Live data from Hacker News

Thoughts on Cloudflare

xn--gckvb8fzb.com

51–60 of 88 posts

Re: Thoughts on Cloudflare

#51
Load of bull. Every article linked in this is either wrong or mischaracterized.

Cloudflare does not facilitate phising - it just made proxying and tunneling easier.

The breaches and bypasses mentioned are anything but - they are linking to a successful mitigation of an attack as if the attacker got away with something of value.

This entire article reeks of trying to fit the evidence to an agenda.

Considering they couldn't find actual evidence of problems and had to resort to mischaracterization this is actually a great reason to use Cloudflare.

Re: Thoughts on Cloudflare

#52
post #29
post #19

Very good post. Cloudflare is continuously adding services to their cloud offerings (the latest being Email delivery) in a familiar pattern of "let's make it impossible to switch".

I'm currently on my Nth run of: - I want to deploy a tiny service for personal use - That has occasional requests (think ~10 a day) - Needs to respond to a few daily events: a CRON job here and there, read an email, webhooks... Think a simpler Zapier In principle this would be perfect for any of the many cloud function providers. But AFAIK all of them have this vendor lock-in built into their business model and I jus…

Some Cloud functions like lambda support OCI container as a runtime target for example.

I understand that feeling but can be hard a provider that fill all that requirements without a expensive cost.

Integrate with the edge computing is part of the price you pay for all the conveniences like automatic builds, Cron and public reachable endpoints (and some of them almost free).

A minimal VPS with linux is always an alternative.

Re: Thoughts on Cloudflare

#53
post #27

Earlier quoted context omitted.

The Internet runs at the will of the government(s). Every government (national, regional, local) has regulations that must be obeyed. Depending upon where you live, some of those regulations may be kept secret from those most affected. An entity like Cloudflare is a juicy target that can be used cooperatively, or abused uncooperatively by those enforcing the regulations. So Cloudflare has solved one problem (DDoS), w…

They already do this for Chinese traffic. They send traffic from China to Alibaba controlled infrastructure. Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba. And I would not be surprised if they were abusing their middlebox position to do all kinds of surveillance based on secret "warrants" in other places.

>Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba.

Source? AFAIK their China product is entirely separate and you need to specifically sign up for it. AWS/Azure have similar arrangements in China but you wouldn't say the Cloudfront users are getting MITMed by the CCP.

Re: Thoughts on Cloudflare

#54

Load of bull. Every article linked in this is either wrong or mischaracterized. Cloudflare does not facilitate phising - it just made proxying and tunneling easier. The breaches and bypasses mentioned are anything but - they are linking to a successful mitigation of an attack as if the attacker got away with something of value. This entire article reeks of trying to fit the evidence to an agenda. Considering they cou…

I've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.

Re: Thoughts on Cloudflare

#55
I dislike how Cloudflare wants to do everything the Cloudflare way. A lot of their services are legit good and insanely cheap though, and containers have the potential to be a game changer that takes them from occasionally useful to the backbone of your cloud.

Re: Thoughts on Cloudflare

#57
post #54

Load of bull. Every article linked in this is either wrong or mischaracterized. Cloudflare does not facilitate phising - it just made proxying and tunneling easier. The breaches and bypasses mentioned are anything but - they are linking to a successful mitigation of an attack as if the attacker got away with something of value. This entire article reeks of trying to fit the evidence to an agenda. Considering they cou…

I've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.

I reported a phishing site to them in 2013. They responded "Access to the submitted phishing URL(s) has been restricted."

Re: Thoughts on Cloudflare

#58
post #27

Earlier quoted context omitted.

The Internet runs at the will of the government(s). Every government (national, regional, local) has regulations that must be obeyed. Depending upon where you live, some of those regulations may be kept secret from those most affected. An entity like Cloudflare is a juicy target that can be used cooperatively, or abused uncooperatively by those enforcing the regulations. So Cloudflare has solved one problem (DDoS), w…

They already do this for Chinese traffic. They send traffic from China to Alibaba controlled infrastructure. Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba. And I would not be surprised if they were abusing their middlebox position to do all kinds of surveillance based on secret "warrants" in other places.

Isn't anyone who connects from China getting MITM'd by the great firewall anyway?

Re: Thoughts on Cloudflare

#59
post #30

What we really need is more IPV6 deployment so normal people can have plenty of routable addresses and we can go back to hosting more things on the edges like we used to, on computers we physically control. There are plenty of applications where the bandwidth of PON fiber commonly deployed to homes is more than sufficient, and the extra latency is irrelevant. Sure, it may be susceptible to DDoS attack, but if tens of…

You’re basically asking people to go defenseless under the theory that “they can’t catch all of us,” like a school of fish.

I don’t think that works. Internet attacks can be automated. Businesses need real defenses.

Re: Thoughts on Cloudflare

#60
post #36

Earlier quoted context omitted.

Running a server from "home" (or an office) I think is too expensive for most businesses. Paying for battery backups, duplicate internet providers, diy NOC, is just too much, especially for small side projects where the goal is publish blogs or write code, not side-hustle SRE

What if I told you, that you don't need battery backups, that one ISP is enough, that you don't need 24/7 network team to plug a cable from your tower server to a router, in order to host a mid-size SAAS from the office tower server? Get real guys.

Get real guys.

I had a PHB who didn't like that our web site went offline for 30 seconds each week.

I explained to her that the alternative would require $200,000 and six new employees.

She hasn't brought it up since.

Very few web sites are "mission critical." Even Facebook could go offline for a few seconds a week and nobody would care or notice.

Post reply on HN