Live data from Hacker News

Do not put your site behind Cloudflare if you don't need to

huijzer.xyz

381–390 of 391 posts

Re: Do not put your site behind Cloudflare if you don't need to

#382
That is terrible advice. Cloudflare is normally an awesome CDN that is effectively free. It reduces resource usage by a large amount due to caching.

Also, if my little blog gets posted on Reddit or somewhere and gets a huge spike.. it won't go down or cost me money in overages.

This actually happened two years ago. I had massive DDOS style traffic that Cloudflare totally was able to mitigate.

Re: Do not put your site behind Cloudflare if you don't need to

#383
post #133

> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…

> Nobody wants to be in this situation even if for a personal, small blog. I would gladly be in this situation if it otherwise lets me remove a large source of complexity, avoid paying a few bucks, and increasing the avoidable centralization of the Internet on my personal, small blog. Maybe I'd change my mind if it continues happening, or if I didn't have unlimited traffic (which is a very bad idea for many reasons o…

I'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)

Re: Do not put your site behind Cloudflare if you don't need to

#384
post #326

Earlier quoted context omitted.

The people you see in a desert with umbrellas are not using it for the rain, but for shade, the rain is the least of their problems.

Even in a desert, people still use umbrellas for protection from the rain: https://lasvegassun.com/news/2016/jan/19/fast-moving-storm-b... And the rain still causes problems, even (or maybe especially in) a desert: https://nypost.com/2022/07/29/las-vegas-braces-for-more-rain...

1 person using an umbrella, 4 are not. I'm starting to doubt if you're even human given that normal people don't go throughout their entire lives always carrying an umbrella wherever they go, even when it might rain.

Re: Do not put your site behind Cloudflare if you don't need to

#385
post #190

Earlier quoted context omitted.

How? Isn’t it more like the difference between carrying an umbrella every day and ducking into the corner shop to buy one when you notice it’s raining?

That's a good analogy since the corner shop is going to be sold out of their small stock of umbrellas during the rain storm so you won't be able to buy one until the rainstorm is over but at least you'll have protection for the next storm. If staying dry is important to you, you should buy the umbrella before the rain.

Oh man. The corner shop around me has a wheeled cart stuffed to the gills with umbrellas, they roll it out to the entrance area when it rains.

Similarly Cloudflare has a giant button marked “I’m Under Attack!” in its signup flow, if I remember correctly…

Re: Do not put your site behind Cloudflare if you don't need to

#386
post #378

Earlier quoted context omitted.

The actual charitable model is that you expect close to zero attacks, but if you actually get hit your expected rate of future attacks goes up by an order of magnitude or two. And it's that change in expectations that gets you to buy protection. You don't care about going down once, you do care about frequent outages. And you know this from the start, you don't realize it later.

I'm not so sure. The risk of future attacks hasn't actually increased, your initial risk assessment was just incorrect.

Yes, the original assessment was wrong. Such things happen all the time to reasonable people.

The person you were describing in your "most charitable" version above was not being reasonable. They didn't just underestimate the petty anger of the internet, they were being fundamentally foolish about their own desires. That's why I replied, to show you a different way someone could end up in this position.

Re: Do not put your site behind Cloudflare if you don't need to

#387
post #133

Earlier quoted context omitted.

> Nobody wants to be in this situation even if for a personal, small blog. I would gladly be in this situation if it otherwise lets me remove a large source of complexity, avoid paying a few bucks, and increasing the avoidable centralization of the Internet on my personal, small blog. Maybe I'd change my mind if it continues happening, or if I didn't have unlimited traffic (which is a very bad idea for many reasons o…

I'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)

Ok, this is definitely even cooler than self-hosting a blog on Hetzner :) How are you using Cloudflare for this? Via Cloudflare Tunnel?

I'm currently unfortunately also behind double NAT, and my home server has been unreachable ever since as a result. I've been torn between using Tailscale Funnel, Cloudflare Tunnel, possibly a VPN with public IPs, or rolling my own thing based on reverse SSH forwarding to a Linux server with a public IP.

Re: Do not put your site behind Cloudflare if you don't need to

#388
True story:

People (or bots) using cloudflare ips to probe for exploited files.

I block the cloudflare cidr they are coming from.

Website backup (wordpress using updraft free) - fails.

Logs show failure to connect to updraft's web site.

I lookup the website's dns and see cloudflare ips.

Those ips are in the CIDR I blocked.

I temp undo the block, run the updraft backup, and go back to blocking millions of cloudflare ips.

Scratching my head on why updraft needs to connect to it's home site to run a backup, and why a better failure notice was not presented.

Re: Do not put your site behind Cloudflare if you don't need to

#389
post #387

Earlier quoted context omitted.

I'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)

Ok, this is definitely even cooler than self-hosting a blog on Hetzner :) How are you using Cloudflare for this? Via Cloudflare Tunnel? I'm currently unfortunately also behind double NAT, and my home server has been unreachable ever since as a result. I've been torn between using Tailscale Funnel, Cloudflare Tunnel, possibly a VPN with public IPs, or rolling my own thing based on reverse SSH forwarding to a Linux ser…

Yes, local nginx http server in a Debian container on a Raspberry Pi, and Cloudflare DNS and argo tunnel providing public IP and SSL.

Re: Do not put your site behind Cloudflare if you don't need to

#390

Earlier quoted context omitted.

Cloudflare will disconnect you from their free plan just as quickly. Especially when you are facing "infected machines by the millions".

Citation needed. I know folks using the free plan that have gotten ddos’d and cloudflare kept them online. Can you point me to an article where cloudflare disconnected someone for getting attacked

They definitely used to do this ca. 2011-2012, any bigger attack and they'd drop you right away if you were on a free plan (and slightly slower if you weren't). But well, that was almost 15 years ago.
Post reply on HN