Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

361–370 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#362

Earlier quoted context omitted.

Nah, the cliche still applies there as well.

No it really doesn't. How are you the product when Cloudflare gives you free tier access? That's not their business model. You aren't the product, but you are an upsell lead for the sales team.

They're logging all decrypted traffic to your website, that's the product.

Re: Do not put your site behind Cloudflare if you don't need to

#363

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

Meanwhile the maintainer of Bear Blog - very nearly the poster child for small blogs with 100 visitors per month - recently put up a post talking about how much extra infrastructure it takes to keep the service online in the face of the massive uptick in AI scraper bot traffic we've had over the past few years. I haven't tried managing my own site in ages, but I get the impression that the modern Internet is pretty m…

The AI DDoS, in my experience, is a few requests per second. You can just serve them.

Re: Do not put your site behind Cloudflare if you don't need to

#364

Earlier quoted context omitted.

In my experience hetzner DDoS protection doesn't work

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

That's not making things worse - that's just what the DDoS achieved anyway, but without harming anyone else.

In either case you just wait for the attacker to reach daddy's credit card limit and then your site is back up.

Re: Do not put your site behind Cloudflare if you don't need to

#365
post #46

Earlier quoted context omitted.

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

Did they put it back up when the DDoS ended? If so, they're not hurting you since it's no worse than the DDoS itself, and they're actually helping you by preventing themselves from having a reason to ban you to save the rest of their sites.

Re: Do not put your site behind Cloudflare if you don't need to

#367

Earlier quoted context omitted.

I'm less scared of the hoster pulling down your site - not the end of the world - then decided to charge you bandwidth fees for all the MS-DOS attacks. The former presumably has no financial impact, the latter, potentially brutal

Off-topic, but there are six different people using the word "hoster" in this thread. I've never heard that word used instead of "host" or "hosting service" before, and yet here it's somehow prevalent. I feel like I'm having a stroke, or I just stepped into an alternate universe. Where did you all pick up that word?

This happens often in comment threads, one comment uses an uncommon word and the entire thread goes along with it.

Re: Do not put your site behind Cloudflare if you don't need to

#368

Earlier quoted context omitted.

As long as the hoster doesn’t actively make things worse by disconnecting you, any further help is just a happy accident. The bar is very low.

That's not making things worse - that's just what the DDoS achieved anyway, but without harming anyone else. In either case you just wait for the attacker to reach daddy's credit card limit and then your site is back up.

No, in the cases 'throwaway150 and I are talking about, your site is not back up. You (hopefully) got an email in your inbox saying your hosting provider has decided to take your website offline because of anomalous traffic or whatever, and after the attack ends you’ve got at least a couple of days of back and forth with support ahead of you before your downtime is actually over.

Re: Do not put your site behind Cloudflare if you don't need to

#369

Earlier quoted context omitted.

That's not really anonymity or privacy in all likelihood, though. Your residential IP is already anonymous. Knowing it tells me nothing other than your general region. The benefit there is that you don't need to have a static IP. And besides, Cloudflare Tunnel is distinct from (though it integrates with) the cdn product.

I would like to know why this comment seems to have been down voted. It's true AFAIK.

> Your residential IP is already anonymous

It certainly isn't.

In fact, IPv4 is the de-facto authorization and authentication system of the Internet. It's stupid but it is what it is.

Cloudflare is the "bitcoin mixer" for laundering IPv4's.

Re: Do not put your site behind Cloudflare if you don't need to

#370

Earlier quoted context omitted.

Afaik, Cloudflare is mostly used for anonymity and privacy, not for scale. DDoS protection is one nice side effect of privacy, but I'd imagine there are others too.

> Cloudflare is mostly used for anonymity and privacy, not for scale I have never heard this before. Anonymity from what? From people knowing your Hetzner ip? I don't know what you're keeping private.

> From people knowing your Hetzner ip?

Yes. You don't really want people to know your IP address. It's like giving your phone number to spammers.

Post reply on HN