5 ms·
It's becoming unusual not to see sites behind CloudFlare now, pretty neat from a routing standpoint and devastating to user privacy and security on the whole. I
by steckerbrett 11y ago
It's becoming unusual not to see sites behind CloudFlare now, pretty neat from a routing standpoint and devastating to user privacy and security on the whole. If things continue in this direction we'll have the cloudflare, and some scraps of regular internet off the side.
- dangrossman 11y agoThe more popular it becomes, the more incentive there is for other companies to enter the space and grab a chunk of the money. The barriers to entry are not insurmountable for e.g. existing CDN companies to start offering DNS, WAF and DDOS mitigation products, making them more like Cloudflare. They already have the peering/hosting relationships and engineering teams experienced at working with large volumes of traffic. I wouldn't be too worried about Cloudflare taking over the internet this early on.
- TheSisb2 11y agoTo continue with your point, we use https://sucuri.net/ https://sucuri.net/ where I work because it has such a great set of tools and extension for our Wordpress blog, which kept getting hacked. Lots of space in this area.
- dangrossman 11y agoGood example: "Sucuri is Building a Comprehensive Alternative to CloudFlare" http://wptavern.com/sucuri-is-building-a-comprehensive-alternative-to-cloudflare http://wptavern.com/sucuri-is-building-a-comprehensive-alter...
- steckerbrett 11y agoIs there reason for people to enter a market with a single obvious leader though? I got the impression that making peering agreements with people on any sort of scale was a bit of a bear. It is already quite ubiquitous, a surprising number of websites use it even if it's not completely obvious, reddit.com has some sort of stealth configuration that bypasses the normal DNS setup for example.
- toomuchtodo 11y ago> Is there reason for people to enter a market with a single obvious leader though? Were there not search engines before Google? Isn't AWS the cloud computing "leader" while Google is trying to break into the space? There is no such thing as an obvious leader, only juicy prey waiting for the next hungry org to eat its lunch. > I got the impression that making peering agreements with people on any sort of scale was a bit of a bear. Hardly. Peering agreements are of similar difficulty level as any vendor negotiation, whether it be with a specific network or an interconnection fabric (IXP).
- manigandham 11y agoThat's how the market works... otherwise we wouldn't have any new companies if everyone gave up before competing with the big guys. There's a lot of potential to do better against anyone.
- Someone1234 11y agoThat's a lot of hyperbole there. If you look at the top 500 websites very few of them are behind CloudFlare, CloudFlare's penetration seems to be SMBs mostly (since larger orgs can afford the in-house mitigations that CloudFlare offers).
- steckerbrett 11y agoDid you know reddit is? You wouldn't know it from looking at the WHOIS, I'm betting lots of places are behind it without showing the normal indicators. Name Server: CNS1.REDDIT.COM Name Server: CNS2.REDDIT.COM Name Server: CNS3.REDDIT.COM Doesn't look like it from here.. ;; ANSWER SECTION: CNS1.REDDIT.COM. 172246 IN A 173.245.58.24 Delegated to? OrgName: CloudFlare, Inc. OrgId: CLOUD14 There we go! CloudFlare after all.
- nulltype 11y agoIt might be easier if you use curl. curl -I https://www.reddit.com https://www.reddit.com HTTP/1.1 200 OK Server: cloudflare-nginx
- joshmn 11y agoThose top 500 websites have the money to sit atop of CloudFlare's enterprise plan, which I believe offers custom-branded DNS servers.
- AdmiralAsshat 11y agopretty neat from a routing standpoint and devastating to user privacy on the whole I'm interested. Please expand on the privacy point. I thought the general move to CloudFlare was a good thing for privacy, as it provides an easy mechanism for getting sites onto HTTPS without having every site to worry about managing certificates.
- ceejayoz 11y agoIf CloudFlare is compromised by an intelligence agency or forced by law enforcement and courts to cooperate, they're a large single-point-of-failure for privacy.
- MichaelGG 11y agoAdditionally, a lot of sites probably just use CFs crypto, without securing it to their backend servers. Hence there could be less encryption overall.
- duskwuff 11y agoIndeed, CloudFlare will happily run an HTTPS front-end proxy to an origin which is using a self-signed certificate, or even to a HTTP origin. Thought that site was secure? Think again!
- slipstream- 11y agoIf the origin used a self-signed cert, doesn't cloudflare use certificate pinning?
- devbug 11y agoLess severely, they themselves know the vast majority of sites users are visiting and the content they're being served. Valuable stuff for advertisers, among others.
- deleted 11y ago[deleted]
- orf 11y agoit’s routed through a high-performance interconnect instead of the public Internet The public internet does seem to be shrinking, more and more closed data silos and now huge chunks of traffic going through a 'trusted' man-in-the-middle. From an individual sites standpoint it's amazing (and I use it for most of my sites), but the bigger they become the more juicy a target they are.
- rakoo 11y agoIs this not some kind of peering, though ? The way I see it, Cloudflare decided to peer with Google instead of using transit or, even worse, public internet (with the overhead it has over AS-to-AS connections). I don't see how the "public internet" somehow lost anything.