Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

351–360 of 483 posts

Re: Cloudflare took down our website

#351
post #298
post #189

Can any1 explain how HN algo works that this post, which at time of writing has 355p, 180comments while being posted 1 hour ago, isn't even on first page (ranked 31)???

It set off the flamewar detector, got flagged by users, and got downweighted by a mod. The 'customer support of last resort' genre is common and not usually a good fit for HN [1]. If people feel this story is unusually relevant and interesting, I'm not sure I agree—long experience has taught us that one-sided articles like this nearly always leave out critical information—but I also don't mind yielding in an occasion…

I would be very happy to hear Cloudflare's actual side of this. (Or - it would have been great if they had given their side to us before getting into this mess). The only critical information from our side that I'm aware of is that we're a casino with multiple domains - which is why I put that right at the top. But most of the info should be relevant to any business interacting with CF.

I do admit that I originally drafted this article as a "customer support of last resort", since that seems to work well for CF specifically. But it's too late for that anyways by now - the problem is "resolved" by fire and we don't plan to move back.

I purely posted it now as a precautionary tale for other people because of all the pain it has caused us. So the audience is tech people in most companies of small size that will hit more traffic at some point in the future.

Re: Cloudflare took down our website

#352

Earlier quoted context omitted.

>I have spent far too long dealing with this as an RNG supplier Is there much of a market for that? I thought random.org had it all sewn up.

Gaming machines are highly regulated, almost like medical devices. There are seals on the hardware, any modification must be approved, you must certify that the payout is the expected one, ...

It's worse than medical devices, at least for the final machines and software.

For components in the path of money flow (payment processors, RNGs, hosting, etc.), it's similar.

Re: Cloudflare took down our website

#353

As far as I can tell, the issue with this is: OP runs a casino/gambling site. Gambling is a regulatory mess (I have spent far too long dealing with this as an RNG supplier), and so it's very hard to comply with every jurisdiction, and each one needs you to prove compliance to operate in that jurisdiction.* Gaming companies spend a lot on compliance and tracking, but since the internet is the internet, it's pretty har…

>I have spent far too long dealing with this as an RNG supplier Is there much of a market for that? I thought random.org had it all sewn up.

No, random.org isn't in that market at all, aside from doing some drawings local to them and unofficial games.

I think we are only one of ~3 TRNG suppliers who have been audited. Many games don't use a TRNG, though.

Since it uses atmospheric noise, you can also influence the numbers from random.org by transmitting radio waves in the area nearby - the operator of random.org has mentioned that there's so much RF activity that he is concerned about whether the bits are still random. A final issue is that they are also so low-volume that they probably can't get enough test data for the required audits (which can be a lot of data).

To underscore the volume question: Random.org used to have a running count of bits generated. The counter wasn't monotonic (before it broke in ~2015-2019), but the peak value I saw when I checked archive.org was about 250 GiB total since 1998 (that was in 2015). That is one quarter of the size of our "light" qualification test ("heavy" is 16 TiB). The RNG auditors also take O(100) megabytes for each audit, which would be a significant fraction of random.org's output.

Re: Cloudflare took down our website

#354
post #327

1-The gambling business is shady by design, whether you like it or not. This was probably more risk than benefit for them based on what they were getting from you. 2-Your business is probably very profitable, and $300 a month is very cheap compared to the potential hassles they could face working with such a business. 3-I find it very inappropriate to dox business representatives and show names when you have carefull…

To (1) - if this was the case, it would have been great if they had talked about it openly or in any way really. To (2) - I do agree that $300 is probably cheap. But I also think that $10k is very expensive, and it seems Fastly agrees.

(3) Mh, I don't think this is doxxing and didn't expect having names would be a big problem. I've just updated the screenshots anyways and censored the names of the representatives.

Cloudflare of course chooses who they want to do business with, but they also pride themselves in being neutral.

Re: Cloudflare took down our website

#355
Okay, with this thread, I'm learning and need to:

One Question: For the Web site for my startup, I have the ASP.NET code running so ASAP will be getting into to a business account with my ISP, IPs, domain names, DNS, etc., at least for the Alpha Test.

So far, my intention is to host my own Web server. I've heard of CloudFlare, how they can help stop DDOS attacks, etc. but so far have hope not to use them.

Question: How realistic is it for me just to host my own Web server and, e.g., avoid any chances of problems with CloudFlare, the Cloud, VPNs, etc.?

Thanks!

Re: Cloudflare took down our website

#356
post #330

Earlier quoted context omitted.

They're mad that cloudflare cut them without real warning. And they should be! Anyone can get on a big company's bad side, and if there aren't extremely important messages being withheld by the author this makes it scary for anyone to use cloudflare. If a custom IP is going to be mandatory, they need to say that and give a deadline, at the very least .

The IP-reputation damage is immediate. Cloudflare is choosing to pass the hard landing directly onto their customer instead of forcing their other customers to share the damage. As a CF customer, I am happy that Cf is preventing another business from damaging mine.

If they had agreed to the enterprise plan and move to BYOIP, pretty sure CF would have given them months to make BYOIP happen

They weren’t protecting you or any of their customers. This is a mafia style shakedown

Re: Cloudflare took down our website

#357

As far as I can tell, the issue with this is: OP runs a casino/gambling site. Gambling is a regulatory mess (I have spent far too long dealing with this as an RNG supplier), and so it's very hard to comply with every jurisdiction, and each one needs you to prove compliance to operate in that jurisdiction.* Gaming companies spend a lot on compliance and tracking, but since the internet is the internet, it's pretty har…

>The solution was to aggressively sell the Enterprise plan

A demand for 120k upfront or else bad stuff happens is by no reasonable definition "selling", aggressive or otherwise

Re: Cloudflare took down our website

#358

Earlier quoted context omitted.

How do you deal with DDoS attacks against said OVH servers?

> By default, every OVHcloud product is supported by the Anti-DDoS infrastructure to defend against malicious activity. https://us.ovhcloud.com/security/anti-ddos/

everyone that has used OVH and received an attack is laughing at that.

Re: Cloudflare took down our website

#359

The way Cloudflare approaches situations like this is not ideal for anyone. You start using the service and don't pay a lot, so you make plans around a certain level of expenses. Then out of the blue you receive an "urgent" email from a sales representative and suddenly you have to go from $20 or $250 to $thousands right away. Obviously it's not in CF's interest to keep a customer that doesn't pay enough, but droppin…

> but dropping a "bomb" on the customer Why on earth any company would jump from $250 to $10k per month unless they had a gun to their heads? Even if their revenue is to the millions/billions (which most likely is considering the nature of their business). They work for their own profit, not Cloudflare's.

The point is it doesn't have to be a "gun to their head". It just needs to be a serious of emails, calls and negotiation.

I'll be they are now paying Fastly a lot closer to $10k/month than $250/month

Re: Cloudflare took down our website

#360

Earlier quoted context omitted.

Genuine question: Why did you use `grok` in that context?

Rule: whenever someone prefaces a question with “genuine question” it’s actually a troll. Also here you go: https://en.m.wikipedia.org/wiki/Grok

> Rule: whenever someone prefaces a question with “genuine question” it’s actually a troll

That’s a very cynical take.

Post reply on HN