Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

321–330 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#321
post #317

Earlier quoted context omitted.

That's a good analogy since the corner shop is going to be sold out of their small stock of umbrellas during the rain storm so you won't be able to buy one until the rainstorm is over but at least you'll have protection for the next storm. If staying dry is important to you, you should buy the umbrella before the rain.

Not if you live in a desert, which most blogs do.

That continues the analogy -- it doesn't rain often in the desert, but almost all deserts receive rain. And since it rains so rarely, you're certainly not going to find an umbrella during the rainstorm.

So again, if staying dry in the rain is important to you, buy an umbrella before the rain, if you don't care about getting wet from time to time, then no need for the umbrella.

While the personal blog owner may not care about DDoS related downtime, he may face extra usage charges due to higher bandwidth, CPU usage, etc that he'd like to avoid.

Re: Do not put your site behind Cloudflare if you don't need to

#323
post #199

Earlier quoted context omitted.

You keep saying stuff like "the fallout" and "the repercussions" but then the only example you can provide is talking to customer service to bring your stuff back online. Is that it? Honestly speaking, not being sarcastic at all.

So the internet is a series of pipes, or tubes, whatever. This quintessential personal blog website is hosted somewhere in this inter connected mess of things. There’s a hierarchy of these pipes/tubes, and they all have some ever diminishing capacity as they head from a mythical center to the personal blog website. When the bad guys want to DDoS the personal blog website they don’t go and figure out the correct amoun…

How is that even legal? Is that my fault if some random guy got upset about what I posted online?

Re: Do not put your site behind Cloudflare if you don't need to

#324

Earlier quoted context omitted.

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.

Cloudflare will disconnect you from their free plan just as quickly. Especially when you are facing "infected machines by the millions".

Likely true, but now you can go back to the original statement: the issue isn't really that the service isn't available for a while... It's that the hoster will remove your server.

Your server will keep existing if cloudflare just drops their free service, effectively going down for the ddosrs but still available for your own access directly

Re: Do not put your site behind Cloudflare if you don't need to

#325

Earlier quoted context omitted.

this is too naive sorry, Hetzner will disconnect (and ban you if DDoS is too long), same as OVH. It works mostly for brutal UDP flooding but sophisticated attacks such as swarm of Puppeteers hosted on infected machines by the millions will not be protected, those "new DDoS mode" are offered by most DDoS providers.

Cloudflare will disconnect you from their free plan just as quickly. Especially when you are facing "infected machines by the millions".

Citation needed. I know folks using the free plan that have gotten ddos’d and cloudflare kept them online. Can you point me to an article where cloudflare disconnected someone for getting attacked

Re: Do not put your site behind Cloudflare if you don't need to

#326
post #317

Earlier quoted context omitted.

Not if you live in a desert, which most blogs do.

That continues the analogy -- it doesn't rain often in the desert, but almost all deserts receive rain. And since it rains so rarely, you're certainly not going to find an umbrella during the rainstorm. So again, if staying dry in the rain is important to you, buy an umbrella before the rain, if you don't care about getting wet from time to time, then no need for the umbrella. While the personal blog owner may not ca…

The people you see in a desert with umbrellas are not using it for the rain, but for shade, the rain is the least of their problems.

Re: Do not put your site behind Cloudflare if you don't need to

#327

Earlier quoted context omitted.

Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.

> Cloudflare is mostly used for anonymity and privacy, not for scale I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.

I self-host my blog on a server in my home. Instead of opening a port to my home network, I'm using Cloudflare Tunnel to expose the blog to the internet.

Re: Do not put your site behind Cloudflare if you don't need to

#328

Earlier quoted context omitted.

> Cloudflare is mostly used for anonymity and privacy, not for scale I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.

I self-host my blog on a server in my home. Instead of opening a port to my home network, I'm using Cloudflare Tunnel to expose the blog to the internet.

That's not really anonymity or privacy in all likelihood, though. Your residential IP is already anonymous. Knowing it tells me nothing other than your general region. The benefit there is that you don't need to have a static IP.

And besides, Cloudflare Tunnel is distinct from (though it integrates with) the cdn product.

Re: Do not put your site behind Cloudflare if you don't need to

#329

I'm running a Raspberry Pi 5 at home as a lightweight web server. I put it behind `cloudflared` as to not leak my home IP address, and today I got to pay for it. Should I just stop being paranoid about "leaking my IP address" and self-host it 100%? All I fear is that my family will have to live with degraded internet experience because some script kiddie targeted me for fun.

I would honestly not want to ever get targeted for a ddos attack on my home network ip. It's 5 bucks to buy a stresser online. Maybe you can even find one for free. People used to do that for fun when skype was around since you could resolve people's IP addresses due to a bug in skype. The worst possible outcome is they disconnect your network or block your port forwarding privileges outside of your own network being down for your family. I wouldn't wish ISP support on anyone, much less ISP support that would rather just terminate you than help you protect your homelab server.

Re: Do not put your site behind Cloudflare if you don't need to

#330
post #326

Earlier quoted context omitted.

That continues the analogy -- it doesn't rain often in the desert, but almost all deserts receive rain. And since it rains so rarely, you're certainly not going to find an umbrella during the rainstorm. So again, if staying dry in the rain is important to you, buy an umbrella before the rain, if you don't care about getting wet from time to time, then no need for the umbrella. While the personal blog owner may not ca…

The people you see in a desert with umbrellas are not using it for the rain, but for shade, the rain is the least of their problems.

Even in a desert, people still use umbrellas for protection from the rain:

https://lasvegassun.com/news/2016/jan/19/fast-moving-storm-b...

And the rain still causes problems, even (or maybe especially in) a desert:

https://nypost.com/2022/07/29/las-vegas-braces-for-more-rain...

Post reply on HN