Do not put your site behind Cloudflare if you don't need to
301–310 of 391 posts
Re: Do not put your site behind Cloudflare if you don't need to
#302Earlier quoted context omitted.
Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.
> Cloudflare is mostly used for anonymity and privacy, not for scale I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.
Re: Do not put your site behind Cloudflare if you don't need to
#303The problem is, we need to. It’s simply insane how many stupid, malicious requests we get without it, and we honestly are a small, unimportant site. If we don’t filter all this crap out, our metrics become basically meaningless, and our Data Warehouse, whose analyses we need to do business with our partners, would be one big „shit in, shit out“ travesty. And on the other hand, becoming non-affected by today’s Cloudfl…
> becoming non-affected by today’s Cloudflare incident was a single DNS update away Except you've now leaked your origin IP so expect increased junk being pointed straight at it. Sure you can firewall it off but even dropping packets burns CPU.
Re: Do not put your site behind Cloudflare if you don't need to
#304Running behind something like Cloudflare doesn't just protect against DDoS, it protects against surprise traffic spikes.
If your site ends up on the Hacker News frontpage it's nice for it not to fall over right as people are trying to check it out.
Re: Do not put your site behind Cloudflare if you don't need to
#305Re: Do not put your site behind Cloudflare if you don't need to
#306Earlier quoted context omitted.
My hoster wouldn't take me down though. Instead it will protect me for free: https://www.hetzner.com/unternehmen/ddos-schutz
this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.
Especially when you are facing "infected machines by the millions".
Re: Do not put your site behind Cloudflare if you don't need to
#307Earlier quoted context omitted.
If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?
> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…
In Russia (I have nothing against Russia - I just know this info about “Дождь ТВ”), some news websites have been targeted by state-baked DDoS attacks, but I highly doubt most people are in this category.
Re: Do not put your site behind Cloudflare if you don't need to
#308Let's assume that i could easily use multiple CDNs/proxies and put them all in my DNS record. It would be nice if web browsers would use happy-eyeballs like logic to switch between multiple IP addresses, but i don't think this is default behavior with multiple A/AAAA records.
Re: Do not put your site behind Cloudflare if you don't need to
#309Earlier quoted context omitted.
What’s the cost of making the internet more centralised because of sheer laziness?
Do you think most people who want to start a blog are thinking about the centralization of internet services?
First, let's stop perpetuating this destructive meme that running nginx on a VPS is rocket science, and fraught with peril; at least not on a forum of so-called hackers.
Re: Do not put your site behind Cloudflare if you don't need to
#310> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
Genuinely I don't understand how people post under their own name or connect their accounts to their real identities at all. I learned early that my opinion can piss people off (even though I think I'm pretty milquetoast to be honest), and there are people with enough time and hate to make their disagreement with you impact you personally. I started using a pseudonym about the time my consulting site got taken down b…