Earlier quoted context omitted.
Source:
https://developers.cloudflare.com/fundamentals/concepts/how-...
Do not put your site behind Cloudflare if you don't need to
381–390 of 391 posts
Re: Do not put your site behind Cloudflare if you don't need to
#382Also, if my little blog gets posted on Reddit or somewhere and gets a huge spike.. it won't go down or cost me money in overages.
This actually happened two years ago. I had massive DDOS style traffic that Cloudflare totally was able to mitigate.
Re: Do not put your site behind Cloudflare if you don't need to
#383> For your small blog with one hundred visitors per month, it's probably the same: "no one will burn their DDoS capabilities on you!" If this is their core argument for not using CDN, then this post sounds like a terribly bad advice. Hopes and prayers do not make a valid security strategy. Appropriate controls and defenses do. The author seems to be completely missing that it takes only a few bucks to buy DDoS as a s…
> Nobody wants to be in this situation even if for a personal, small blog. I would gladly be in this situation if it otherwise lets me remove a large source of complexity, avoid paying a few bucks, and increasing the avoidable centralization of the Internet on my personal, small blog. Maybe I'd change my mind if it continues happening, or if I didn't have unlimited traffic (which is a very bad idea for many reasons o…
Re: Do not put your site behind Cloudflare if you don't need to
#384Earlier quoted context omitted.
The people you see in a desert with umbrellas are not using it for the rain, but for shade, the rain is the least of their problems.
Even in a desert, people still use umbrellas for protection from the rain: https://lasvegassun.com/news/2016/jan/19/fast-moving-storm-b... And the rain still causes problems, even (or maybe especially in) a desert: https://nypost.com/2022/07/29/las-vegas-braces-for-more-rain...
Re: Do not put your site behind Cloudflare if you don't need to
#385Earlier quoted context omitted.
How? Isn’t it more like the difference between carrying an umbrella every day and ducking into the corner shop to buy one when you notice it’s raining?
That's a good analogy since the corner shop is going to be sold out of their small stock of umbrellas during the rain storm so you won't be able to buy one until the rainstorm is over but at least you'll have protection for the next storm. If staying dry is important to you, you should buy the umbrella before the rain.
Similarly Cloudflare has a giant button marked “I’m Under Attack!” in its signup flow, if I remember correctly…
Re: Do not put your site behind Cloudflare if you don't need to
#386Earlier quoted context omitted.
The actual charitable model is that you expect close to zero attacks, but if you actually get hit your expected rate of future attacks goes up by an order of magnitude or two. And it's that change in expectations that gets you to buy protection. You don't care about going down once, you do care about frequent outages. And you know this from the start, you don't realize it later.
I'm not so sure. The risk of future attacks hasn't actually increased, your initial risk assessment was just incorrect.
The person you were describing in your "most charitable" version above was not being reasonable. They didn't just underestimate the petty anger of the internet, they were being fundamentally foolish about their own desires. That's why I replied, to show you a different way someone could end up in this position.
Re: Do not put your site behind Cloudflare if you don't need to
#387Earlier quoted context omitted.
> Nobody wants to be in this situation even if for a personal, small blog. I would gladly be in this situation if it otherwise lets me remove a large source of complexity, avoid paying a few bucks, and increasing the avoidable centralization of the Internet on my personal, small blog. Maybe I'd change my mind if it continues happening, or if I didn't have unlimited traffic (which is a very bad idea for many reasons o…
I'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)
I'm currently unfortunately also behind double NAT, and my home server has been unreachable ever since as a result. I've been torn between using Tailscale Funnel, Cloudflare Tunnel, possibly a VPN with public IPs, or rolling my own thing based on reverse SSH forwarding to a Linux server with a public IP.
Re: Do not put your site behind Cloudflare if you don't need to
#388People (or bots) using cloudflare ips to probe for exploited files.
I block the cloudflare cidr they are coming from.
Website backup (wordpress using updraft free) - fails.
Logs show failure to connect to updraft's web site.
I lookup the website's dns and see cloudflare ips.
Those ips are in the CIDR I blocked.
I temp undo the block, run the updraft backup, and go back to blocking millions of cloudflare ips.
Scratching my head on why updraft needs to connect to it's home site to run a backup, and why a better failure notice was not presented.
Re: Do not put your site behind Cloudflare if you don't need to
#389Earlier quoted context omitted.
I'm behind Starlink, which is NAT'd to a shared public IP address, and I refuse to pay for hosting, so Cloudflare is how https://potateaux.com is on the Web. Of course nobody looks at it because there's very little there besides a cool landing page and a couple of JavaScript gags, so one outage per lifetime is a perfectly acceptable cadence in exchange for $0 in Cloudflare service costs :)
Ok, this is definitely even cooler than self-hosting a blog on Hetzner :) How are you using Cloudflare for this? Via Cloudflare Tunnel? I'm currently unfortunately also behind double NAT, and my home server has been unreachable ever since as a result. I've been torn between using Tailscale Funnel, Cloudflare Tunnel, possibly a VPN with public IPs, or rolling my own thing based on reverse SSH forwarding to a Linux ser…
Re: Do not put your site behind Cloudflare if you don't need to
#390Earlier quoted context omitted.
Cloudflare will disconnect you from their free plan just as quickly. Especially when you are facing "infected machines by the millions".
Citation needed. I know folks using the free plan that have gotten ddos’d and cloudflare kept them online. Can you point me to an article where cloudflare disconnected someone for getting attacked