5 ms·
> JUST STOP MASS BLOCKING. You literally have no reason to. As someone who has dealt with massive influx of requests caused by bad actors who use everything in
by mikeortman 4y ago
> JUST STOP MASS BLOCKING. You literally have no reason to.
As someone who has dealt with massive influx of requests caused by bad actors who use everything in their arsenal to mask their behavior, yes they do. It may not be ideal by any means, but DoS attacks can be very, very expensive and being extra trigger happy on the ban is the difference between an operational site to most to an unavailable site for all.
- daqhris 4y agoThe reasons behind mass blocking can be understood if your run a website and manage online servers. I resorted to putting my website under a Cloudflare firewall. I benefit from it by getting web traffic stats and keeping away the bad requests. Many bots are set up with Tor and automate their browsing. It would be impossible for me to pay fees in order to fend off DDOS attacks. My site is awalkaday.art. The amount of bad requests, per Cloudflare classification, goes up to 70-90% of regular web visitors. Imagine if you have to service 9 unidentifiable/shady customers, out of 10 people visiting your online store? It's not financially wise to allow anyone to deplect hardware resources (i.e: servers) of a new internet services. Moreover, these bad requests don't improve the growth or bring in revenue. The world wide web is too wild. Its unregulated in the sense that anyone from anywhere can start and successfully run an army of bots to scour the Internet for specific purposes. I'm happy that Cloudflare can help mitigate some security issues before they occur.
- notpushkin 4y ago> The amount of bad requests, per Cloudflare classification, goes up to 70-90% of regular web visitors. Or do they just make them up?
- theamk 4y agoIf you mean that those requests were not made at all, then it's unlikely, as this is trivial to check: repoint DNS directly to your server and watch. CF seems to care about their reputation, so I don't think they would do something that is so simple to disprove. If you mean that those requests were actually "good" (real humans) but CF mistakenly mark them as bad... then yes, this probably happens. For example, I have old tablet which regularly gets CF captcha, and sometimes this causes me to abandon some websites rather than solve it. I am sure that this appears in the logs as "bad" request -- after all, how can you tell frustrated human from defeated bot/DDOS? But for many sites, the question is not "captcha vs same content no captcha" but rather "captcha vs significantly reduced functionality"... so at least for me, occasional captcha is worth not having to login / having full-resolution images etc...
- photoGrant 4y agoTo be fair I have stats for my site that before Cloudflare barely got a look-see, but when I ran it through Cloudflare for a private zero tunnel, the requests from all over the world were in their thousands by a few days. Seemed fishy, but never questioned it.
- sli 4y agoThe only thing I can think of is some bad actor that constantly tries CF websites to try and find a hole that can be exploited. Otherwise that does sound pretty fishy.
- uconnectlol 4y agoI thought HN of all places would understand this: The Cloudflare captcha is not for DDoS. It's for the rest of the "security" issues Cloudflare markets itself as a solution to: > The problem is Tor exit nodes often have very bad reputations due to all the malicious requests they send, and you can do a lot of harm just with GETs. Content scraping, ad click fraud, and vulnerability scanning are all threats our customers ask us to protect them from and all only take GET requests. https://blog.cloudflare.com/the-trouble-with-tor/ https://blog.cloudflare.com/the-trouble-with-tor/