4 ms·
Exactly this. The amount of cost & time to make a (WordPress/Drupal/random database backed CMS website) site run well on a cheap VM is significantly higher than
by mattferderer 3y ago
Exactly this. The amount of cost & time to make a (WordPress/Drupal/random database backed CMS website) site run well on a cheap VM is significantly higher than Cloudflare's free & paid options. Those aren't my first choice in CMS these days but a lot of the small business web still run them & migrating isn't cheap from a technical or user training perspective.
If you happen to have a popular CMS like WordPress on a cheap VM, odds are you are going to get DDoS all the time, even if you only have 100 legit views/day. Cloudflare will reduce this dramatically.
I would guess any site not using Cloudflare (or someone similar) is more likely overengineering. As always though, every case is unique & it depends.
- johnklos 3y agoAbsolutely bull poop. First, setting up anything using some third party service like Cloudflare is already too much work and doesn't even work for many people in parts of the world Cloudflare has determined are undesirable. Second, I can, have and do host popular CMSes on hardware much more modest than Raspberry Pi performance. Third, "odds are you are going to get DDoS all the time"? Are you a Cloudflare shill? This is nothing but wildly hyperbolic. In a quarter of a century of hosting, I've had to deal with one specific DDoS actor. One. How are you going to claim that "odds are you are going to get DDoS all the time"? Go ahead, provide evidence, although I'm sure you can't and won't.
- mattferderer 3y agoNot sure how using Cloudflare is more work than setting up your own LAMP VM or installing WordPress on a SaaS even. People put up fake WordPress logins as honey pots. I'm not sure what to say to this. If you host a WordPress site you're going to get lots of traffic trying to take your website down unless your provider is helping you block it. If you go outside on a summer day, the sun is going to be shining. I have never had a WordPress site that didn't get a ton of bad traffic. If it lived on a cheap VM with a MySQL database, PHP & WordPress, it was going to be under stress at least a few times a year. Tossing Cloudflare on it takes less than 10 minutes & a few years ago was the 1 of the easiest/cheapest ways to get SSL on it. In my quarter of a century of hosting, I have had a lot of DDoS attacks & none of those sites got over 100k legit users a month. Most also didn't care about users outside their own country. It doesn't matter to me if you use Cloudflare or someone else. I don't make money off it but I will admit it is one of my favorite providers by far. I do also really like how the executive team is personal, handles themselves online & reaches out to devs.
- johnklos 3y agoTo host a Wordpress (as an example) site, you need to set up Wordpress and add content. To do anything with Cloudflare, you have to set up an account and configure things. If you don't use Cloudflare, you don't have to set it up. How could that be anything but extra work? Also, it's not standard - it's their own thing. And what happens if you use a VPN, or a provider that they don't like, or if you live in an area that Cloudflare simply doesn't like? I have no idea how people putting up Wordpress honeypots is related to this discussion, but for everything else, you're advocating treating symptoms and ignoring the problem. If you, or anyone else, want to run a Wordpress site and you expect a firewall or DDoS service to protect you from stupidity, it might work for a time, but it's not the best idea. If you don't rename your wp-login.php, that's on you. If you install 27 plugins that you don't really need then ignore the fact that they'll need constant updates, that's on you. But those are common sense things - again, the root issue should be addressed, so the symptoms never happen. Also, if bots banging on your wp-login.php and/or "ton of bad traffic" are what you consider a DDoS, perhaps you really should consider basic site security. We call "a ton of bad traffic" normal. I'd much rather a site that has fundamentally fewer problems than a poorly configured one that's "protected" by Cloudflare. Oh - and what does "most also didn't care about users outside their own country" have to do with it? You're advocating FOR the idea of stratifying the Internet? Then I guess you really are a fan of what Cloudflare is doing!