4 ms·
That assumes all users who are performing the attack are authenticated - an extremely unlikely scenario. All said users would also have to be able to pass a cap
by problems 10y ago
That assumes all users who are performing the attack are authenticated - an extremely unlikely scenario. All said users would also have to be able to pass a captcha which gets engaged in the case that a site is under active attack.
> the best CloudFlare can do to safe the back-end is to drop requests, which makes the attack successful
It can also drop the attack requests, which is generally not from authenticated users, and pass the real traffic to the backend.
Only in the case of real user, authenticated traffic is CloudFlare not a solution. In cases of high unauthenticated user or high fake user traffic or in cases of attacks not operating on HTTP at all, CloudFlare will solve the problem perfectly. Some of the nastiest attacks, like reflection attacks, don't even touch HTTP at all but will quickly knock most servers offline - even lead many server providers to nullroute you to protect their other customers. It'll also get you out in cases of high real user, unauthenticated traffic - like being posted on HN, reddit, etc.