3 ms·
The OP has posted a follow-up, but it’s also from 2016: https://www.slashgeek.net/2016/06/07/cloudflare-making-internet-little-bit-faster-select-group-people/ h
by markonen 7y ago
The OP has posted a follow-up, but it’s also from 2016:
https://www.slashgeek.net/2016/06/07/cloudflare-making-internet-little-bit-faster-select-group-people/ https://www.slashgeek.net/2016/06/07/cloudflare-making-inter...
Two things that have changed since then are 1) Cloudflare’s Privacy Pass browser extension and 2) their significant network expansion, both of which would be likely to affect the experience described.
One thing that has not changed, however, is how many (typically unsophisticated) web site operators actively search their logs for signs of suspicious / bot activity and then institute manual blocks in the hope of catching all of them. This is often done with very blunt instruments, such as whole-country blocks.
In contrast, people who are confident about their infrastructure can deal with the background noise of the Internet appropriately—by doing nothing.
- judge2020 7y agoI think a sizable portion of the small websites that use CF are on so much of a budget that they use a $10/month VPS for hosting then turn to CF for "ddos protection" in order to handle any spikes in traffic that would take down their under-provisioned server. Issue here is that CF's layer 7 flood protection (that's even on the free plans, you can use the rate limiting service for smaller-scale floods) doesn't take effect unless you are really getting hit hard, the cutoff is probably 500 requests per second or more. When CF fails to protect against the small 30 request per second flood once, they're probably going to go through and add a bunch of aggressive blocks like blocking entire countries, as you've said.