Live data from Hacker News

Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

blog.cloudflare.com

91–100 of 168 posts

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#91

Earlier quoted context omitted.

The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…

I am convinced that while harder, there are more intelligent ways to block these DDoS attacks other than blocking entire geographies. I often travel between Africa and US, and there are things like buying furniture (home depot blanket blocks non US customers, but they would simply allow shipping only to US addresses), buying cars (there are large car sites that don't allow browsing from outside US, even if you've alr…

As a business owner who geoblocks:

It's not usually a benefit to a business if a customer pays upfront.

Whether my customer pays by debit or credit, I get all of that money upfront before I let the transaction proceed.

Some businesses, like car dealers, actually make more money if the customer buys using debt, because they get incentivized by the loan company.

And lastly, the sheer scale of the US economy means that it's really not worth the hassle. All of Africa would be equal to one of the larger states (Wikipedia says $3T, Texas is 2.1T and Cali is 3.5T).

So it's vastly simpler, cheaper, and easier to deal with say 30m Texans or 40m Californians than literally 1.3 billion people in Africa or India, and you get roughly the same total addressable market and a fraction of the bots & scams.

Hence why many sites simply block non-North American traffic.

I wish we lived in a world that was more fair and open, but a couple of bad actors can really ruin things for everyone.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#92
post #75
post #4

It's a seemingly simple and obvious way to lazily migrate your data, but if using Sippy means one less thing for the application code to worry about, and (I assume) is a free add-on, then it provides a ton of value. I have to admit that Cloudflare has been killing it recently with DevX / OpsX. If I wasn't against that company's role in modern internet (as a user of Tor, their firewall is annoying to no end), I would…

What's the alternative if most of tor traffic is password attempts and bad actors how do you protect yourself from tors bad actors without effecting all of tors users. I work at a company that runs a large website top 1000 websites in the world, and we don't even have to block tor exit nodes since they trigger our bot and snap blocking rules on our firewall, how do we let valid for users through without letting all t…

My take on this: if there is some DDoS taking place from same IP I am connecting from, that sucks for me but I'm willing to tolerate it (good old fail2ban). But having such a firewall all the time, even when you are getting less than 1 request per second from ToR? That's an overkill

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#93

Earlier quoted context omitted.

I am convinced that while harder, there are more intelligent ways to block these DDoS attacks other than blocking entire geographies. I often travel between Africa and US, and there are things like buying furniture (home depot blanket blocks non US customers, but they would simply allow shipping only to US addresses), buying cars (there are large car sites that don't allow browsing from outside US, even if you've alr…

> I am convinced that while harder, there are more intelligent ways to block these DDoS attacks other than blocking entire geographies. Sure. Even by default, Cloudflare won't block entire countries. That's a CHOICE some businesses make if the default blocks aren't enough, and they don't have the time or resources to configure more nuanced WAF rules. (OWASP isn't exactly straightforward). Edit: For example, at that j…

I'm aware of this, CF can be very granular, but businesses do not on average have the know-how or bandwidth to properly setup their rules to not come off like a...holes. So the effect is that most businesses behind CF come off like a...holes. My point is CF does not seem very interested in coming up with a better solution, like maybe a list of CF managed WAF profiles that work well and don't make both the businesses and CF seem like they do not care. Those profiles could be paid.

And yes! it's better to buy local, and Africa can't blame the US because our economy isn't there, and we aren't building all the things we should be building. But that is an entirely different discussion isn't it?

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#94

Is Cloudflare requiring you to switch to Enterprise plans if your usage is above some threshold? In a previous discussion on HN about Cloudflare, a good half dozen people replied saying they got calls when their usage increased above some level that they had to switch to an enterprise plan, and AFAIK those start at $5K/month (from a brief talk with sales a few weeks ago). We have tens of TB in AWS that we'd like to m…

$5k/month is just Cloudflare's opening bid. In Enterprise sales, you are expected to negotiate for a discount. Common rule of thumb is that Enterprise sales (in general, across vendors) start at ~$2k/month (this is what's necessary to pay for salespeople's salaries) and savvy negotiators will end up close to that figure for bare-bones plans.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#95
post #75
post #4

It's a seemingly simple and obvious way to lazily migrate your data, but if using Sippy means one less thing for the application code to worry about, and (I assume) is a free add-on, then it provides a ton of value. I have to admit that Cloudflare has been killing it recently with DevX / OpsX. If I wasn't against that company's role in modern internet (as a user of Tor, their firewall is annoying to no end), I would…

What's the alternative if most of tor traffic is password attempts and bad actors how do you protect yourself from tors bad actors without effecting all of tors users. I work at a company that runs a large website top 1000 websites in the world, and we don't even have to block tor exit nodes since they trigger our bot and snap blocking rules on our firewall, how do we let valid for users through without letting all t…

How would you deal with an attack though residential US proxies? Your method falls apart.

How many of us deal with automated password attacks is to issue questions that only locals or people with specific knowledge could answer. Change the questions and do everything custom.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#96

Earlier quoted context omitted.

Cloudflare doesn't hate Tor. Blocking Tor is purely a customer configuration

>Blocking Tor is purely a customer configuration ...that's on by default and so used by the vast majority of Cloudflare customers making it effectively a Cloudflare configuration.

I'm pretty sure it is not on by default and cloudflare also provides onion routing by default so it even helps legitimate Tor users.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#97

Earlier quoted context omitted.

I am convinced that while harder, there are more intelligent ways to block these DDoS attacks other than blocking entire geographies. I often travel between Africa and US, and there are things like buying furniture (home depot blanket blocks non US customers, but they would simply allow shipping only to US addresses), buying cars (there are large car sites that don't allow browsing from outside US, even if you've alr…

As a business owner who geoblocks: It's not usually a benefit to a business if a customer pays upfront. Whether my customer pays by debit or credit, I get all of that money upfront before I let the transaction proceed. Some businesses, like car dealers, actually make more money if the customer buys using debt, because they get incentivized by the loan company. And lastly, the sheer scale of the US economy means that…

When I say pay "upfront", I don't mean that the upfront cash is better for business, but that usually, the credit industry is very good at letting people buy things they can't afford. Some one who pays upfront likely can afford and might have higher lifetime value. Someone to advertise to, upsell, or whatever.

Secondly, I also get it, there's only so many things a business can worry about, and supporting geographies with historically high fraud rates is not high on the list, this is why my gripe here is with CF that does not make it easier to improve this even though they know they control such a huge chunk of the web.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#98
post #6

Earlier quoted context omitted.

This, CF is the only service that I find amazing, and that I do not use for anything. Compared to AWS, I think I prefer the "we're your unopinionated infra provider, if you want a WAF we have that too", vs the CF "block the world, especially the developing world, give zero craps about it". I fundamentally would be unhappy as their customer even if their service were stellar because I do not want my apps to be associa…

The geographical blocks are not enforced by Cloudflare as a blanket ban, but are chosen by each account owner (it's a setting you configure). I've worked with a few companies that saw this as a very valuable service (like small domestic companies blocking international traffic, especially from Russia and China, because we had no presence there anyway and that cut down bot traffic by like 95%). Likewise, TOR access is…

I don’t understand the parent viewpoint.

“I don’t like Cloudflare because they’re trying to centralize the Internet and block me”

It’s not as though Cloudflare goes out and randomly inserts themselves in Internet traffic and has some blanket policy of ruining TOR or blocking you.

Cloudflare has customers (site hosts) that have choice in the marketplace and choose them. The customer configures whether their services use Cloudflare or not. The customer configures TOR access, CAPTCHA level, geoblocks, and any other number of hundreds of parameters.

Then people get mad at Cloudflare when a site/host selects Cloudflare and configures it in a way that blocks them?

Cloudflare is selling what people want to buy and providing the service in the way they configure it. If you have a problem with that take it up with the site/host/CF customer, I truly don’t understand how/why they can or should be blamed for their success.

I think what you’ll find is that many Cloudflare customers are practical and pragmatic. Want access to our site over Tor? Sorry but Tor is 99.999% shady/malicious traffic we don’t care about. The risk vs reward isn’t there so blocked. Maybe if a customer says something we’ll enable it but that has never and will never happen so blocked.

Our PCI scans and auditing systems are showing weird traffic from Asia even though we have no customers or business there? Blocked.

Repeat this for any other number of factors and you can start to understand why Cloudflare has double the market share of their nearest competitor (AWS Cloudfront).

They offer a product suite site owners and hosts love. The collateral damage from a tiny fringe of legitimate users who get stuck in the CAPTCHAs, use tor, etc just don’t matter to the site hosts. If they did they would configure Cloudflare differently or leave them altogether.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#99
post #87

Is Cloudflare requiring you to switch to Enterprise plans if your usage is above some threshold? In a previous discussion on HN about Cloudflare, a good half dozen people replied saying they got calls when their usage increased above some level that they had to switch to an enterprise plan, and AFAIK those start at $5K/month (from a brief talk with sales a few weeks ago). We have tens of TB in AWS that we'd like to m…

AFAIK R2 is priced completely separately on a pay as you use basis. Have you got a link to these replies?

I've done some searching around, but can't seem to find the thread where this came up. It was in the replies to some HN post, and there were 4-5 top level comments all saying the same thing. Wish I would have bookmarked it or something.

Re: Cloudflare Sippy: Incrementally Migrate Data from AWS S3 to Reduce Egress Fees

#100

Is Cloudflare requiring you to switch to Enterprise plans if your usage is above some threshold? In a previous discussion on HN about Cloudflare, a good half dozen people replied saying they got calls when their usage increased above some level that they had to switch to an enterprise plan, and AFAIK those start at $5K/month (from a brief talk with sales a few weeks ago). We have tens of TB in AWS that we'd like to m…

I specifically asked this question to Sales and they told me no. There probably isn't an official policy and it's up to the discretion of the people involved. In my case I had 100 MB of data on S3 that I was serving to a lot of users (250 TB - 500 TB of egress per month). This is free for me on R2 because you aren't billed for requests served from cache and we have a 100% cache hit rate. I was very up front about this to sales and they said they didn't care as long as we paid for some kind of support package. We were paying for the $20/mo plan but later elected to upgrade to the $200/mo plan. Not a bad deal since the data transfer from AWS alone was more than $20,000.

I don't want to take advantage of them and get on their abuse list since this is production. I'm happy to pay more! I just don't want to deal with negotiating an Enterprise plan. They ask you so many questions like "how many Page Rules do you want? How many Worker requests?" I just want R2. And this response confuses them too because they say "well R2 is pay-what-you-use..." I would honestly be happier with a $5000/mo "excessive R2 bandwidth" fee. But they don't seem to want to implement that.

Post reply on HN