Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

251–260 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#251

Earlier quoted context omitted.

Remember if it costs nothing, you’re the product.

And if you pay for it, you're still the product. This false notion of Paying = Better is driven entirely by profit seeking companies who want you to pay them for access and then they want to get paid for showing you ads as well.

Oh sure - I mean, bmw heated seats anyone? But even there you’re still not the product, you’re captive audience that might put up with that kind of abuse because of sunken cost fallacy and all that.

Re: Do not put your site behind Cloudflare if you don't need to

#253
Clearly there is plenty of DDOS capacity out there so your argument is invalid. One ten millionth of the current traffic would be enough to bring a small blog or service down.

Also if you aren’t practiced at diagnosing a DDOS or if your monitoring is not tuned for it, diagnosing it can be supremely difficult. Answering as someone who has successfully diagnosed ddos at 11pm on a Sunday night without access to the logs or monitors (mostly because the necessary monitoring did not exist)

And I could only do that because I had a decade of experience and I had the clarity of emotional distance (not my site, not my server, not my fault).

Re: Do not put your site behind Cloudflare if you don't need to

#254
post #167

Earlier quoted context omitted.

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.

evidence?

Re: Do not put your site behind Cloudflare if you don't need to

#256
post #46

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

I mean I'm not worried about it either, but I've been on the internet long enough that I know some of the people I used to know will probably do it just to do it. Gamers can be quite toxic.

Re: Do not put your site behind Cloudflare if you don't need to

#257
post #243
post #237

Earlier quoted context omitted.

Concurrent and constant. This is nothing like real traffic, nothing like the good old hug of death. It seems to find the slowest endpoints (well it does like my search and category pages, but sometimes it really hammers a single page for an hour), builds up until your site goes into its knees and instead of going slower it starts to hammer from other IP ranges until you have them all banned. This can go on for hours…

Genuinely curious: Do you run this on single tenant hardware that you own ?

No, it's several virtual server mostly because simplicity and I sleep better at night :)

Re: Do not put your site behind Cloudflare if you don't need to

#258

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#259

Earlier quoted context omitted.

This isn't true for paid services with a free tier

Nah, the cliche still applies there as well.

No it really doesn't. How are you the product when Cloudflare gives you free tier access? That's not their business model. You aren't the product, but you are an upsell lead for the sales team.

Re: Do not put your site behind Cloudflare if you don't need to

#260

Earlier quoted context omitted.

> These are very different situations. It is obvious those two are very different situations. I'm not sure I understand your point. Yeah, nobody will be bothered by a short 15 minute DDoS attack. I prolly wouldn't even notice it unless I'm actively checking the logs. Sure, nobody is going to be bothered by that. But what if someone's DDoSing persistently with a purpose? Maybe they're just pissed at you. My point is..…

> a sustained DDoS attack will just make your host drop you I'd love to see someone suing the host for damages. The contract binds them as much as it binds you. Sounds like a good way to have your next gaming rig financed.

I'm pretty sure in every webhost terms of service I've ever read they leave language in to kick you out if you are degrading the service for others. Turns out a prolonged DDoS attack is degrading the service for others. The bigger cloud providers are drastically less likely to drop you but now you're paying a premium on hosting.
Post reply on HN