I know that 10TB per month is like 30k/year and SSL for SaaS is around 40k/year on the enterprise plan. No idea about pricing for having your own IP. I have no idea why Cloudflare would ask you to use these two features. SSL for SaaS is only useful if you want to add domains and certificates via API. I have had my fair share of negative experience with Cloudflare but this is next level bad. U…

From personal experience I know that 10TB per month is like 30k/year What the hell? That's way more than AWS costs, 90% of which would be egress fees. And cloudflare has done a lot of marketing to rightfully call out those egress fees as far too high.

It's the whole enterprise plan, you can't only buy traffic. So you also get all the features which you don't need or want as you can see from the screenshota shared in the original post.

Even on the enterprise plan they don't really start to talk to you about traffic until you are like 3x over your contracted traffic for a couple of months.

It sucks, it feels like they are competing against themselves because they don't have clear pricing or limits.

Re: Cloudflare took down our website

#255

As far as I can tell, the issue with this is: OP runs a casino/gambling site. Gambling is a regulatory mess (I have spent far too long dealing with this as an RNG supplier), and so it's very hard to comply with every jurisdiction, and each one needs you to prove compliance to operate in that jurisdiction.* Gaming companies spend a lot on compliance and tracking, but since the internet is the internet, it's pretty har…

BYOIP is reasonable, though I doubt anyone actually does legislation blocks by IP. Since like half of companies on the internet use Cloudflare or other multi-tenant infrastructure everyone is aware that you can't block an IP address and hit one target. The only thing I've seen is DNS blocks (both DNS protocol directly and based on TLS SNI). FYI, we also fully block users from the US (due to regulations). My problem h…

You would be surprised how big of a hammer ISPs will use when they are told to hit something. They live in a very different world than many modern web software companies - they are the plumbers for lots of things you take for granted, and look at the world the way a plumber does. Thanks to TLS, the plumbers can't see the HTTP headers to figure out what's actually flowing, so they sort of end up whacking all of it.

Generally, low-reputation IP addresses are associated with scams, spammers, and other similar things. Gaming somehow gets lumped into this bucket in some jurisdictions, but that hurts you worldwide (similar with other "sin businesses" like porn). These blacklists get published (I think there's some parts of BGP that make this happen, but I'm not quite sure what the mechanism is), and being on any one of them hurts your traffic everywhere because it becomes suspect.

I agree with you that this mix of compliance, engineering, and sales is gross. If this was the issue, they should have just told the OP.

Re: Cloudflare took down our website

#257

Meta: 455 points, 3hrs old, but on the 2nd page of HN. What's up with the algo?

I'm not sure. It was on spot one on the first page, then something happened and it got downranked: https://hnrankings.info/40481808/ maybe due to being flagged by people (according to another comment).

I guess it's due to general negative sentiment towards casinos, which may be understandable but doesn't (in my biased opinion) change anything about CF's behaviour in this post. I would have left it out but it's necessary in order to provide the full context.

Re: Cloudflare took down our website

#258
post #227

Earlier quoted context omitted.

It's not just 10k a month. it's 10k a month for the plan that allows you to BYOIP (Bring your own IP addresses). That was cloudflare's issue. Their business was causing IP reputation damage and all plans but the enterprise BYOIP plans share the same IP pool. Essentially it was "use your own IP pool and pay us for the cost of maintaining that pool for you or GTFO". This wasn't just a normal sales rep hitting them up.…

> So this really should be seen as an act of goodwill rather than malice. It's called "extortion"

It's not extortion if you would have been banned off the platform flat out had you been a smaller account.

Re: Cloudflare took down our website

#259
post #85

We had a site hosted on CF business plan with fairly large bandwidth usage (completely legal, had a lot of media). They approached us with an enterprise plan but we did not have the budget for it. Asked for a little time, they said fine and we moved much of the bandwidth usage to a couple of dedicated servers on OVH I think. Never heard from them after that.

How do you deal with DDoS attacks against said OVH servers?

> By default, every OVHcloud product is supported by the Anti-DDoS infrastructure to defend against malicious activity. https://us.ovhcloud.com/security/anti-ddos/
Post reply on HN