5 ms·
Cloudflare Down Again – and DownDetector Is Also Down
https://downdetector.tr/
- RockRobotRock 10mo ago[flagged]
- JimmaDaRustla 10mo agoThis made getting paged at 4am worth it
- sebmellen 10mo agoMe too man
- deleted 10mo ago[deleted]
- PascalStehling 10mo agodowndetectors downdetector shows that downdector should not be down. Something is wrong here. https://downdetectorsdowndetector.com/ https://downdetectorsdowndetector.com/
- Lionga 10mo agohttps://downdetectorsdowndetectorsdowndetectorsdowndetector.com/ https://downdetectorsdowndetectorsdowndetectorsdowndetector.... says https://downdetectorsdowndetectorsdowndetector.com/ https://downdetectorsdowndetectorsdowndetector.com/ is down
- terom 10mo agodowndetectorsdowndetector.com does not load the results as part of the HTML, nor does it do any API requests to retrieve the status. Instead, the obfuscated javascript code contains a `generateMockStatus()` function that has parts like `responseTimeMs: randomInt(...)` and a hardcoded `status: up` / `httpStatus: 200`. I didn't reverse-engineer the entire script, but based on it incorrectly showing downdetector.com as being up today, I'm pretty sure that downdetectorsdowndetector.com is just faking the results. downdetectorsdowndetectorsdowndetector.com and downdetectorsdowndetectorsdowndetectorsdowndetector.com seem like they might be legit. One has the results in the HTML, the other fetches some JSON from a backend (`status4.php`).
- Folyd 10mo agoi can confirm it down again
- deleted 10mo ago[deleted]
- B4n4n4 10mo agoLinkedIn down
- jacquesm 10mo agoThat's a net positive then.
- pappya_coder 10mo agoYes
- ericcurtin 10mo agoTime to use some local ai with Docker Model Runner :) No cloudflare no problem https://github.com/docker/model-runner https://github.com/docker/model-runner
- jakewins 10mo agoIncident link at cloudflare: https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q
- JoeWiltshire 10mo agohttps://downdetectorsdowndetectorsdowndetectorsdowndetector.com/ https://downdetectorsdowndetectorsdowndetectorsdowndetector.... reports that https://downdetectorsdowndetectorsdowndetector.com/ https://downdetectorsdowndetectorsdowndetector.com/ is down, guessing downdetectorsdowndetectorsdowndetector runs via cloudflare!
- yellowbanana 10mo agoThis is art
- designerarvid 10mo agohttps://youtu.be/CIpbEa6KTNI?si=tgEaPo8xG7KnpxLt&t=564 https://youtu.be/CIpbEa6KTNI?si=tgEaPo8xG7KnpxLt&t=564
- dlillard0 10mo ago[dead]
- klas_segeljakt 10mo agoIt's downdetectors all the way down
- zombot 10mo agoIs that the same as "All downdetectors are down"?
- ineedasername 10mo ago
- deleted 10mo ago[deleted]
- Vivianfromtheo 10mo agoCrunchyroll down too got me and the anime community stressed
- A_D_E_P_T 10mo agoIf Crunchyroll is down for 30 minutes it's nbd, because you know they'll be back. If the pirate sites are down for any duration, it can be very stressful, because they can be gone for good.
- ablation 10mo agoAlready being discussed here: https://news.ycombinator.com/item?id=46158191 https://news.ycombinator.com/item?id=46158191
- deadbabe 10mo agoIf that was a better discussion, it would be at the top.
- pyuser583 10mo agoI assume this is why Claude stopped working
- lionkor 10mo agoThere are other LLMs you can ask to be absolutely, 100% sure.
- Maxion 10mo agoYou're absolutely right – Here is a list of current SOTA models that you can try! Would you want me to: - Create a list of all LLM models released in the past few months - Let you know why my existence means you can't afford RAM anymore - Help you learn sustenance farming so that you can feed your family in the coming AI future?
- FranklinMaillot 10mo agoNot sure if this is related, but has anyone seen their allowance used up unexpectedly fast? Had Claude Code Web showing service disruption warnings, and all of a sudden I'm at 92% usage. I'm on the pro plan, only using Sonnet and Haiku. I almost never hit the 5-hour limit, let alone in less than 2 hours.
- CGamesPlay 10mo agoDid you accidentally hit tab to turn on “always thinking”? It burns tokens much faster.
- FranklinMaillot 10mo agoNo, I found the issue. It went all in on unit tests and wrote way too many.
- Jsmith4523 10mo agoYou know what, maybe AI is taking all the goddamn jobs
- immibis 10mo agoThey pretty much said this. All the big companies that had recent outages are companies that publicly embraced vibe coding.
- poszlem 10mo agoThis ignores all the companies that publicly embraced vibe coding and did NOT have outages. Not a huge fan of vibe coding, but let's keep the populism to minimum here.
- lxgr 10mo agoOn top of that, humans are more than capable of causing high-impact outages as well. (It's easier with massive unforced centralization, of course.)
- jasonvorhe 10mo agocausality, causation, yadda yadda. They already explained that it was some react server component update. sure, could've also been done with some ai assist but we don't know. These companies also don't vibe code (which would involve just prompting without editing code yourself, at least that's the most common definition). I really hope news like these won't be followed by comments like these (not criticism of you personally) until the AI hype dies down a bit. It's getting really tiresome to always read the same oversimplified takes every time there's some outage involving centralized entities such as cloudflare instead of talking about the elephant in the room, which is their attempt of doing MITM on the majority of internet users.
- johncolanduoni 10mo agoAll the big companies embraced vibe coding, so I’m not sure there was a natural experiment here.
- echelon 10mo agoAppears to be fixed now. Just lost 30 minutes of working. If this is unwrap() again, we need to have a talk about Rust panic safety.
- jasmes 10mo agoTime to rewrite Rust’s unwrap() in Rust obviously.
- jacquesm 10mo agoNow multiply that 'just' by the number of people affected.
- Maxion 10mo agoDoes it make it worse or better if I say it's RSC? https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q
- johncolanduoni 10mo agoWell, technically RSC was messed up, and then the hotfix for the messed up RSC was itself messed up. I guess there’s a lot of blame to go around.
- camillomiller 10mo agoThe entirety of shopify was down too for 30 minutes.
- hdgvhicv 10mo agoAnd once again simple self hosted services remain up.
- jacquesm 10mo agoNeat trick: just do job interviews when Cloudflare is down...
- f311a 10mo ago> A change made to how Cloudflare's Web Application Firewall parses requests caused Cloudflare's network to be unavailable for several minutes this morning. This was not an attack; the change was deployed by our team to help mitigate the industry-wide vulnerability disclosed this week in React Server Components. We will share more information as we have it today.
- tietjens 10mo agodoes this mean we can blame React Server Components for something new?
- johncolanduoni 10mo agoI always suspected RSC was actually a secret Facebook plan to sabotage the React ecosystem now that their competitors all use it to some degree. Now I’m convinced.
- girvo 10mo agoI mean RSC wasn’t really even the FB folks as far as I remember, they barely control React anymore
- osener 10mo agoListen to the sound of HN hawks erupting with joy when they realize they can blame JS, React, RSC, Rust, Cloudflare, and the cloud all for one outage.
- tietjens 10mo agoFor those hawks, Christmas has come early.
- __turbobrew__ 10mo agoWhen are they going to figure out that canary deployments are a good idea? Do they just push every change straight to prod globally?
- dtf 10mo agoEdinburgh Airport is also down, suspending all flights after an "IT issue with our air traffic control provider". Not sure if this is coincidental, but the timing is rather suspicious!
- johncolanduoni 10mo agoMaybe the little plane icons on the ATC screens are a PNG hosted on some Cloudflare domain.
- huflungdung 10mo ago[dead]
- Popeyes 10mo agoFontawesome?
- Maxion 10mo agominified js depependency loaded from some CDN?
- Nextgrid 10mo agoNot a safety-critical system but I know passenger information screens in at least some airports are just full-screen browsers displaying a SaaS-hosted webpage.
- AmbroseBierce 10mo agoThey laughed at my base64 encoded icons, now there, enjoy your downtime.
- ErroneousBosh 10mo agoAnnoyingly I wanted to fly a parcel from Edinburgh up to Stornoway, but it's looking like I'd be quicker driving the seven hours up to the ferry terminal myself.
- hoherd 10mo ago
- yatralalala 10mo agoInternet is no longer decenstralised. Some interesting DNS data https://news.ycombinator.com/item?id=46159249 https://news.ycombinator.com/item?id=46159249
- huijzer 10mo agoHence why I wrote a post on 18th of Nov (previous Cloudflare outage): https://huijzer.xyz/posts/123/do-not-put-your-site-behind-cloudflare-if-you-dont-need-to https://huijzer.xyz/posts/123/do-not-put-your-site-behind-cl.... That blog post made it to the front page of HN and my site did not go down. Nor did any DDoS network take the site out even though I also challenged them last time by commenting that I would be okay with a DDoS. I would figure out a way around it. In general, marketing often works via fear, that's why Cloudflare has those blog posts talking about "largest botnet ever". Advertisement for medicine for example also works often via fear. "Take this or you die", essentially.
- em500 10mo agoYes, marketing often works via fear. And decision making in organizations often works through blame shifting and diffusion of accountability. So organizations will just stick with centralization and Cloudfare, AWS, Microsoft et al regardless of technical concerns.
- peanut-walrus 10mo agoCloudflare is widely used because it's the easiest way to run a website for free or expose local services to internet. I think for most cloudflare users, the ddos protection is not the main reason they're using it.
- dev_l1x_be 10mo agoInstead of figuring out a novel way of distributing content a stateful way with security and redundancy in mind we have created the current centralised monstrosity that we call the modern web. ¯\_(ツ)_/¯
- privera13 10mo agoDown of a System
- ndsipa_pomu 10mo agoWAKE UP!
- ractive 10mo agoGrab a brush and put a little makeup.
- 7-Zark-7 10mo agoThe old guard has left as they we too much of an expense in this cost-cutting age... without mentors, crap creeps in and now we are seeing what happens when people don't know how things work, are in charge...
- bflesch 10mo agoWhy not build the next cloudflare then, I'm sure it is appreciated by HN folks.
- ai-christianson 10mo agoOr maybe we just move away from cloudflare-like services altogether.
- smallerize 10mo agoAnd just live with high latency?
- cess11 10mo agoSure, why not?
- bflesch 10mo agoWhat is "high latency" nowadays? If people wouldn't bundle 30mb into every html page it wouldn't be needed. Also cloudflare is needed due to DDOS and abuse from rogue actors, which are mostly located in specific areas. Residential IP ranges in democratic countries are not causing the issues.
- ptidhomme 10mo agoAren't botnet targeting cheap and unsecured consumer devices specifically in the residential IP ranges ?
- poulpy123 10mo agowhat about downdowndetectordetector ?
- noosphr 10mo agoAnother dozen or so of these and the self mutilation that teach companies have engaged in the last few years with mass lay-offs should finally end. Extrapolating at current rates I guess that means April 2026.
- bflesch 10mo agoHow are these clowns deploying stuff on a Friday, it is unbelievable to me. It is not even funny any more. It seems cloudflare is held together by marketing only. They should stop all of these stupid initiatives and keep their stack simple. And I'm 100% sure the management responsible for this is already fueling up the ferraris to drive to their beach house. All of us make them rich and they keep on enshittifying their product out of pure hubris.
- giuscri 10mo agohow do you tell they deployed new stuff?
- bflesch 10mo agoSee https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q https://www.cloudflarestatus.com/incidents/lfrm31y6sw9q "A change made to how Cloudflare's Web Application Firewall parses requests caused Cloudflare's network to be unavailable for several minutes this morning. This was not an attack; the change was deployed by our team to help mitigate the industry-wide vulnerability disclosed this week in React Server Components." The bug is known since several days, and the hotfix was already in place. So they worked on the "final fix" and chose to deploy it on a friday morning.
- heisenbit 10mo agoIf the deployment was related to the React Server issue then maybe it was unavoidable.
- bflesch 10mo agoYes, but a hotfix was already in place. They chose to deploy the "proper fix" this morning, and obviously it went wrong. Also they didn't do a phased rollout because it impacted their high-value customers such as shopify as well as claude, causing significant damages. Their procedures are not good.
- steve1977 10mo agoEverything related to React is avoidable by not using React.
- LightBug1 10mo agoOk, at what point is "We use Cloudflare" going to be a supply-chain red marker? At what point does the cost outweigh the benefit?
- noosphr 10mo agoI know I shouldn't, but I really can't help myself: https://blog.cloudflare.com/20-percent-internet-upgrade/ https://blog.cloudflare.com/20-percent-internet-upgrade/
- winternewt 10mo agoWhat are you implying by linking to that article?
- RamRodification 10mo agoI'm not the person you are replying to, but like all of technology, you just find the latest (or most public) change made, and then fire your blame-cannon at it. Excel crashed? Must be that new WiFi they installed!
- ErroneousBosh 10mo ago"Ever since you replaced my wiper blades the clutch has been slipping"
- stingraycharles 10mo ago“haha rust is bad” or something, is’s a silly take. these things hardly, if ever, are due to programming language choice and rather due to complicated interactions between different systems.
- skywhopper 10mo agoCloudflare was crowing that their services were better because “We write a lot of Rust, and we’ve gotten pretty good at it.” The last outage was in fact partially due to a Rust panic because of some sloppy code. Yes, these complex systems are way more complex than just which language they use. But Cloudflare is the one who made the oversimplified claim that using Rust would necessarily make their systems better. It’s not so simple.
- EugeneOZ 10mo ago
- borplk 10mo agoIncoming "Look at all this cool postmortem stuff about our fuckup" blog post. It's getting a bit old guys.
- deleted 10mo ago[deleted]
- stanislavb 10mo agoI "envy" DownDetector these days ... I wanna know how much money they are making out of these Cloudflare downs...
- tonyhart7 10mo agoYou know its bad when DownDetector is also down
- willswire 10mo agoWoke up this morning with my iPhone and Apple Watch suddenly in a different time zone. Anyone else experience this?
- testplzignore 10mo agoAre you by chance on an airplane?
- bobowzki 10mo agoI host my companys website on Cloudflare pages using Cloudflare's DNS. I don't want to move to 100% self hosting but I would like to have self hosted backup. Has anyone solved this?
- skywhopper 10mo agoHaving a self-hosted “backup” that is ready to go at any time means having a self-hosted server that’s always on, basically. There are lots of cheap colo or VM options out there. But the problem is going to be dealing with an outage… how do you switch DNS over when your DNS provider is down? Well, one way is to use a different DNS provider than either of your hosting options. You can see this is getting complicated. Might be better to take the downtime. But if I had to make a real recommendation I’m not aware of any time in the last decade that a static site deployed on AWS S3/Cloudfront would have actually been unavailable.
- amiga386 10mo ago> how do you switch DNS over when your DNS provider is down? You list multiple nameservers. yoursite.com. 86400 IN NS ns1.yourprovider.com. yoursite.com. 86400 IN NS ns2.yourprovider.com. yoursite.com. 86400 IN NS ns1.yourotherprovider.com. yoursite.com. 86400 IN NS ns2.yourotherprovider.com.
- jasonsgt 10mo ago[dead]
- Maksadbek 10mo agoDo we have downdectector for downdetector ?
- thenthenthen 10mo agoWe seriously need to start to be thinking of Up-detectors
- HackerThemAll 10mo agoThere are too many of that recently. Cloudflare is starting to look amateurish. Can't they test their stuff properly before deploying it to production?
- bflesch 10mo agoMaybe they test with shopify.com before the deploy it to their important customers ;)
- jtrn 10mo agoI have a tentative take, and I kind of feel stupid for even claiming this, since I don't work in Cloud-ops, or whatever, but it's fun to try to participate, and I spent some time articulating what i think is a good perspective on Cloudflare now a days, and as psychologist, I am primary interested in the psychology of things. Basically, my take is: It’s not a technical monoculture; it’s a billing psychology + inertia culture. I dont think the internet is fragile simply because Cloudflare is so ubiquitous, because that view ignores the economic factor of why people choose them. The situation is really a perfect bi-modal distribution: at the low end, you have hobbyists and personal sites who use Cloudflare because it is the only viable free option, and at the extreme high end, you have massive enterprises that truly need that specific global capacity to scrub terabits of attack traffic. However, I think the following perspective is important: For the vast middle ground of the internet—most standard businesses and SaaS platforms—Cloudflare could be viewed as redundant. If you are hosting on AWS, Google Cloud, or Azure, you are already sitting behind world-class infrastructure protection that rivals anything Cloudflare offers. The reason this feels like a dangerous monoculture isn't because Google or Amazon can't protect you, but rather because Cloudflare wins on the psychology of billing. They sell a flat-rate insurance policy against attacks, whereas the cloud giants charge for usage, which scares people. Ultimately, the internet isn't suffering from a lack of technical alternatives to DDoS protection, nor is Cloudflare a NECESSARY single point of failure; it is just suffering from a market preference for predictable invoices over technical redundancy, and inertia, leading to an extremely high usage of Cloudflare. So basically: Even though we are currently relying a lot on Cloudflare, we are far from vendor lock-in, and there is a clear path to live without them, given that there are many alternatives. Maybe we could view this as a good thing, since basically medium to large-scale enterprises efficiently subsidize small and hobby-level actors? So to summerize: The 2018-era "just use Cloudflare for everything" advice is outdated, and the following is a better philosopy: If you're tiny: Cloudflare free tier is still a no-brainer. If you're huge and actually get attacked: pay for Cloudflare Enterprise or equivalent. If you're anywhere in between: seriously consider whether you need it at all. The hyperscalers are good enough, and removing Cloudflare can actually improve your availability (fewer moving parts). I think Cloudflare thinks this way too, which is why they've been pushing Zero Trust, Workers, WARP, Access, and Magic Transit, to become the default network stack for companies, not just the default firewall. /wall-of-text
- deleted 10mo ago[deleted]