Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

291–300 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#291
I ran a highly trafficked adult website for 18 years. In the early days, CDNs were unattainable for me and I managed my own rudimentary network by hosting bare metal servers in data centres around the world, using geo-ip aware DNS servers to send traffic to the closest data centre to them.

My most significant running expense was bandwidth cost. So I never switched to cloud since the bandwidth costs would have instantly bankrupted me. Cloudflare, on the other hand, was the single most significant development when it came to my bottom line. Adding a basic, $200 / month business account saved me thousands per month on bandwidth + server costs.

DDoS protection was just a nice perk.

Most small websites are hosting with cloud providers these days. If their websites are at all media rich (and most are these days), and those assets can be cached by a CDN ... the cost savings on bandwidth are not marginal. They are often the difference between being able to afford to host your website or not having one at all.

There are, of course, ways to optimize and reduce those expenses without a 3rd party CDN. But if Cloudflare still has their free plans for smaller traffic volumes, it is often a financial decision to use them over your cloud provider's CDN options.

Re: Do not put your site behind Cloudflare if you don't need to

#292
The problem is, we need to. It’s simply insane how many stupid, malicious requests we get without it, and we honestly are a small, unimportant site.

If we don’t filter all this crap out, our metrics become basically meaningless, and our Data Warehouse, whose analyses we need to do business with our partners, would be one big „shit in, shit out“ travesty.

And on the other hand, becoming non-affected by today’s Cloudflare incident was a single DNS update away, and effective in under a minute.

I’m not saying we are perfectly happy, and I don’t exactly love the Cloudflare bill, but just slapping them in front of our loadbalancer and have them filter out the bad guys has been a good deal so far.

Re: Do not put your site behind Cloudflare if you don't need to

#293
post #269

Earlier quoted context omitted.

If you can move off of CDNs then you're not in a world where all personal blogs are centralized.

And thus, the lemmings walk straight off the cliff. There seems to be two views. One forward looking and one not. The forward looking view appropriate recognizes the threat of centralization. Centralization crushes small businesses (and small blogs), leads to censorship (see youtube et al.), and destroys competition. No one on the planet can compete with cloudflare pound for pound and thus if they decide your site is…

I'm amazed at the responses saying something like, "It's great because when you go down, you can point to the BBC and say, it's not our fault, everyone is down." That should be the clue that this gives them enormous power. It's also bad for overall resilience. Better that businesses go offline more often in an uncorrelated manner, than go offline less frequently but simultaneously. I guess it's great if all you care about is not catching blame.

Re: Do not put your site behind Cloudflare if you don't need to

#294

The problem is, we need to. It’s simply insane how many stupid, malicious requests we get without it, and we honestly are a small, unimportant site. If we don’t filter all this crap out, our metrics become basically meaningless, and our Data Warehouse, whose analyses we need to do business with our partners, would be one big „shit in, shit out“ travesty. And on the other hand, becoming non-affected by today’s Cloudfl…

> becoming non-affected by today’s Cloudflare incident was a single DNS update away

Except you've now leaked your origin IP so expect increased junk being pointed straight at it. Sure you can firewall it off but even dropping packets burns CPU.

Re: Do not put your site behind Cloudflare if you don't need to

#295
The massive centralisation going through cloudflare, especially their dns, is good reason to reconsider using them. It doesn't matter how good their product or ethos is, 10s of %s of the Internet traffic going through one company is a bad thing for the Internet.

Re: Do not put your site behind Cloudflare if you don't need to

#296
post #118

Earlier quoted context omitted.

You think someone would DDoS you because you made a comment like this on HN? Seems a bit overly cautious.

Do providers offering VPS have a layer of protection against such attacks? It might overwhelm their routers etc too?

many VPS providers want to get rid of you if you're on receiving end of the attacks as well. since you threaten the stability of their operations.

Re: Do not put your site behind Cloudflare if you don't need to

#297
post #254

Earlier quoted context omitted.

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.

evidence?

Handled hundred of dedicated servers for different projects over the last 20 years. Yes, OVH literally does ban accounts, and Hetzner nullroute your service at first if it's an elaborated attack.

Re: Do not put your site behind Cloudflare if you don't need to

#298

I administer a PHP website with very little legit traffic per month, but a few thousand pages probably. The bot traffic is crazy. We're not using Cloudflare for that site, but we're using a local static-page cache... and without it, the site simply can't function. You don't need to be the target of a dDoS to use a CDN. Also, using CDNs (Fastly via Github pages, not Cloudflare, in this case) once allowed us to be feat…

Simply put, in order for moving off of Cloudflare (or similar) to be practical, bot and scraper traffic is going to have to be reigned in heavily.

Getting bots under control would be better for the health of the web anyway, but the chances of that happening are practically zero. Even if the AI bubble collapses entirely, there's still going to be loads of ill-behaved scrapers and exploit sniffers roaming about.

I don't know if it's possible to fix this issue, short of the entire world enacting strict regulations mandating that scrapers and bots be well-behaved, which is never going to happen and even if it did could end up being just as or more destructive than rogue bots.

Re: Do not put your site behind Cloudflare if you don't need to

#299
post #167

Earlier quoted context omitted.

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

that's ddos protection....

Re: Do not put your site behind Cloudflare if you don't need to

#300
post #183

Earlier quoted context omitted.

No its like saying you should buy a new battery after your battery dies. Yeah, its nice to have a spare battery around i guess but its not like your battery dying will significantly ruin your finances

It's more like buying the plug-in version after the battery dies... You already experienced the downtime, so if not having downtime was a goal you already failed. If avoiding downtime is not important then there's no reason to add anti-downtime capability to your system. The most charitable modeling of this approach is that the downtime incident may prompt one to realize that avoiding downtime actually is an importan…

The actual charitable model is that you expect close to zero attacks, but if you actually get hit your expected rate of future attacks goes up by an order of magnitude or two. And it's that change in expectations that gets you to buy protection.

You don't care about going down once, you do care about frequent outages. And you know this from the start, you don't realize it later.

Post reply on HN