5 ms·
> I'm about to graduate from a broke high-schooler to be a broke college student. I could reduce costs and run a minimal VM that acts as a WireGuard VPN server
by marcus_cemes 5y ago
> I'm about to graduate from a broke high-schooler to be a broke college student. I could reduce costs and run a minimal VM that acts as a WireGuard VPN server and proxy TCP using fancy firewall rules or whatnot, but that would also cost money.
Fellow student here. I love free tiers, but they can also be extremely frustrating. I actually prefer paying for reasonable priced services, that way you know what you're getting. For example I pay 2€/month for a 1vCPU/2GB Hetzner VPS with 20GB of storage, with 20TB of free egress (prices increased recently due to IPv4 shortage, they still charge me only 2€ however). That's about as much as a cup of coffee in CH, I can't recommend Hetzner enough. It could easily handle all traffic without Cloudflare. Having started to get a lot of spam through that domain, I'll take any protection that CF might be giving me. Also, setting up/maintaining Ubuntu from scratch has been extremely beneficial for me.
If you're limited by your location, there's nothing wrong with offloading to a VPS or running a reverse proxy. Considering you mentioned port 80/443, I imagine that a NGINX reverse proxy would be sufficient? It's basically your own mini-cloudflare proxy, only you're in control.
> I had used Cloudflare briefly before. My issue arose when I realized that they remove your SSL certificate, then use their own. Cloudflare is a big MITM service.
Why is this an issue? Any platform that serves requests on your behalf must be able to decrypt the request payload, I think any security expert would argue that having them use their own trusted certificate is much, much better than giving up the private key associated with your own certificate. Trust me, nobody (+/- 0.1%) checks the certificate when visiting your website... If they found a way to just forward on TCP packets, what useful service would they provide? A port-forwarding alternative? It's not so much a man-in-middle attack, you agree to a ToS and they provide a service. Ultimately, the DNS record is the authority on domain ownership, any server that is pointed to by the DNS record is authorised to represent that domain, and is sufficient to request a unique certificate from Let's Encrypt, for example.
> But I still don't like you.
Why not? I've been using Cloudflare for years, if only for the great DNS management panel. Of the "cloud" companies, they're my favourite. I believe Vercel use their infrastructure (they run their own datacentres), they're great to listen to on podcasts and have some interesting disruptive tech coming out, namely R2, which as a small filmmaker hobbyist, is truely a gamechanger for me. If their interests diverge from mine, I simply terminate my account and reasign the nameservers with my registrar. There's no lock-in.
- aborsy 5y agoAt Hetzner, 1vCPU, 2GB RAM, 20GB HDD is 4.15 euro per month. Still a bit cheaper than AWS Lightsail.
- brianzelip 5y ago>> Why not? > I don't like the centralization of the internet. Routing everything through Cloudflare, using Amazon AWS, all of it (in my opinion at least) harms the internet by consolidating power in the hands of just a few large monoliths.
- DenseComet 5y agoYeah I never understood the decryption issue either. Even if you don't use them, Cloudflare offers a lot of services that do need to understand what the payload is. Its like complaining an AWS ELB needs to decrypt traffic to load balance.
- abofh 5y agoTo be fair, [classic] ELB's do NOT need to decrypt traffic if you're really paranoid - you can load balance on TCP. Then it's only per-socket load balancing and you lose a lot of cloudwatch insights, but if you need truly end-to-end encryption, it's an option. I think you can do the same with NLB's. ALB's, however, have to terminate the HTTP so no choice there.