Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

301–310 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#302

Earlier quoted context omitted.

Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.

> Cloudflare is mostly used for anonymity and privacy, not for scale I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.

[deleted]

Re: Do not put your site behind Cloudflare if you don't need to

#303
post #294

The problem is, we need to. It’s simply insane how many stupid, malicious requests we get without it, and we honestly are a small, unimportant site. If we don’t filter all this crap out, our metrics become basically meaningless, and our Data Warehouse, whose analyses we need to do business with our partners, would be one big „shit in, shit out“ travesty. And on the other hand, becoming non-affected by today’s Cloudfl…

> becoming non-affected by today’s Cloudflare incident was a single DNS update away Except you've now leaked your origin IP so expect increased junk being pointed straight at it. Sure you can firewall it off but even dropping packets burns CPU.

Of course not, you can point your domain(s) to any Cloudflare competitor.

Re: Do not put your site behind Cloudflare if you don't need to

#304
> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!"

Running behind something like Cloudflare doesn't just protect against DDoS, it protects against surprise traffic spikes.

If your site ends up on the Hacker News frontpage it's nice for it not to fall over right as people are trying to check it out.

Re: Do not put your site behind Cloudflare if you don't need to

#306
post #167

Earlier quoted context omitted.

My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.

Cloudflare will disconnect you from their free plan just as quickly.

Especially when you are facing "infected machines by the millions".

Re: Do not put your site behind Cloudflare if you don't need to

#307
post #46

Earlier quoted context omitted.

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

This is mostly scaremongering, not all hosting providers take your site down just because someone you pissed off decided to DDoS you.

In Russia (I have nothing against Russia - I just know this info about “Дождь ТВ”), some news websites have been targeted by state-baked DDoS attacks, but I highly doubt most people are in this category.

Re: Do not put your site behind Cloudflare if you don't need to

#308
CDNs and reverse proxies are important part of internet infrastructure. Problem here is not that webservers use CloudFlare, but that use only CloudFlare.

Let's assume that i could easily use multiple CDNs/proxies and put them all in my DNS record. It would be nice if web browsers would use happy-eyeballs like logic to switch between multiple IP addresses, but i don't think this is default behavior with multiple A/AAAA records.

Re: Do not put your site behind Cloudflare if you don't need to

#309
post #83

Earlier quoted context omitted.

What’s the cost of making the internet more centralised because of sheer laziness?

Do you think most people who want to start a blog are thinking about the centralization of internet services?

Do I think people who want to do X should have some modicum of morals? Yes I do, but I can't fully blame them when ethics is not taught in most schools, least of all computer sciences.

First, let's stop perpetuating this destructive meme that running nginx on a VPS is rocket science, and fraught with peril; at least not on a forum of so-called hackers.

Re: Do not put your site behind Cloudflare if you don't need to

#310

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Genuinely I don't understand how people post under their own name or connect their accounts to their real identities at all. I learned early that my opinion can piss people off (even though I think I'm pretty milquetoast to be honest), and there are people with enough time and hate to make their disagreement with you impact you personally. I started using a pseudonym about the time my consulting site got taken down b…

A DDoS back then was what, one guy banging F5 on his keyboard for a while?
Post reply on HN