They force you to use their DNS servers if you want to use their S3...
Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
61–70 of 168 posts
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#629 cents a gigabyte downloaded versus 0 cents a gigabyte downloaded is a pretty good deal. There’s not much AWS can do about it because they must make untold billions from those sweet, sweet S3 egress fees. I’d be willing to bet S3 egress fees make up about 60% of all AWS revenue.
I have to imagine CloudWatch makes AWS a lot of money too. Very often, when I look into an account from work that is spending a lot, CloudWatch is a large contributor.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#63Earlier quoted context omitted.
Those are completely different things though. If someone is trying to validate credentials/cards using your service, they're not trying to DoS it. Those types are usually using only a few IPs and are easy to detect/block (or even tarpit and help others) at app/proxy level. (Multiple failures for different usernames - block for some time) You need DDoS protection when someone does not want your service to stay up.
Well no, cred stuffing often results in termination or suspension of service by the merchant accounts used by the victim. This denies them the ability to sell thier goods and services - generally this denies end users the ability to ise the victim's service just as effectively as a volumetric attack. Further, cred stuffing is often automated by a botnet. The two things are distinct, but have similar means and end res…
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#64It's a seemingly simple and obvious way to lazily migrate your data, but if using Sippy means one less thing for the application code to worry about, and (I assume) is a free add-on, then it provides a ton of value. I have to admit that Cloudflare has been killing it recently with DevX / OpsX. If I wasn't against that company's role in modern internet (as a user of Tor, their firewall is annoying to no end), I would…
This, CF is the only service that I find amazing, and that I do not use for anything. Compared to AWS, I think I prefer the "we're your unopinionated infra provider, if you want a WAF we have that too", vs the CF "block the world, especially the developing world, give zero craps about it". I fundamentally would be unhappy as their customer even if their service were stellar because I do not want my apps to be associa…
Likewise, TOR access is similarly configurable. Companies choose to block it because more often than not it IS bot traffic, and the few potential real customers who use TOR are deemed not worth the headaches of the rest of the network.
Cloudflare's WAF is really pretty granular, with a lot of toggles and overrides: https://developers.cloudflare.com/waf/managed-rules/
Anecdote: For small businesses with limited web resources, these are just everyday tradeoffs they have to make in order to keep hosting and security fees reasonable. At the place I worked at, previously we were spending tens of thousands a year on hosting and thousands more for a competing WAF that cost like 10x more and didn't work very well. Cloudflare let us move to a much lower hosting plan and cost like $240/yr and drastically reduced bot traffic. Not a single customer complained over the next year or two. It was a huge improvement in both performance and costs.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#65Earlier quoted context omitted.
This, CF is the only service that I find amazing, and that I do not use for anything. Compared to AWS, I think I prefer the "we're your unopinionated infra provider, if you want a WAF we have that too", vs the CF "block the world, especially the developing world, give zero craps about it". I fundamentally would be unhappy as their customer even if their service were stellar because I do not want my apps to be associa…
The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…
I understand they don’t want get hacked but believe it or not, customers travel.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#66Earlier quoted context omitted.
I have to imagine CloudWatch makes AWS a lot of money too. Very often, when I look into an account from work that is spending a lot, CloudWatch is a large contributor.
Really? From Custom metrics, or logs? It's pretty rare that I hear anyone use it in production, there's usually either a SaaS like Datadog/New Relic or a homegrown setup with e.g. Prometheus.
Then, one month, I got a ~$500 bill out of no where.
Docker had changed an api causing my service to return 5xx errors all month. Each error was individually logged to CloudWatch - which racked up a ~$500 bill.
I moved to Cloudflare Workers that day and haven’t moved back.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#67Earlier quoted context omitted.
The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…
It’s so annoying when I travel and I can’t access login to my Utility provider’s website to pay my bill. I understand they don’t want get hacked but believe it or not, customers travel.
Security and convenience are always tradeoffs. I think 2FA is annoying as heck too (much prefer passkeys these days), or ridiculous password requirements, email passwordless login, etc., but those are all choices some admin or manager made on behalf of their business.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#68Earlier quoted context omitted.
This, CF is the only service that I find amazing, and that I do not use for anything. Compared to AWS, I think I prefer the "we're your unopinionated infra provider, if you want a WAF we have that too", vs the CF "block the world, especially the developing world, give zero craps about it". I fundamentally would be unhappy as their customer even if their service were stellar because I do not want my apps to be associa…
The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…
I feel like geoblocking is the easy way out, because if developing countries suddenly started waving their cards en masse, these merchants would find a way to let them in.
Speaking of card waving, it likely only appears that developing countries are not a large customer base because to merchants, they look like US customers.
Most African countries don't have access to Visa/Master cards, so often they'll have a US account where they can transfer some of their money. Others might earn in the US (like remote workers), and spend considerably in the US.
Then, because most merchants don't ship outside the US, these customers would use shipping forwarders, like myus.com.
So when making the decision to "block Nigeria because we don't really have any customers there", they're likely not considerig this potentially large customer base they're alienating.
Even worse, these are usually customers that do not have access to credit, only debit, so for example, when buying large ticket items (like a car), they tend to pay for it all upfront, so likely great customers.
Then there are the business customers, the ones what want to buy containers full of merchandise. Those too get blocked.
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#69Earlier quoted context omitted.
Not sure about the parent commender, but a few of the small SaaS companies I've worked with were regularly targeted by carding and credential stuffing attacks. I don't know whether the attackers ever realised much direct benefit from targeting them, I always thought they were just soft targets for validating credit card or credential lists. But if you don't have any DDoS protection set up, either of these attacks wil…
Those are completely different things though. If someone is trying to validate credentials/cards using your service, they're not trying to DoS it. Those types are usually using only a few IPs and are easy to detect/block (or even tarpit and help others) at app/proxy level. (Multiple failures for different usernames - block for some time) You need DDoS protection when someone does not want your service to stay up.
Regardless of whether or not it’s the intention of the attackers to disrupt the service, that’s the effect it can have, and it’s something DDoS protections service will usually mitigate, especially the services that incorporate WAF functionality (which I think is pretty much all of them?…).
Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees
#70Earlier quoted context omitted.
Is blocking users from Nigeria an official policy? Can anyone link me to either their official policy or to studies of which countries are blocked and how complete the block is?
CF blocks "bad rep" IP blocks. I think nigeria part was a joke