7 ms·
Cloudflare is a major source of centralization. The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but
by fivesigma 10y ago
Cloudflare is a major source of centralization.
The more providers offer something like this, the merrier. I understand that this isn't a layer 7 solution, but that has it's downsides as well - Cloudflare (or any other reverse proxy) will MITM all your TLS traffic, for example.
It's also time to address the elephant in the room: AWS. "Oops, you got DDOS'ed? Here, have a $50k invoice"
- majke 10y ago[disclaimer: I work for CF] CloudFlare also regularly speaks about attacks and mitigations, therefore is helping the community to build better defences. Other providers stay shy and never disclose their magic. We believe DDoS is an internet wide problem and one of the ways to solve it is to spread the mitigation know how. Examples: - DNS attacks https://www.youtube.com/watch?v=UcAygzNSxlI&t=2h13m20s https://www.youtube.com/watch?v=UcAygzNSxlI&t=2h13m20s - Iptables is great https://www.youtube.com/watch?v=pCVTEx1ouyk https://www.youtube.com/watch?v=pCVTEx1ouyk - Our DDoS mitigation pipeline https://www.youtube.com/watch?v=XiK4643YdOk https://www.youtube.com/watch?v=XiK4643YdOk - BPF for DNS https://blog.cloudflare.com/introducing-the-bpf-tools/ https://blog.cloudflare.com/introducing-the-bpf-tools/ - BPF for SYN https://blog.cloudflare.com/introducing-the-p0f-bpf-compiler/ https://blog.cloudflare.com/introducing-the-p0f-bpf-compiler... - Kernel bypass with netmap https://blog.cloudflare.com/single-rx-queue-kernel-bypass-with-netmap/ https://blog.cloudflare.com/single-rx-queue-kernel-bypass-wi... - NTP attacks https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ https://blog.cloudflare.com/technical-details-behind-a-400gb... - DNS amplification https://blog.cloudflare.com/deep-inside-a-dns-amplification-ddos-attack/ https://blog.cloudflare.com/deep-inside-a-dns-amplification-... - Recent attack trends https://blog.cloudflare.com/a-winter-of-400gbps-weekend-ddos-attacks/ https://blog.cloudflare.com/a-winter-of-400gbps-weekend-ddos... - L7 attack with ad networks https://blog.cloudflare.com/mobile-ad-networks-as-ddos-vectors/ https://blog.cloudflare.com/mobile-ad-networks-as-ddos-vecto...
- scrollaway 10y agoCloudflare gets so much undeserved hate on HN. You guys do amazing work, provide an incredible service and your writeups are awesome. Thank you.
- kristofferR 10y agoYeah, but they've also the "Wifi Captive Portal" of the internet, which frequently creates trouble (if you're using Tor for example).
- corobo 10y agoTor is used for abuse. If you want the privacy* you get with Tor the price you pay is that sites and services will check that you're not one of the abusers. At least it's not a flat-out ban. Any other large network on such a small IP space (as an example maybe a NAT-using mobile ISP) would be checked just as harshly. * Or any other reason you're using it. Edit: If I'm wrong can you please reply explaining why? I'm having an emotional rollercoaster of up and downvotes here! Please do feel free to correct me if I'm wrong, we all need learnin'
- rickycook 10y agothat's a pretty poor excuse. why is privacy only available by submitting to a poor experience? privacy should be default, not a punishment
- Karunamon 10y agoYou're looking at it purely from the user side. Look at it from the admin side. Tor is basically a massive open proxy, and by blocking it or throwing up human checks like captchas, you eliminate a significant source of spam and abuse. There's not much to be done about this otherwise - a Tor user is sharing a network with a significantly higher than usual amount of the bad elements of the internet.
- 10y ago
- eeZi 10y agoI work for a hosting company. Can confirm that CloudFlare's posts help us building our own defenses and I'm grateful that they're sharing their knowledge. So, thank you!
- mixedbit 10y agoCalling this "the elephant in the room" is very insightful. It surprises me that AWS is so often recommended as the best choice for new businesses without large capital. AWS automatically scalable infrastructure changes DoS outcomes from 'your server is down due to DoS', to 'your company is out of business due to DoS' (and for small company it doesn't even need to be a large DDoS, shell script on a single machine with decent link can generate substantial AWS cost).
- ljf 10y agoI've seen people state, in comments here and in blog posts, about DDoS attacks and also the resulting charge from Amazon - but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'. Do you have any examples of companies or individuals being help liable by Amazon for these costs? Totally prepared to accept I'm wrong, just going on my experience so far.
- Hupriene 10y agoUnless there is a contractual guarantee somewhere, that's not something I like to bet my company on.
- jerguismi 10y ago> but in every case that I've seen the person goes on to say 'after talking with Amazon they dropped this charge'. Negotiating the bill afterwards is an experience most people want to avoid, I think. I guess many would prefer a service where they don't receive the huge bill to begin with, even with other downsides.
- snowwrestler 10y agoCalling a reverse proxy company "MITM" seems kind of silly to me. It's not an attack, it's a service provider doing what their customers ask them (pay them) to do.
- CPLX 10y agoThe letters stand for "man in the middle" which seems to me a quite literal description of what's going on. The word attack isn't used.
- snowwrestler 10y agoI know what it stands for and it is the name of an attack. Try Googling "man in the middle" and see what all the results say. It is not a neutral term. When a service provider decrypts and filters traffic for you, it's usually just called decrypting and filtering traffic.
- rakoo 10y agoExcept MiTM is used primarily, if not exclusively, in attack scenarios. Otherwise any third-party you use as a website owner is a MiTM.
- deno 10y agoIf they’re stripping encryption and reapplying they’re MITM. Seems pretty straightforward.
- rakoo 10y agoIt's amazing how you can redeclare the meaning of words and distort reality just to fit your narrative. Stripping encryption implies that there was, at some point, some sort of encryption between the browser and the website itself, which there never ever was. In the Cloudflare architecture the browser never ever interacts with the website, always with the Cloudflare servers. When you've got the small lock, it never implied that you were connecting to the website, but always that you were connecting to what lies behind the domain name, which is the Cloudflare servers. As an additional point, the website owner has always agreed to use this architecture; they're not somehow victim of some kind of attack from a spooky middleman. They ask (heck, some of them even pay) for it. It is part of the way they want to serve content. You should tone down the sentimental analysis and keep to the facts. Cloudflare is a reverse proxy service the website owner uses; it is part of their infrastructure.