Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

371–380 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#371

Earlier quoted context omitted.

My site being down for a couple days is not an unacceptably large loss, unlike an uninsured car being wrecked. It also isn't a good analogy because insurance doesn't apply retroactively to wrecks that happened before start of term, and is event-based rather than providing continuous value.

I thought that's why it's a good analogy - DDoS protection doesn't apply retroactively to prior attacks (or even current attacks, it's hard to apply DDoS protection while your site is down due to DDoS). If you want protection from DDoS, you need it before the DDoS. If you want to insure your car in case of accident, you need to insure it before the accident.

>or even current attacks, it's hard to apply DDoS protection while your site is down due to DDoS

Why? with cloudflare it's very easy, just put your site behind a reverse proxy, change the dns and disable direct access. Am I missing something?

Re: Do not put your site behind Cloudflare if you don't need to

#372

Yep, my websites are up and running. No AWS, no CloudFlare, no problem. We get excited by KPIs like uptime or scale while in truth for most of us those are not the key metrics. We think like BigTech because that's the metrics they sell us. It's a mistake that is profitable for them.

See kravietz's reply "...99% of websites hosted CF do not need neither AWS or CF..." in https://agora.echelon.pl/notice/B0P53zburJfENpkXEu

Re: Do not put your site behind Cloudflare if you don't need to

#374

Earlier quoted context omitted.

That's not making things worse - that's just what the DDoS achieved anyway, but without harming anyone else. In either case you just wait for the attacker to reach daddy's credit card limit and then your site is back up.

No, in the cases 'throwaway150 and I are talking about, your site is not back up. You (hopefully) got an email in your inbox saying your hosting provider has decided to take your website offline because of anomalous traffic or whatever, and after the attack ends you’ve got at least a couple of days of back and forth with support ahead of you before your downtime is actually over.

So until daddy's credit card runs out, plus two days. A shame, but it still doesn't cause meaningful harm.

Or get a different provider. Some are faster to respond. I had a false positive DDoS detection from netcup once (I was scraping an FTP site in active mode) and they automatically routed my IP through a DDoS scrubbing service, and automatically stopped that when an attack was no longer detected. I don't know what they have set up to be able to reroute a single IP globally like that - they agreed with some of their upstreams, to allow the occasional /32 for DDoS protection purposes.

Re: Do not put your site behind Cloudflare if you don't need to

#375
post #83

Earlier quoted context omitted.

What’s the cost of making the internet more centralised because of sheer laziness?

Do you think most people who want to start a blog are thinking about the centralization of internet services?

The people starting a tech blog damn well should be

Re: Do not put your site behind Cloudflare if you don't need to

#376

Earlier quoted context omitted.

No it really doesn't. How are you the product when Cloudflare gives you free tier access? That's not their business model. You aren't the product, but you are an upsell lead for the sales team.

They're logging all decrypted traffic to your website, that's the product.

Source:

Re: Do not put your site behind Cloudflare if you don't need to

#378
post #183

Earlier quoted context omitted.

It's more like buying the plug-in version after the battery dies... You already experienced the downtime, so if not having downtime was a goal you already failed. If avoiding downtime is not important then there's no reason to add anti-downtime capability to your system. The most charitable modeling of this approach is that the downtime incident may prompt one to realize that avoiding downtime actually is an importan…

The actual charitable model is that you expect close to zero attacks, but if you actually get hit your expected rate of future attacks goes up by an order of magnitude or two. And it's that change in expectations that gets you to buy protection. You don't care about going down once, you do care about frequent outages. And you know this from the start, you don't realize it later.

I'm not so sure. The risk of future attacks hasn't actually increased, your initial risk assessment was just incorrect.

Re: Do not put your site behind Cloudflare if you don't need to

#379
post #46

Earlier quoted context omitted.

If you added up all the outage time caused by DDOS and all the outage time caused by being behind auxiliary services that have their own outages... I wonder which would be larger? I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares?

> I'm not too worried about someone DDOSing my personal site. Yeah, they could do it. And then what? Who cares? Have you experienced a targeted DDoS attack on your personal site? I have. I too had this attitude like yours when I didn't know how nasty targeted DDoS attacks can get. If you're not too worried about someone DDoSing your personal site, then your host taking your website down and then you having to run cir…

A forum I manage was DDoSed, but I think it was by (AI) content scrapers as no one expressed any issues or anger towards the forum.

I temporarily got around it by blocking the subnet of their IPs.

I have since put it behind Cloudflare.

Re: Do not put your site behind Cloudflare if you don't need to

#380

All the people posting all their reasons why they use Cloudflare ("it's free!"/"it's easy!"/"my site won't go down!") makes me realize this apparent arms race is going to effectively result in the total centralization of all web content. Cool. Seems like a great idea to rely on a singular US service rather than diversify the risk across hundreds/thousands of services around the world. What could possibly go wrong?

Oh yeah: If you host behind Cloudflare, you can basically expect your site/service is inaccessible by all of Spain every weekend or so: the government there decided to just completely cut off Cloudflare to stop illegal sports streaming sites. A couple posts about this:

https://daniel.es/blog/cloudflare-vs-la-liga/

https://harro.com/2025/06/06/is-blanket-ip-blocking-justifie...

https://cybersecurityadvisors.network/2025/04/15/la-liga-blo...

https://www.techradar.com/vpn/vpn-privacy-security/cloudflar...

Post reply on HN