3 ms·
I used it for my low traffic personal site and thought it was great. But then one my posts got on the front page of HN and the traffic triggered CAPTCHAs for ev
by luigi 14y ago
I used it for my low traffic personal site and thought it was great. But then one my posts got on the front page of HN and the traffic triggered CAPTCHAs for everyone. I dialed down the security settings and the CAPTCHAs went away, but still, that was annoying. And tech support wouldn't own up to their software thinking an HN spike was an attack.
Then I used it for my startup, which was using an SSL cert, and it had major problems on launch day because of that (ugh). It continued to have SSL compatibility issues for a week, so I've only been using it as a DNS since. As a test, I enabled it on staging and have left it off on production. To their credit, it seems like the SSL downtime issues have gone away.
It's been fine as a DNS, but I don't really have any desire to enable the CloudFlare features again. I love the idea of it keeping me safe from spambots and DDOS. At the same time, it really is a single point of failure, and it's failed more than any other technology in my stack. And the caching layer is way too brittle. I've set up rules to turn it off in staging.
- dragonmantank 14y agoI hate their stance toward SSL. When one of the sites on Cloudflare needed SSL the only thing you could do was turn off caching for HTTPS. Since then they've added an SSL service where you can get an SSL cert from them. It only SSL's the traffic from the client to Cloudflare, not from Cloudflare back to the server so you've still got part of your transport not secured. I wonder how many people bought into that service without realizing that. (You can have Cloudflare connect HTTPS back to your server, but they still offer that partially covered option for some reason).
- adriand 14y agoThanks, I really appreciate the personal insight. I may take a wait-and-see approach with this one now.