Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

331–340 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#331

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

> Sometimes people do DDoS your small blog because some random stranger didn't like something you said somewhere online.

I've received death threats. Do I engage in charged political commentary on my site? Not really. Just vaguely left-of-centre stuff in a way that I feel moves the discussion forward (and not even that often). The internet is fun: you're instantly connected to every unhinged asshole lunatic in the world.

Re: Do not put your site behind Cloudflare if you don't need to

#333
Everything is a "single point of failure" if you play around enough with the definition of "single". Your custom server with backup solution is a "single" thing, which is really not that far off from what Cloudflare is. From a technical point of view it's hard to get more redundant than things like Cloudflare; it's really not that centralised beyond being one organisation.

It's just that if your server fails no one hears about it. But as a rule, your custom server will fair more often than Cloudflare.

And you "need" it quicker than you think. DaemonForums is a small (no longer very active) forum; I ran the site for the first few years from 2008 to 2013. I served it off a small Intel Atom server. I haven't been involved in over a decade, but last year the current admin added Cloudflare because traffic from bots was getting out of control. He helpfully posted some stats:

  Period          Usage   Maximum Expected Overusage
  July 2025       5 GB    ∞       5 GB     No overusage
  June 2025       63 GB   ∞       63 GB    No overusage
  May 2025        788 GB  ∞       788 GB   No overusage
  April 2025      1038 GB ∞       1038 GB  38 GB
  March 2025      540 GB  ∞       540 GB   No overusage
  February 2025   379 GB  ∞       379 GB   No overusage
  January 2025    397 GB  ∞       397 GB   No overusage
  December 2024   401 GB  ∞       401 GB   No overusage
  November 2024   484 GB  ∞       484 GB   No overusage
  October 2024    328 GB  ∞       328 GB   No overusage
  September 2024  357 GB  ∞       357 GB   No overusage
  August 2024     355 GB  ∞       355 GB   No overusage
  July 2024       326 GB  ∞       326 GB   No overusage
  June 2024       189 GB  ∞       189 GB   No overusage
  May 2024        238 GB  ∞       238 GB   No overusage
  April 2024      225 GB  ∞       225 GB   No overusage
  March 2024      125 GB  ∞       125 GB   No overusage
  February 2024   76 GB   ∞       76 GB    No overusage
  January 2024    68 GB   ∞       68 GB    No overusage
  December 2023   34 GB   ∞       34 GB    No overusage
  November 2023   31 GB   ∞       31 GB    No overusage
  October 2023    31 GB   ∞       31 GB    No overusage
  September 2023  24 GB   ∞       24 GB   No overusage
  August 2023     22 GB   ∞       22 GB   No overusage
  July 2023       22 GB   ∞       22 GB   No overusage
  June 2023       22 GB   ∞       22 GB   No overusage
  May 2023        18 GB   ∞       18 GB   No overusage
  April 2023      20 GB   ∞       20 GB   No overusage
  March 2023      21 GB   ∞       21 GB   No overusage
  February 2023   20 GB   ∞       20 GB   No overusage
  January 2023    34 GB   ∞       34 GB   No overusage
  December 2022   38 GB   ∞       38 GB   No overusage
  November 2022   28 GB   ∞       28 GB   No overusage
  October 2022    25 GB   ∞       25 GB   No overusage
  September 2022  18 GB   ∞       18 GB   No overusage
  August 2022     36 GB   ∞       36 GB   No overusage
  July 2022       84 GB   ∞       84 GB   No overusage
  June 2022       71 GB   ∞       71 GB   No overusage
  May 2022        91 GB   ∞       91 GB   No overusage
  April 2022      89 GB   ∞       89 GB   No overusage
  March 2022      88 GB   ∞       88 GB   No overusage
  February 2022   89 GB   ∞       89 GB   No overusage
  January 2022    89 GB   ∞       89 GB   No overusage
  December 2021   98 GB   ∞       98 GB   No overusage
  November 2021   101 GB  ∞       101 GB  No overusage
  October 2021    97 GB   ∞       97 GB   No overusage
  September 2021  92 GB   ∞       92 GB   No overusage
  August 2021     94 GB   ∞       94 GB   No overusage
  July 2021       84 GB   ∞       84 GB   No overusage
  June 2021       83 GB   ∞       83 GB   No overusage
  May 2021        92 GB   ∞       92 GB   No overusage
  April 2021      91 GB   ∞       91 GB   No overusage
  March 2021      76 GB   ∞       76 GB   No overusage
  February 2021   68 GB   ∞       68 GB   No overusage
  January 2021    82 GB   ∞       82 GB   No overusage
  December 2020   74 GB   ∞       74 GB   No overusage
  November 2020   76 GB   ∞       76 GB   No overusage
  October 2020    71 GB   ∞       71 GB   No overusage
  September 2020  65 GB   ∞       65 GB   No overusage
  August 2020     75 GB   ∞       75 GB   No overusage
  July 2020       71 GB   ∞       71 GB   No overusage
  June 2020       65 GB   ∞       65 GB   No overusage
  May 2020        71 GB   ∞       71 GB   No overusage
  April 2020      56 GB   ∞       56 GB   No overusage
  March 2020      59 GB   ∞       59 GB   No overusage
  February 2020   56 GB   ∞       56 GB   No overusage
  January 2020    61 GB   ∞       61 GB   No overusage
  December 2019   55 GB   ∞       55 GB   No overusage
  November 2019   51 GB   ∞       51 GB   No overusage
  October 2019    54 GB   ∞       54 GB   No overusage
  September 2019  51 GB   ∞       51 GB   No overusage
  August 2019     49 GB   ∞       49 GB   No overusage
  July 2019       49 GB   ∞       49 GB   No overusage
  June 2019       46 GB   ∞       46 GB   No overusage
  May 2019        63 GB   ∞       63 GB   No overusage
  April 2019      46 GB   ∞       46 GB   No overusage
  March 2019      46 GB   ∞       46 GB   No overusage
  February 2019   43 GB   ∞       43 GB   No overusage
  January 2019    83 GB   ∞       83 GB   No overusage
  December 2018   52 GB   ∞       52 GB   No overusage
  November 2018   53 GB   ∞       53 GB   No overusage
  October 2018    49 GB   ∞       49 GB   No overusage
  September 2018  45 GB   ∞       45 GB   No overusage
  August 2018     46 GB   ∞       46 GB   No overusage
  July 2018       20 GB   ∞       20 GB   No overusage
  July 2018       34 GB   ∞       34 GB   No overusage
  June 2018       59 GB   ∞       59 GB   No overusage
  May 2018        51 GB   ∞       51 GB   No overusage
  April 2018      59 GB   ∞       59 GB   No overusage
  March 2018      49 GB   ∞       49 GB   No overusage
  February 2018   44 GB   ∞       44 GB   No overusage
  January 2018    47 GB   ∞       47 GB   No overusage
  December 2017   49 GB   ∞       49 GB   No overusage
  November 2017   43 GB   ∞       43 GB   No overusage
  October 2017    46 GB   ∞       46 GB   No overusage
  September 2017  47 GB   ∞       47 GB   No overusage
  August 2017     43 GB   ∞       43 GB   No overusage
  July 2017       42 GB   ∞       42 GB   No overusage
  June 2017       46 GB   ∞       46 GB   No overusage
  May 2017        42 GB   ∞       42 GB   No overusage
  April 2017      59 GB   ∞       59 GB   No overusage
  March 2017      46 GB   ∞       46 GB   No overusage
  February 2017   45 GB   ∞       45 GB   No overusage
  January 2017    46 GB   ∞       46 GB   No overusage
  December 2016   43 GB   ∞       43 GB   No overusage
  November 2016   38 GB   ∞       38 GB   No overusage
  October 2016    41 GB   ∞       41 GB   No overusage
  September 2016  32 GB   ∞       32 GB   No overusage
  August 2016     34 GB   ∞       34 GB   No overusage
  July 2016       33 GB   ∞       33 GB   No overusage
  June 2016       41 GB   ∞       41 GB   No overusage
  May 2016        46 GB   ∞       46 GB   No overusage
  April 2016      51 GB   ∞       51 GB   No overusage
  March 2016      53 GB   ∞       53 GB   No overusage
  February 2016   39 GB   ∞       39 GB   No overusage
  January 2016    42 GB   ∞       42 GB   No overusage
  December 2015   36 GB   ∞       36 GB   No overusage
  November 2015   35 GB   ∞       35 GB   No overusage
  October 2015    32 GB   ∞       32 GB   No overusage
  September 2015  38 GB   ∞       38 GB   No overusage
  August 2015     36 GB   ∞       36 GB   No overusage
  July 2015       35 GB   ∞       35 GB   No overusage
  June 2015       34 GB   ∞       34 GB   No overusage
  May 2015        35 GB   ∞       35 GB   No overusage
  April 2015      55 GB   ∞       55 GB   No overusage
  March 2015      44 GB   ∞       44 GB   No overusage
  February 2015   28 GB   ∞       28 GB   No overusage
  January 2015    36 GB   ∞       36 GB   No overusage
  December 2014   38 GB   ∞       38 GB   No overusage
  November 2014   41 GB   ∞       41 GB   No overusage
  October 2014    64 GB   ∞       64 GB   No overusage
  September 2014  44 GB   ∞       44 GB   No overusage
  August 2014     43 GB   ∞       43 GB   No overusage
  July 2014       42 GB   ∞       42 GB   No overusage
  June 2014       27 GB   ∞       27 GB   No overusage
  May 2014        31 GB   ∞       31 GB   No overusage
  April 2014      40 GB   ∞       40 GB   No overusage
  March 2014      38 GB   ∞       38 GB   No overusage
  February 2014   37 GB   ∞       37 GB   No overusage
  January 2014    24 GB   ∞       24 GB   No overusage
From: https://daemonforums.org/showthread.php?t=12809#post76328

The traffic increased by an order of a magnitude, to the point where it was causing problems.

Does it "need" Cloudflare? Probably not – you can just expand your hardware, or maybe fiddle with some other stuff. But Cloudflare is simple, cheap, and easy.

I have no great love for Cloudflare, but posts like this are not in sync with the state of the modern internet.

Re: Do not put your site behind Cloudflare if you don't need to

#334

Earlier quoted context omitted.

In my experience hetzner DDoS protection doesn't work

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

Re: Do not put your site behind Cloudflare if you don't need to

#335
post #46

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

The downtime cause by DDoS. It's now an endemic problem in the modern internet. Even relatively tiny communities suffer from it, because it's so damn easy to do.

Re: Do not put your site behind Cloudflare if you don't need to

#336

Earlier quoted context omitted.

This is my worry. What is cloudflare exactly? What regulations are they under? Am I and my privacy protected? How much of my privacy do I need to give up for whats essentially part of a protection racket, be it intentional or not. What happens when I use their SSL, can they sniff my packets? What intelligence and law enforcement do they work with? As someone with vulnerable and targeted identities its a lot harder to…

Cloudflair is what happens when a platonic idea of the internet clashes with market realities. All the questions posed are very important but most websites are run by businesses with motives about as pure as Cloudflair’s. As for people… A programming club I attended is filled with people who run homelabs, use Linux and generally dislike anything corporate. The project to switch communication of discord is now more th…

Cloudflare is what happens when the internet as a platonic idea fails to come up with a sensible answer to ddos attacks. When there's no pipe fat enough to take the traffic a moderate DDoS can bring to bear, you need means of filtering in a distributed fashion, and in way the internet is organised that takes connections and hardware which are essentially impossible for a small operation to muster.

Re: Do not put your site behind Cloudflare if you don't need to

#337

Earlier quoted context omitted.

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

This!! Everyone seems to "really need" that unlimited scalability of AWS & Co - but they'll happily scale your compute and the bill for you.

Sure maybe you'll get lucky and they waive it.

But sometimes going down is a feature if you're not a multi m/billion dollar business

Re: Do not put your site behind Cloudflare if you don't need to

#338

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

CDN is not the same as DDoS protection.

Cloudflare does both but some providers do one or the other. You can use any CDN no matter if you use Cloudflare or not (shout-out to Bunny CDN btw, very happy with them - they do one thing and do it well)

Re: Do not put your site behind Cloudflare if you don't need to

#339

Earlier quoted context omitted.

Do providers offering VPS have a layer of protection against such attacks? It might overwhelm their routers etc too?

many VPS providers want to get rid of you if you're on receiving end of the attacks as well. since you threaten the stability of their operations.

Thanks.. Trying to understand the issue bit better if you can bear with me..

Let's say you manage to install some cloudfare equivalent in your Vps so your hands are clean. That still exposes the provider systems up to that point, eating up resources?

Or they'll still knock you off and ban your IP at the first point of entry itself..

Cos where that leads us is subscribing to cloudfare type service almost becomes inevitable.. You can't get around it with some free software running in your own box.

Re: Do not put your site behind Cloudflare if you don't need to

#340

Earlier quoted context omitted.

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

Off-topic, but there are six different people using the word "hoster" in this thread. I've never heard that word used instead of "host" or "hosting service" before, and yet here it's somehow prevalent. I feel like I'm having a stroke, or I just stepped into an alternate universe. Where did you all pick up that word?
Post reply on HN