Live data from Hacker News

Cloudflare Email Service: private beta

blog.cloudflare.com

311–320 of 578 posts

Re: Cloudflare Email Service: private beta

#311

Earlier quoted context omitted.

For registering/authenticating to service, SMS mostly. Same deal in Russia in my experience, basically every website/service signup asks for your mobile number and just texts verification codes.

So smart-phone is required for everything there? No computer flows for website access? "We" definitely don't want that... but many others do as it takes control away from people.

No, any kind of phone that can receive codes over SMS will work (like the ultra-cheap feature phones you can probably get at your local corner store). From a computer browser, you still enter your mobile number to login, then enter the verification code it sends you over SMS. I've also seen sites that offer phone call as an alternative to SMS, so you can presumably also login from a landline.

Re: Cloudflare Email Service: private beta

#312

Earlier quoted context omitted.

I don't know what kind of internet you used but mine didn't randomly decide to block my access to a website because some quasi monopolist decided I wasn't allowed to use a certain website for intransparent reasons.

Being blocked from a web site and having to hit a little box are two different things. Are you talking about the former or the latter? If it's the former ... that has literally never happened to me unless I'm on a VPN and even then it's rarely (if ever) CF that's doing the blocking. If it's the latter then it reflects the sad truth that we can't have nice things anymoret. I have lots of problems with the accessibilit…

> never happened to me

"Never happens to me means never happens to anyone"

Also it's quite amusing what if you had got hit with an infinite captcha here then you couldn't post your comment.

Re: Cloudflare Email Service: private beta

#313

Earlier quoted context omitted.

So smart-phone is required for everything there? No computer flows for website access? "We" definitely don't want that... but many others do as it takes control away from people.

For just SMS authentication, you just need a phone. Any kind of phone. But it also just so happens that in both of those countries, you must have your identity attached to any SIM you purchase. So, anything that makes you register with your phone number will indirectly link your real identity to that registration. It must be very convenient for their governments!

[deleted]

Re: Cloudflare Email Service: private beta

#314

Earlier quoted context omitted.

You will still be required to hand it over, or sit in jail while your confiscated, inventoried equipment is processed by forensics. If I want to be subpoena proof, I’d host the subject system outside the jurisdiction with an org having no connection or nexus in the adversary jurisdiction. Admittedly, this is up to your threat model. Do you want to know, but still be legally required to provide access? Or do you want…

I don't mind being warranted, if they come to the door with warrant I will give them my boring, pedestrian inbox but I do mind my data being drag-netted, or hoovered up by scummy big tech and then sold on (whether that's for slop training, ads, anything really)

Why do you mind that? Your life is exactly the same one way or another. Principles, I guess, but it looks to me its just for the sake of it. For me, time is precious, all I need is data safety so I backup stuff offline constantly.

Re: Cloudflare Email Service: private beta

#315

Earlier quoted context omitted.

I don't know what kind of internet you used but mine didn't randomly decide to block my access to a website because some quasi monopolist decided I wasn't allowed to use a certain website for intransparent reasons.

Being blocked from a web site and having to hit a little box are two different things. Are you talking about the former or the latter? If it's the former ... that has literally never happened to me unless I'm on a VPN and even then it's rarely (if ever) CF that's doing the blocking. If it's the latter then it reflects the sad truth that we can't have nice things anymoret. I have lots of problems with the accessibilit…

I can’t book a table at a local restaurant without calling because their resy link is behind Cloudflare and Cloudflare has decided that my up-to-date Firefox is out of date and therefore can’t pass the challenge. In reality it’s more likely that one of my ad blockers is stopping it from doing what it wants. It doesn’t even let me hit the box.

Re: Cloudflare Email Service: private beta

#316
post #247

> Today, we're excited to announce just that: the private beta of Email Sending, a new capability that allows you to send transactional emails directly from Cloudflare Workers. So many comments here assumed from the title they're offering a hosted email service, they aren't, they are announcing their own Sendgrid.

What’s the point of it for Cloudflare? It feels like they’re randomly offering different products. Are they trying to be a full cloud platform like everyone else? If not, then what?

> Are they trying to be a full cloud platform like everyone else?

Yes.

Re: Cloudflare Email Service: private beta

#317
post #175

Earlier quoted context omitted.

As a website owner who uses Cloudflare after having being DDOS'd, I agree whole heartedly. Cloudflare succeeded to do what Google tried and failed with AMP, and we are all the worse off for it. [Though at least it is not Google, that would be worse.] I cannot afford to be DDOS'ed and there are bad actors that have already proven that they _will_ take me down if they could. So, I feel bad for the internet being walled…

What was your infrastructure like? Were the DDoSes affecting you at the application or network layer? I wonder if there's the case to be made for something like CF but integrated into your L4 and L7 LB infrastructure.

CFs single biggest piece of leverage on L7 DDoS is that once a node in a botnet attacks one of their properties, it usually can’t be used to attack any others for a substantial duration. Botnets rely on being retasked frequently so this dramatically reduces their effectiveness. Volumetric DDoS is even worse: you need to have the peering relationships and hardware to handle Tbps of traffic to an IP you announce. Doing either of these in your own infra is not feasible if you’re much smaller than a hyperscaler.

Re: Cloudflare Email Service: private beta

#318
post #292

Earlier quoted context omitted.

I can't imagine what a court case about whether the US president has the power to unilaterally dismiss officials in executive-branch agencies could possibly have to do with this. At least you're referencing the United States in 1934, though. Things were very dysfunctional politically in the US at that time, but not nearly as bad as what was going on in some other parts of the world.

> can't imagine what a court case about whether the US president has the power to unilaterally dismiss officials in executive-branch agencies could possibly have to do with this Seriously? You don't see the relevance of independent agencies to this discussion?

No.

And the dynamics of inter-branch checks and balances within the US federal government aren't directly relevant to the question of whether the federal government as a whole is a reliable institution in the first place (nb: it isn't).

Re: Cloudflare Email Service: private beta

#319
post #4

Eventually all Internet protocols will be MITMed by cloudflare. Your single point of interception!

I think first they were hugely successful in their DDoS protection product that consisted of a DNS connected load balancer.

But now they took the excuse of security to act as a MiTM for everything else, when conveniently, it makes for a great business model to just be slapped in the middle of every connection.

Re: Cloudflare Email Service: private beta

#320
post #4

Eventually all Internet protocols will be MITMed by cloudflare. Your single point of interception!

I’ve never understood the evil MITM endgame here. Cloudflare’s ToS and contracts prevent them from doing nastiness with your data without breach, and approximately all their revenue comes from large enterprises that will leave in droves (and some will actually sue them) if they started exploiting it.

The thing where they let DDoSers use them to protect their public sites from rival DDoSers is sketchy as hell, but doesn’t rely on having your data.

Post reply on HN