Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

71–80 of 483 posts

Re: Cloudflare took down our website

#71
post #46

Sounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.

Taking a step back, why would they even care if their platform is supposedly neutral and not responsible for the content ? If they can indeed stop providing services to a casino, why cannot they shutdown a website spreading pro-war propaganda, or a website selling illegal services ? It means they are making editorial choices, instead of just being the technological provider and being a neutral "internet pipe". Not su…

> Not sure it's really in their best interest to self-police in the end, as they could lose their DMCA safe harbor provision ?

This.

That said, we're seeing this across so many platforms, from datacenters to social network sites.

They blew their safe harbor provisions years ago and yet remain untouched despite this.

Re: Cloudflare took down our website

#72

Earlier quoted context omitted.

How does paying $10k a month solve that?

For $10k / mo paid 1 year in advance, your cloud provider does a legal review of the situation and figures out how to make your problem work on both the technical and legal level. It's not a "special plan", it's consulting. Edit: "How do you know?" -- I don't know it's actually what happened, but when switching to enterprise, you don't go from 10% margin to 98% margin. The added costs actually represent added budget…

Or they had already decided to kick them out and tried to get some money out of them first.

Re: Cloudflare took down our website

#73

Earlier quoted context omitted.

But for $10k a month cloudflare is ok with that? Either it's acceptable or it's not, there is no way that this looks good for cloudflare either way.

That's not true at all. That line of argument gets close to "if this product is free for open source, why is it not free for me? either it costs something to operate or it doesn't." You don't get to price the service.

In this case "the service" would be to look the other way on illegal activities for $10k/mo.

I'm not saying cloudflare can't do it, I'm just saying it's wrong.

Re: Cloudflare took down our website

#74

Sounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.

I mean, sure, they’re probably doing some sketchy regulatory dodging or whatever. Which part of this can Cloudflare solve by having them pay $120k/year to them?

The post mentions BYOIP. I assume Cloudflare wanted OP on BYOIP to mitigate risk, and Cloudflare wanted them to pay for the privilege.

Re: Cloudflare took down our website

#75
post #39
post #25

Earlier quoted context omitted.

The point is more that the author is an unreliable narrator and you need to apply a little salt to the rest of the story. Cloudflare absolutely shouldn't be taking bribes to permit regulatory evasion. But if they are, I want more evidence than a substack post.

It also seems strange they dont know their Traffic Numbers. >Note that 80TB is the number they tried to sell us, I don’t know if it is accurate since they removed all our access to historical analytics. I mean you dont need accurate Data but surely most would know by heart their traffic in rough figures? Or am I the old dog where every new Web Dev are so used to Cloud and Serverless they have no idea what they are us…

People seem to have a very laissez faire take on egress which I’ve never understood given the really impressive markups the cloud providers charge on it. But yeah, it seems like the attitude is that as long as you’re using “cloud-native” services (AKA locked-in proprietary offerings) then cost is low and doesn’t matter anyway because it’s opex, not capex.

I spend a lot of time wondering if the Emperor is wearing any clothes.

Re: Cloudflare took down our website

#76
Notable, their Enterprise plan quote included BYOIP. I think that's the kicker. Cloudflare likely got a few of their anycast load balancing IPs blocked in one country, causing a huge disruption, because this customer that makes them no money wasn't in full compliance with local laws.

Re: Cloudflare took down our website

#77
I have been hearing stories from developers/entrepeneurs about Cloudflare being very weird to deal with:

"We'd like to talk to you about an enterprise plan."

"No thanks, I'm fine with the free plan."

"Based on your traffic, we'd like to talk to you about an enteprrise plan."

"Is there a traffic limit on the free plan?"

"No, there is no limit. But based on your traffic, we require you to get an enteprirse plan."

[Gives up and gets an enterprise plan]

[6 months later]

"Based on your traffic, we'd like to talk to you about up'ing your enteprise plan to a new monthly pay."

"Is there a cap to traffic in our current plan? I don't see that in our terms."

"No, there is no cap to traffic in cloudflare plans, but based on your traffic, we're going to require you to pay more per month than you are currently paying."

"OK, can you tell me the traffic limit in our current or new plan? So I know what I'm paying for and when I'm approaching it?"

"No. But you need to pay more."

[Wash, rinse, repeat, every 6-12 months]

It seems like while cloudflare technically does not charge for egress, in fact for large egress it's just a game of chicken between the customer and a salesperson every 6-12 months, with the salesperson trying to figure out the most they can manage to get without losing the customer? I mean, I guess that is standard for enteprise sales, but I think usually you at least have some terms to know what you've got for how long without a renegotiation?

Re: Cloudflare took down our website

#78

> When we told them we were also in talks with Fastly, they suddenly "purged" all our domains Holy shit.

What’s especially shocking is how closely coupled sales and engineering are. Like I get they talk, but for a sales call to end in engineering pulling the plug…

To me it's pretty clear: Trust & Safety (NOT engineering; they don't appear to be involved) likely raised an alarm saying "Customer X is breaking TOS - no immediate resolution available, but something might be possible given extensive legal & engineering review. Recommend switching to enterprise so we can study how to make it work."

In that light you can see why Sales would be sent as the messenger. But I agree they shouldn't have been involved. Sending a T&S representative would have been better. But then again it looks like from screenshot #2 that they kind of did that? They just didn't have a direct call with T&S.

Re: Cloudflare took down our website

#79
post #64

It has become apparent that doing business with Cloudflare is a liability.

This is the nail on the coffin, but make no mistake, Cloudflare has been a liability. It's a massive Man In the Middle decrypting all traffic, including OkCupid and 4chan for example. Imagine all those 4channers learning they aren't actually anon.

Re: Cloudflare took down our website

#80

Sounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.

Using localized versions of your services to comply with regional laws and enhance user experiences (i.e. make money) is SOP for practically every international $bigco. Online gambling is regulated and legal in ~50%-70% of the world; without actual evidence to the contrary, it’s completely reasonable to assume that this is a legitimate business. I’m really struggling to agree with the “two sides to every story” replies being left here about how there’s likely shady activity going on behind the scenes, when to me the post read as candid and transparent about the nature of the nature of the business, the admitted legitimacy of CF’s TOS violation claims against them, and the content of the communications with CF.

My 2c: It’s scummy that CF did this. It looks like they were disingenuous about the severity of the violations and used it as an excuse to get more $$$ from an already paying customer to make the manufactured problem go away.

Post reply on HN