6 ms·
This boils down to 'Cloudflare did something' and without the Enterprise plan you'd never be able to pull the data required to diagnose the problem. Oh also, Cl
by a2tech 4y ago
This boils down to 'Cloudflare did something' and without the Enterprise plan you'd never be able to pull the data required to diagnose the problem. Oh also, Cloudflare knows they did something but plays the blame game until you get to someone that openly acknowledges that they know something is broken.
I've said it before and I'll say it again--Cloudflare is not making the Internet safer, its just making it less open. I know that is not the overwhelming sentiment of HN and me complaining about it isn't going to change anyones mind.
- cuuupid 4y agoAs a bit of a meta point it’s a bit astonishing how good Cloudflare is at PR and community management. The sentiment I’ve seen here in the past is overwhelmingly pro-Cloudflare. Every now and then they’ll publish a hit piece on AWS here and there’ll be an AWS hate thread, but no one seems to question Cloudflare’s motives for promoting bad press about their competitor directly to their target market. Then again in most things, the underdog trying to upstage the incumbent is always a popular narrative. You’re right that talking about it likely isn’t going to change any sentiment.
- throwaway2847 4y agoHN is like any other community and is thoroughly captured by some hype machines (Cloudflare, the language that shall not be named) and virulently opposed to others (cryptocurrency)
- jcuenod 4y agoWhat are you talking about? Java doesn't have a hype machine...
- groffee 4y ago> it’s a bit astonishing how good Cloudflare is at PR and community management It's really not, look at any cloudflare support thread here and how they crawl out of the woodwork for damage control because they failed in basic customer service it's a huge red flag, and everyone in the comments always sees it. cloudflare is cancer and needs to die.
- Jamie9912 4y agoCloudflare isn't really to blame here when the customer has FULL control over all security settings - they can define rules as they please, and have all the tools (including the API) to do this
- davedx 4y agoHuh? In this case, CloudFlare updated the OWASP ruleset, causing Troy's payments integration to break. That's not nice DX in my opinion.
- Jamie9912 4y agoCustomer should be aware that they are relying on Cloudflare defined rulesets and should understand that they change
- aniforprez 4y agoThis sounds like victim blaming honestly. If Troy Hunt, one of the most well known security researchers around and who's been running HIBP for almost a decade now ends his blog post with effectively a shrug saying "I dunno what happened" how is any reasonable customer who doesn't have access to the Enterprise plan supposed to debug any of this especially when Cloudflare themselves barely admitted fault? They even tried rolling back the OWASP ruleset and it didn't change a thing. He had to manually add the exceptions to the firewall. This is arguably terrible DX
- Jamie9912 4y agoI feel like Cloudflare could do a lot better at letting the customer know they are using rules managed by them and how that affects their traffic. But at the end of the day, enterprise customers should be experts at this (and in many cases have people employed whos job is literally for this) - and they have all the tools available to them
- aniforprez 4y ago
- aestetix 4y agoAnd don't forget, if they don't like you, they will happily deactivate your account with no notice and no reason given.
- weird-eye-issue 4y agoSource?
- imwillofficial 4y ago[flagged]
- sudhirj 4y agoBit hyperbolic, no? Maybe rephrase to "if you engage in Neo-nazi hate crime and promote real world harm, they'll deactivate your account after much internal deliberation on their role as gatekeepers and will publish a post with clearly stated rationale"? I'm not advocating Cloudflare, but I do think we need to be fair when judging stuff like this.
- jaywalk 4y agoYour description of what happened is a bit hyperbolic as well. I remember this event, but the details are pretty fuzzy. IIRC, it stirred up so much controversy precisely because no US laws were broken. So saying "engage in Neo-nazi hate crime and promote real world harm" is inaccurate. The content was garbage, no doubt about it. But let's not get hyperbolic in the other direction either.
- JohnFen 4y ago"no US laws were broken" != lacking in harmful activities.
- ASalazarMX 4y ago> no US laws were broken People keep confusing private organizations and governments. They don't need to break any laws to become undesirable customers, and any private company that tolerates these kind of customers does so at their own discretion. The world doesn't owe them a right to be awful people, but they can still be awful if they accept the consequences.
- carapace 4y ago> Cloudflare is not making the Internet safer, its just making it less open. They're doing both, eh? I switched my family's home DNS to Cloudflare's family-safe DNS ( https://blog.cloudflare.com/introducing-1-1-1-1-for-families/ https://blog.cloudflare.com/introducing-1-1-1-1-for-families... ) to protect them from malware and porno (I'm not a prude, they don't use the Internet for that (no really! We are weirdos.) and porn sites are often a malware vector anyway.) A few months ago I noticed that you can't browse weed stores through their DNS anymore. I don't really blame them, I'm assuming it's due to pressure from the US Federal Gov. (who still consider pot to be some insanely dangerous narcotic!) But it was definitely a personal "until they come for you" moment.
- JohnFen 4y agoThis sounds like perfectly reasonable behavior, not needing any pressure from government agencies. I would assume that anything purporting to filter the internet to be "family safe" would exclude weed stores, as well as liquor stores, tobacco stores, and anything else that most people would consider inappropriate for children.
- JohnFen 4y ago> Cloudflare is not making the Internet safer I am certainly not a fan of Cloudflare and woudn't use their services, but I think this is not an accurate statement. Their services do objectively provide a security benefit. The only question is really whether or not the cost/benefit ratio is favorable.
- fmajid 4y agoOnly if you discount the impact on users who are blocked like those on VPNs, or myself because Cloudflare seems to dislike my ISP, and have no recourse.
- throwawayapples 4y agoTry getting a fresh IP from your ISP. I had a single IP that was blocked (incredibly annoying, and apparently impossible to have cloudflare fix it), but triggering a DHCP change caused me to get a good one.
- fmajid 4y agoThey use CGNAT, having even a dynamic IP that’s all yours for a few days is sadly becoming a thing of the past as the IPv4 address crunch grows worse but Western ISPs and enterprises still procrastinate on IPv6 adoption.
- JohnFen 4y agoThat sort of thing falls into the "cost" category.
- canes123456 4y agoYes, even considering this the benefits out way the costs. I use cloudflare competitor at my work. Ideally all APIs would never have security issues and always have amazing rate limiting. In practice, this is never the case. What I use stops low skilled attack on the scale of millions of malicious requests per day against thousands of false positives. (still way too high) In addition, when the high skilled attacker find a massive hole it also slows down them down so that they get thousands of requests in vs millions. In addition, it let you block them much faster than needing a new deployment and let have another way to detect them. Is there other ways to do this? Yes. By the time you implement everything will hackers stolen millions of dollar from your customers? Probably
- Lt_Riza_Hawkeye 4y agoOverall I agree with you - the only caveat I have to offer is Cloudflare's support of eSNI. My opinion on CF used to be quite black and white, but there is at least someone in there (for who knows how long) contributing to the actual security of the web. Not mutually exclusive with doing harm in other ways.