Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

91–100 of 483 posts

Re: Cloudflare took down our website

#91

Earlier quoted context omitted.

How does paying $10k a month solve that?

For $10k / mo paid 1 year in advance, your cloud provider does a legal review of the situation and figures out how to make your problem work on both the technical and legal level. It's not a "special plan", it's consulting. Edit: "How do you know?" -- I don't know it's actually what happened, but when switching to enterprise, you don't go from 10% margin to 98% margin. The added costs actually represent added budget…

Great theory!

The only questions that come to mind: how do you know? If that was the case why didn't they tell the customer?

Re: Cloudflare took down our website

#92
post #79
post #64

It has become apparent that doing business with Cloudflare is a liability.

This is the nail on the coffin, but make no mistake, Cloudflare has been a liability. It's a massive Man In the Middle decrypting all traffic, including OkCupid and 4chan for example. Imagine all those 4channers learning they aren't actually anon.

That's literally their business and why people use Cloudflare.

Caching, detecting+modifying headers, routing traffic, ...

Re: Cloudflare took down our website

#93

- "This also means that if a country DNS-blocks our main domain, a secondary domain may still be available. This could arguably be seen as a violation of the Cloudflare TOS, as they wrote above." Attorneys love it when people put everything in writing like this.

Devil's advocate:

If a country A decides to block twitter.com but forgets to ban x.com which remains available ... is Twitter engaging in illegality / violation of CDN terms of service?

Re: Cloudflare took down our website

#94
post #34

Earlier quoted context omitted.

But for $10k a month cloudflare is ok with that? Either it's acceptable or it's not, there is no way that this looks good for cloudflare either way.

I'm not defending Cloudflare's exact actions in this scenario, but it seems reasonable that there are cases where yes, for $10k Cloudflare is okay. Risk can be mitigated, especially if you take care to know what the risk is, but risk mitigation and the salaries of the risk mitigation teams are not free. The answer of "no, we will not host you unless you pay us enough money to hire people to make sure we're not breaki…

And all of that is fine when communicated properly. Even if OP is an unreliably narrator are we to believe they also left out some of CF's emails?

To me it looks like https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_pr... is entirely the wrong email to send in the situation and if you are as old as I am and come from where I come from, you will have flashbacks to "reading between the lines" of the party daily in the 1980s. The real content is at the bottom:

> As we have a very short window to report back to Trust & Safety team, please let me know if you can make time tomorrow

Big red flashing lights: the right questions are 1) why is T&S involved at all 2) What are their concerns which forces such a hurried deadline? 3) What are the consequences of missing this deadline.

The right email would start with something like this:

> Providing services to your business constitutes serious legal risk to Cloudflare. We are happy to work with you in the future if you are buying an Enterprise plan. As we need to commit significant resources to accommodate you, we need an annual commitment. Otherwise, with much regret we need to terminate our services provided to you as it is our right per Terms on date/time. ("We may at our sole discretion terminate your user account or Suspend or terminate your use or access to the Service at any time, with or without notice for any reason or no reason at all.")

> This plan would also include these features:

Re: Cloudflare took down our website

#96
post #66

This is my first post on Hacker News as I primarily just browse. This situation kept me intrigued, wanting to know how it would unfold. The Google Cloud situation and all these little happenings, including the proliferation of Gen AI into everything, make me long for the days when companies had their mainframes onsite, in closets or separate rooms, away from CDNs and cloud networks. It seems like a better idea to use…

Did you ever notice the bit in EULAs that states that maximum liability to the vendor is capped at what you paid?

When big cloud goes down, you get a few days of credit. That's it.

Re: Cloudflare took down our website

#97

Sounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.

Hmm. My take is the casino structured its business to comply, not to evade interest. Further, I don't see how Cloudflare benefits by taking on the risk to charge more to help a customer avoid scrutiny. More like: they know it's a humming business and want a piece.

Compliance:

> We do have multiple domains that mostly act as mirrors to our main domain. We have these for a few reasons. One is that since we are a casino, we have different regulatory requirements we need to comply with in many countries.

Evasion:

> Another is that we use them to target different global user groups and affiliates and track conversions long-term. This also means that if a country DNS-blocks our main domain, a secondary domain may still be available.

This is more like one gang hitting up another for "protection" payments. I had to laugh when they called it "Trust & Safety".

Re: Cloudflare took down our website

#99

Sounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.

Hmm. My take is the casino structured its business to comply, not to evade interest. Further, I don't see how Cloudflare benefits by taking on the risk to charge more to help a customer avoid scrutiny. More like: they know it's a humming business and want a piece.

The way I read the screenshots of the emails from the articles seemed to suggest that something the authors company was doing was causing issues with IP reputation on CloudFlares range.

Them very aggressively highlighting the BYO IP feature and then even suggesting third parties to rent IPs from strikes me as a significant detour from their normal “script” (having dealt with their AU sales team before).

Re: Cloudflare took down our website

#100

Earlier quoted context omitted.

A reasonable scenario to me seems to be: An automatic "upgrade to the enterprise plan" requirement was triggered, and then in the process of the sales calls to make that happen, Cloudflare got serious eyes on the customer for the first time (whereas at a paltry $250/month previously they wouldn't have), and realized exactly what line of business the customer was involved in, and decided to fire them.

This actually seems reasonable, and a potential part of the narrative the original poster would be likely to leave out.

Again, none of this explains why they asked for 120k/year and shut it down after they didn't pay.

It doesn't matter the reasoning - its the execution wherein lies the issue - this is an extortionary business practice plain and simple.

By the way, it appears gambling sites are fine on CF [1].

[1] https://community.cloudflare.com/t/using-the-services-for-on...

Post reply on HN