10 ms·
Thoughts on Cloudflare
- Avamander 1y ago> Cloudflare has become a highly attractive target for state-sponsored attacks, suffering from recurring breaches. Their sheer scale, considering that they are serving a substantial portion of the internet, means that an outage or compromise could have widespread, costly consequences. I'm unsure how much of these can actually be called "attacks" rather than "complying with local laws" that lets them operate in a lot of countries. Including hostile ones. They really don't segment customer data sufficiently to mittigate this either. CloudFlare even officially says that they don't actually enforce even Regional Services and you have to do that yourself as a customer. Rest of customers get even fewer guarantees than that. Have fun, three-letter agencies. https://developers.cloudflare.com/data-localization/limitations/ https://developers.cloudflare.com/data-localization/limitati... > Regional Services operates on your hostname's IPs. We recommend using DNSSEC and/or DNS over HTTPS to ensure that DNS responses are secure and correct. This of course is funny considering how CloudFlare has used the same DNSSEC key signing key for ⪆10 years. It also doesn't mention BGP hijacks or similar MITM attacks, because there's also not much anyone besides CloudFlare can do against that.
- WhyNotHugo 1y ago“complying with local laws” isn’t always a good thing. Here’s some behaviours that you need to report in some countries in order to comply with local laws: * someone is a homosexual * someone had sex out of wedlock * someone is a communist * someone is right-wing * someone is a Muslim * someone is _not_ a Muslim * someone spoke ill of the current ruler * someone hosted a messaging service, and didn’t ask users for a copy of their id
- rwmj 1y agoHere in the real world companies have 3 choices: (1) comply with local laws, (2) don't operate at all in the country, or (3) operate in the country but ensure they have no staff there and never visit. Anything else is going to involve fines and/or prison for your executives and employees. I once interviewed at a UK gambling company that was doing option #3, and during the interview it was made clear that I'd never be able to visit the US because they were operating there illegally. (I declined the offer.) Some time later, it was in the news that one of their executives had been arrested and imprisoned in the US when he visited on holiday. (https://www.pinsentmasons.com/out-law/news/another-uk-betting-exec-is-jailed-in-the-us https://www.pinsentmasons.com/out-law/news/another-uk-bettin...)
- jasonvorhe 1y agoIn which countries do you have to report someone for any of that? Genuinely curious. Can't think of a single country where any of these criteria would be a reportable offense.
- Avamander 1y agoI can certainly think of a few where some of these things are illegal or forbidden enough to result in death if someone found out.
- jasonvorhe 1y agoSo, what are some of them?
- Avamander 1y agohttps://en.wikipedia.org/wiki/Criminalization_of_homosexuality https://en.wikipedia.org/wiki/Criminalization_of_homosexuali...
- QuantumNoodle 1y agoAuthor did a surprisingly good job hanging on to all the receipts to support his claim "cloudflare bad." But his alternatives are all CDN providers - which is not even the side of the business that makes cloudflare unique and makes them money. The piece, thorough as it may be, does not offer alternatives to products that cover the exciting parts of their business and I was looking forward to seeing what those were - for example tailscale or Pangolin (Open source alternative to Cloudflare Tunnels) or equivalents for serverless/edge compute. This makes it feel as if the author does not _really_ understand cloudflare's role/position and that this article is just a collection of links that report of the company's (valid) imperfections. For example, their workers platform, DDoS protection, and software-defined network functions (WAN, firewall, Zero-trust, etc) have made my life as a developer in my last few roles very productive and successful. And migrating away from those services was just as easy as signing up. It might sound like I am defending cloudflare, but I am not. I share the author's concern about them becoming a monopoly that MITM's a lot of the Internet. But the author provides no evidence of to this claim. My experience has been the opposite: cloudflare interoperated with legacy systems and other cloud providers without locking us in or using anti-competitive tactics. Their presence often improved integration even when other vendors didn’t reciprocate. When people flock to a service because it’s genuinely useful rather than "can't leave Hotel California", that’s not a monopoly — it’s market preference. That said, there is a real risk if innovation stalls or leadership becomes greedy. Companies that stop innovating sometimes resort to aggressive or extractive practices to stay relevant. It seems to be the trend once companies get too big to die - innovation stalls and their flywheel slows and they become desperate (or greedy) to stay relevant. I would monitor for those signs before I sound any alarm.
- anonymousiam 1y agoThe Internet runs at the will of the government(s). Every government (national, regional, local) has regulations that must be obeyed. Depending upon where you live, some of those regulations may be kept secret from those most affected. An entity like Cloudflare is a juicy target that can be used cooperatively, or abused uncooperatively by those enforcing the regulations. So Cloudflare has solved one problem (DDoS), while creating several new ones, which most people feel is a fair trade, but it's not a prefect world and there is no perfect solution.
- goatsi 1y agoIt's pretty disappointing that the author (writing in 2025) says "perhaps to maintain its status as the world’s largest botnet operator," and links to a Spamhaus report from Q1 of 2020.[0] If you check the most recent version of the report from Spamhaus (Jan to June 2025)[1], Cloudflare is nowhere to be seen, and Digital Ocean, who they recommend as a Cloudflare alternative is listed as third largest botnet host in the world. Looking back through the historical reports this isn't a new phenomenon, in Q4 of 2022 Digital Ocean was ranked #2 and Cloudflare was down at #17. [0]https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-q1-2020/ https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-thre... [1]https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-january-to-june-2025/ https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-thre...
- simultsop 1y agoIt is sad. The post could be a paragraph of basically ending with negative attributes of oligo and mono polies. Which are what should be evaded. Other than that, alternatives do not go far as cloudflare does. If you experience a heavy DDOS, either you bankrupt with a large invoice or you suffer heavy outage. I do not understand why this primary service misses to be listed. Nobody in the planet offers DDOS free, especially to news agencies at their difficult times.
- darkwater 1y agoYes, I agree. The anti-monopolistic spirit of the post is good but when you read sentences like that or recommending "major cloud services" as an alternative, well, it starts to smell like a hit piece.
- ksec 1y agoIf it wasn't on HN, being upvoted by some, I wouldn't have clicked on the link judging from the domain name. Turns out it is unicode issues. I wonder if HN will ever fix it.
- dymk 1y agonot (exactly) a unicode encoding issue, it's IDNA encoding. it's unicode encoded as ascii.
- dangus 1y agoSo it’s an issue with HN being a trash website. A trash website that I like a lot, but still a trash website. Maybe in 20 years we’ll be able to use emojis on here.
- Insanity 1y agoI actually don’t want emojis on here. I prefer the current “early 2000s” look. I don’t see it being a good thing for discussions if they are littered with emojis. And we still have good old ASCII :-)
- dangus 1y agoSo when we all die and everyone on HN in the future grew up in a different era where all the symbols available on your keyboard are expected to be supported, will they want that early 2000s look where shit doesn’t work or is that just an arbitrary decision based on nothing? Is YC a nostalgia-fueled organization or are they supposed to be investing in new technology?
- numpad0 1y agoNot really, it's just yet another inconclusive indication that absolutely nobody wants unicode for machine evaluated strings.
- bombcar 1y agoWe can use emojis, just higher class ones. 𓂺
- naet 1y agoI once had to migrate a good number of web properties off of Cloudflare for a client. They were an agency that had used it as a go-to for many years and many clients, until the CEO of the company stated publicly that they would no longer use cloudflare as a political thing (there had been a news story that Cloudflare was providing ddos protection for some Nazi websites and refused to take them down, or something similar enough). My takeaway was basically that people use Cloudflare a lot because it is a strong service with a ton to offer at a very low price point. It's a bit like gmail - just very convenient and offers a lot for free or very cheap. Switching at that scale made a significant increase in their monthly bill. I do applaud people who go out of their way to create alternatives to major services like cloudflare, gmail, chrome, etc. As an individual it can be hard to do though, or at least not always the path of least resistance.
- phantomathkg 1y agoMaybe it is me, but I wouldn't take whatever advice provided by someone who is only known by pseudonym.
- devmor 1y agoWhat a silly thing to say in an era where anonymity is under constant attack by forces that want to harm us all.
- noman-land 1y agoWhat's your name?
- isodev 1y agoVery good post. Cloudflare is continuously adding services to their cloud offerings (the latest being Email delivery) in a familiar pattern of "let's make it impossible to switch".
- reassess_blind 1y agoI don’t see a problem with a company continuing to make useful products. Email delivery was a pretty logical next step for Cloudflare.
- kuschkufan 1y agorelevant username
- kaoD 1y agoNon-sequitur. Op comment is not criticizing that they offer another product, but that they offer another proprietary product that furthers locks you into their ecosystem.
- afiori 1y agoThe problem is that globally the concepts of monopolies being bad and antitrust regulations being good have in practice left the current zeitgeist
- kaoD 1y agoI'm currently on my Nth run of: - I want to deploy a tiny service for personal use - That has occasional requests (think ~10 a day) - Needs to respond to a few daily events: a CRON job here and there, read an email, webhooks... Think a simpler Zapier In principle this would be perfect for any of the many cloud function providers. But AFAIK all of them have this vendor lock-in built into their business model and I just refuse to cave in. Is there anything that I can do to not lock myself into an edge-computing ecosystem (or whatever this is called in the provider of choice) and still get the benefits? Is there any provider that supports any standard that is not tied specifically to their offering?
- miyuru 1y agoI use cloudflare on my sites because my servers does not have IPv4. If the all the ISPs can get the their networking knowledge up-to-date I can remove it. I have set the protection level to the lowest setting to not trigger unnecessary capatchs.
- ancarda 1y agoWe're slowly making progress. We're almost at 50% IPv6 worldwide traffic to Google: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html Depending on what country you're in and what your traffic patterns look like, it might be higher. Some countries are >70% IPv6 traffic to Google. Do you ever check your access logs to see when you're ready to go IPv6 only?
- Canada 1y agoWhat we really need is more IPV6 deployment so normal people can have plenty of routable addresses and we can go back to hosting more things on the edges like we used to, on computers we physically control. There are plenty of applications where the bandwidth of PON fiber commonly deployed to homes is more than sufficient, and the extra latency is irrelevant. Sure, it may be susceptible to DDoS attack, but if tens of millions of people were running personal and business systems from home it's debatable this would be less resistant than having a few centralized companies own us all.
- itake 1y agoRunning a server from "home" (or an office) I think is too expensive for most businesses. Paying for battery backups, duplicate internet providers, diy NOC, is just too much, especially for small side projects where the goal is publish blogs or write code, not side-hustle SRE
- mystifyingpoi 1y agoWhat if I told you, that you don't need battery backups, that one ISP is enough, that you don't need 24/7 network team to plug a cable from your tower server to a router, in order to host a mid-size SAAS from the office tower server? Get real guys.
- itake 1y agoIt’s not for me, but my paying customers. I guess I could ask them if they are ok if the service goes down when Florida has a hurricane
- reaperducer 1y agoGet real guys. I had a PHB who didn't like that our web site went offline for 30 seconds each week. I explained to her that the alternative would require $200,000 and six new employees. She hasn't brought it up since. Very few web sites are "mission critical." Even Facebook could go offline for a few seconds a week and nobody would care or notice.
- 1y ago
- drake99 1y agoxn--gckvb8fzb.com whats this ?
- blacktulip 1y agoマリウス.com
- MattJ100 1y agoIt's the ASCII encoding of a Unicode domain name: https://en.m.wikipedia.org/wiki/Internationalized_domain_name https://en.m.wikipedia.org/wiki/Internationalized_domain_nam...
- lloeki 1y agoTangential nitpick: I wish HN would display the punycode IDN in the submission URL as the intended マリウス.com I mean, I understand the opportunity for abuse, but if it displays fine as UTF8 in comments in the previous sentence it might make sense to display it correctly over there in the submission.
- bluelightning2k 1y agoI really like using Cloudflare. I think durable objects are a great innovation for example.
- NathanFlurry 1y agoI’ve been building an open-source alternative at https://github.com/rivet-dev-engine https://github.com/rivet-dev-engine It’s the only bit of the Cloudflare stack (afaik) that did not have an open-source alternative for the JS ecosystem. I built heavily with DO on another OSS project, but realized it was incredibly problematic that our customers couldn’t truly self-host.
- scottydelta 1y agoGitHub link says 404
- nromiun 1y agoI actually looked at all the alternatives listed by the author. Here is the problem: none of them are competitive with Cloudflare. With Cloudflare you don't even need to provide a credit card, just setup with your website and it is "free" for lifetime. They might pressure you to switch to paid plans if you start getting PBs of traffic, but until that point they will deliver your content for free. It is a huge advantage. Specially when you consider the egress pricing of major cloud providers.
- ranger_danger 1y agoIt's a win for both sides... you get free protection/proxy service, and they get to MITM all your traffic.
- nromiun 1y agoThat's like saying your cloud providers are stealing and looking at all your code. Technically you might be right but it is still somewhat disingenuous. Not to mention all the alternatives are doing MITM anyway. So why single out Cloudflare?
- ranger_danger 1y ago> it is still somewhat disingenuous. Depends on your perspective IMO... if I either think there is reason to believe they are spying on people for nefarious purposes, or if I do not want them to allow the government to spy on me without a warrant, I'd prefer they not have that ability to begin with, regardless of whether it's code sitting on the device or the web traffic that transits through them. > So why single out Cloudflare? Because I believe they have a much larger influence and percentage of traffic than all the alternatives combined, but you're right, they all have the same weakness and I would like a solution to it.
- deadbabe 1y agoCloudflare isn’t perfect but people do have other options, and yet they come back to Cloudflare. Without Cloudflare it is more likely the internet would be a shittier less secure place. I think there are worse companies to worry about out there. Will their power only grow? Yup.
- Illniyar 1y agoLoad of bull. Every article linked in this is either wrong or mischaracterized. Cloudflare does not facilitate phising - it just made proxying and tunneling easier. The breaches and bypasses mentioned are anything but - they are linking to a successful mitigation of an attack as if the attacker got away with something of value. This entire article reeks of trying to fit the evidence to an agenda. Considering they couldn't find actual evidence of problems and had to resort to mischaracterization this is actually a great reason to use Cloudflare.
- TkTech 1y agoI've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.
- Thorrez 1y agoI reported a phishing site to them in 2013. They responded "Access to the submitted phishing URL(s) has been restricted."
- peanut-walrus 1y agoNot my experience at all. We've reported hundreds if not thousands of sites and with few exceptions they have taken them down swiftly. Definitely one of the best cloud operators when it comes to this.
- TkTech 1y agoAs recently as August 8th, I reported a phishing site targeting seniors into installing a pre-configured Atera client (who _also_ failed to respond in a reasonable time) by pretending to be an event invite. It was blatant and obvious phishing. This was the response: --- Hello, Cloudflare received your Phishing report regarding: ---- We are unable to process your report for the following reason(s): We were unable to confirm phishing at the URL(s) provided. Please be aware Cloudflare offers network service solutions including pass-through security services, a content distribution network (CDN) and registrar services. Due to the pass-through nature of our services, our IP addresses appear in WHOIS and DNS records for websites using Cloudflare. Cloudflare cannot remove material from the Internet that is hosted by others. Please reply to this message, keeping the report identification number in the subject line intact, with the required information. To respond to this issue, please reply to abusereply@cloudflare.com. Thanks, The Cloudflare Team. --- This is the typical response for me from Cloudflare - it took 2 more weeks before it was finally taken down. If I had to hazard a guess, your high volume of reports gets you into a very different support bucket than the occasional reporter.
- CuriouslyC 1y agoI dislike how Cloudflare wants to do everything the Cloudflare way. A lot of their services are legit good and insanely cheap though, and containers have the potential to be a game changer that takes them from occasionally useful to the backbone of your cloud.
- jockm 1y agoHelp me understand your point better. How do you want the services to work? Is there some standard you are advocating for, or for them to mimic existing services, or what?
- doublerabbit 1y agoBy not harshly penalizing those who legitimately use VPN's, proxies? I'm using FreeBSD - This is on the hit list I'm using Waterfox - This is on the hit list I'm using my colocated server for a VPN from a reputable provider - This is on the hit list I eliminate the last two and suffer with my ADSL. My ADSL isn't a standard domestic provider so I'm hit with that too for using an alternative provider. I am still being penalized for using FreeBSD. Every page I encounter that uses Cloudflare ends up with a captcha. Why isn't there a way to verify myself that I am an actual legit person? I've clicked the captcha enough times, why does it have to be every single time? Why can't I whitelist my IP? If this is truly the only way to restrict bad actors, then it's pathetic. Am I'm going to be hit for using Xorg and not Wayland in the future? Their "bot" protection technology is years out of date. I don't like that Cloudflare has total control on how I can see the internet. I don't need any of their services, I don't want any of their services and others may praise them but to me not required. This may of worked five years ago, but like cookie banners, it doesn't work now. Yet they wish to spin up new modern services and neglect the old that actually made Cloudflare and not some power-hungry MiTM service. That's what it feels like but not that they will listen. I hate the fact that any point they can just go full anal and force you to X. The internet is suppose to have some sort of freedom, it's less than freedom. Using the internet now is like an animal in a cage. Heck, I would even register an account with Cloudflare if it allowed me to verify legitimacy.
- jbrooks84 1y agoI truly think all the post they do on stopping an even larger DDOS, is them just paying a DDOS service or making the DDOS themselves
- RLAIF 1y ago[dead]
- hyruo 1y agoAny infrastructure can be abused, but that doesn't negate its legitimate uses.In fact, it is precisely because of the popularity of free services such as CloudFlare that the threshold for network security has been significantly lowered.