Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

401–410 of 483 posts

Re: Cloudflare took down our website

#401

I will remind HNers: is Cloudflare not the company that leaked sensitive data through cache files that were indexed by at least Google, and when the tech community were up in arms about the massive leakage of sensitive data, the CEO’s strategy was to turn up here and criticise Google for not deindexing quickly enough? You get what you pay for.

This was a much needed reminder. Although, it's quite difficult to find a better DDoS mitigator which is better than CF, I still wouldn't trust them for everything. Especially, since they are most likely snooping on the decrypted HTTPS connections

Re: Cloudflare took down our website

#402

Earlier quoted context omitted.

That's one of the main reasons I'm leary about them. Such a big f-up is difficult to forget. It shows that they have a move fast and break things culture which for a company that is responsible for critical infrastructure feels wrong.

I interviewed there once and they asked me what I would do if a service broke after a deployment. I said the first step was to revert to the last known good version and then investigate. Color me surprised when that was not the answer they expected.

That's strange. What was the "correct" answer?

Re: Cloudflare took down our website

#403

Earlier quoted context omitted.

She did say that she didn't bring in any customers...

She did say she was around for only 6 months and enterprise sales cycles can last 12+. Though I guess if you’re engaging in scammy behavior it can be much less… maybe she wasn’t willing to do that.

Although in OP apparently the enterprise sales cycle is 24 hours

Re: Cloudflare took down our website

#404

Earlier quoted context omitted.

It is a good article, good to have practical details of how this goes down... but really an international casino cant afford more than $250 a month?

Getting a demand to increase the payment by 40x is shocking no matter how much you make.

No sane company just goes “oh, that is fine. Must be that ‘ole inflation making times tough at $vendor, eh?”

Not in response to the way Cloudflare came at them, anyway.

Re: Cloudflare took down our website

#405
I'm surprised by how many comments seem to assume Cloudflare is at fault. Shouldn't the default assumption be that no one did anything wrong?

In defense of Cloudflare, the sys ops engineer should have understood the situation and knew they were misusing Cloudflares services. They decided to play hard ball by bringing up the fact they were thinking of leaving. And we have no history of the multiple phone calls they had with Cloudflare.

Re: Cloudflare took down our website

#406
post #133

Earlier quoted context omitted.

When it comes to laws and taxes, "comply" and "evade" tend to be synonyms. "In order to comply with tax regulations and donor laws, we had to structure our activities in order to make it possible for political donations to be classified as regular consulting income".

At least from discussions I've had over the years with my accountants, comply and evade are very different. Evasion is when you are doing something that's explicitly illegal. Optimization and compliance is when you comply with the law while trying as much as possible to reduce your tax. In some cases, there's a bit of a grey area where you use multiple structures that according to your accountant should comply with t…

This is in part why good laws are more concerned with what “it” is rather than what “it” is called. Good laws define something and then name it, so that you can test a pattern of facts and determine whether “it” is indeed what the law covers.

For me, my corporate tax professional errs on the side of well tested strategies or those that the IRS has ruled on administratively, and that is perfect for my risk tolerance.

Re: Cloudflare took down our website

#407

Earlier quoted context omitted.

> undocumented limit this makes it sound like the limit is automatic or applies non-discriminately to customers, but my first instinct is that this was manually set by someone, maybe the sales reps again?

Yeah so I think it might’ve been a real system limit of sorts. Something timing out somewhere, some pipe getting clogged in a way that their edge nodes couldn’t scale their way out of the way they usually do. Eg because the scaling/monitoring code didn't detect that particular pipe getting clogged etc. We had weird long-running http requests at the time. Note, this is pure conjecture, I’m just well aware from my own…

> I don’t believe they’re that kind of business

I didn’t either, but then I read this post :/

Re: Cloudflare took down our website

#408
post #298

Earlier quoted context omitted.

It set off the flamewar detector, got flagged by users, and got downweighted by a mod. The 'customer support of last resort' genre is common and not usually a good fit for HN [1]. If people feel this story is unusually relevant and interesting, I'm not sure I agree—long experience has taught us that one-sided articles like this nearly always leave out critical information—but I also don't mind yielding in an occasion…

I would be very happy to hear Cloudflare's actual side of this. (Or - it would have been great if they had given their side to us before getting into this mess). The only critical information from our side that I'm aware of is that we're a casino with multiple domains - which is why I put that right at the top. But most of the info should be relevant to any business interacting with CF. I do admit that I originally d…

My experience with Cloudflare is that anytime “Trust and Safety” are involved, no one will ever be told anything. Even if it’s a totally benign or even good situation. Even if they find a case in your favor or resolve an issue for you.

Whoever runs that team really, really gets off on being withholding, as Buster Bluth would say.

Re: Cloudflare took down our website

#409

Earlier quoted context omitted.

I wouldn't trust a company after they pulled this stunt just once. Why are you letting them do this to you(r company)?

it's not me -- which is why i'm not nervous about talking about it on HN. I work in the non-profit sector and don't currently use Cloudflare. Just stories I've heard from others. I'd guess that the cost of switching/cost compared to other alternatives/cost compared to business value/revenue, remained sustainable for the customer, who didn't want to deal with a switch. In truth, this is kind of how "enterprise sales"…

My experience with Pulumi enterprise sales has been that they’re fairly forthcoming about how much everything will cost based on usage.

I think it’s weird to accept an enterprise contract without explicit terms…

Re: Cloudflare took down our website

#410
post #384

Earlier quoted context omitted.

This still doesn't contain the word "gambling". Instead, it says that they can terminate your account at any moment, for any reason, no matter what your business type is, which is the opposite of "trust".

Oh well, last I checked “gambling” will match with a .* regex pattern.

You said "I’m going to guess that you need to have an Enterprise contract to be a business of certain categories".

If that was the problem, this issue wouldn't be relevant to most people.

When you switch to "they can terminate anyone", and they act this rashly and unexpectedly, that means anyone needs to live in fear.

Post reply on HN