4 ms·
"5. Lack of dynamic resizing, only 20 “variants” allowed" Best practice when it comes to images on the web is to use a fixed number of sizes. Why they limited
by AtNightWeCode 5y ago
"5. Lack of dynamic resizing, only 20 “variants” allowed"
Best practice when it comes to images on the web is to use a fixed number of sizes. Why they limited it to 20 I do not know though. You should never allow dynamic image resizing since it is commonly used in various attacks.
- LukeLambert 5y agoThat’s why many image CDNs allow signed URLs. With Cloudflare Image Resizing, you’d need to implement that functionality using Workers.
- danielskogly 5y agoCloudflare is industry leading when it comes to facing those kinds of attacks, though, and it's supported in the "Cloudflare Image Resizing" [0] product. Also, using a fixed number of sizes might be best practice when it comes to a website you have full control over, and can plan the content for. When it comes to user-generated content, where you want to give the user the opportunity to select a custom crop for an image, you don't necessarily have that kind of control. The alternative we considered was doing the crop on the client before uploading the image, but that ensures loss of information, and makes it impossible for the user to edit their selection at a future time without re-uploading the image. [0]: https://developers.cloudflare.com/images/image-resizing https://developers.cloudflare.com/images/image-resizing
- jrochkind1 5y ago> You should never allow dynamic image resizing since it is commonly used in various attacks. Can you say or link to more? I'm not following this. Like... attacks... on Cloudflare?
- AtNightWeCode 5y agoI worked with sites that had performance issues because of attacks against dynamic image scaling in Cloudflare (scaling probably done with workers). Services like Cloudflare does not in general protect against service design issues. I try to explain that to people all the time. I also worked with another provider where a monthly bill got 5 times higher one month because images were requested at many different large sizes.
- rhizome 5y agoYeah, I've come across sites that allow arbitrary resizing via dimension numbers in the URL. Seems like it would be easy to CPU ddos by submitting random numbers in those fields.
- magicalhippo 5y agoAnd it's fairly easy to "snap" to the nearest available size variant. That way one can add cached variants after-the-fact.
- Aeolun 5y agoYou could do the same by requesting any dynamic page many times. Adding a rate limit to image resizing is no harder than adding it to any other URL.
- jrochkind1 5y agoHuh. I don't understand how this would effect a site using Cloudflare Images. It seems like maybe a DDOS against Cloudflare itself, but I don't see how it would be a problem for your site. But you say it was, so. But okay, thanks for providing more context. I have not used Cloudflare Images at all, so I don't really know, just trying to make sense of it.
- afavour 5y agoResizing an image is computationally intensive (at least compared to the average HTTP request). You can sidestep that by using caching: resize once, then serve the cached version from then on. Dynamic resizing opens you up to a DDOS attack, essentially: someone would request the image at 1x1, and 1x2, and 1x3... you get the idea. But yeah, if there was anyone able to mitigate that risk via other means you'd think it would be Cloudflare.
- deleted 5y ago[deleted]
- Aeolun 5y ago> Best practice when it comes to images on the web is to use a fixed number of sizes. What is the idea behind this? It doesn’t seem to add anything other than to leverage caching a bit better.
- ryan_lane 5y agoIt's a common DoS vector. If you limit the allowed sizes, you can predict your min/max for compute, storage, cache, networking, etc. If you allow arbitrary resizing, the client can iterate indefinitely, doing things like "give me 1x1, now 1x2, now 2x2", which will tie up your compute resources, eat up storage, push legitimate data out of your cache, etc.
- manigandham 5y agoAll major file/image upload services use signed URLs to prevent this. It's a minor abuse vector and not much of an issue. Cloudflare started as DDOS protection and should add similar features rather than limit functionality.