3 ms·
It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much
by jillesvangurp 18d ago
It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. And they have a few other things that aren't half bad to use with pretty generous freemium layers.
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.
- pocksuppet 18d agoThe hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
- CommanderData 18d agoIs there any evidence of this
- bcye 18d agoWell it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-nsa-taps-google-yahoo-data-center-links/ https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
- CommanderData 18d agoThe reputational damage for CF would be intense. Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
- samlinnfer 18d agoThey already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.
- stef25 18d agoMaybe that's why the keep hosting extremist content.
- done_lurking 18d agoI thought Cloudflare generally refuses to serve those kinds of sites. What content is Cloudflare serving that is extremist?
- pocksuppet 18d agoMany torrent sites, that's a kind of extremism.
- 1vuio0pswjnm7 17d agoI have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries I don't think it's convincing If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc. The fact is businesses do "tolerate it" For example, https://en.wikipedia.org/wiki/Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed The MITM design of CF is what it is It creates risks, but these risks are tolerated
- 1vuio0pswjnm7 18d agoIf the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost The damage of being spied upon, if there is any, is already done 1. It's not clear why commenters are only concerned about intelligence agencies
- esperent 18d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)? If so, what's your source for that claim?
- icantevenhold 18d agoHeck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level
- strictnein 18d ago> "it’s no big secret that the NSA is listening in on the node/isp level" The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
- milkshakes 18d agosee https://en.wikipedia.org/wiki/XKeyscore https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago
- strictnein 18d agoYes, I'm well aware of XKeyscore. If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it. Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
- thorbutt 18d agoThat doesn't seem unique to Cloudflare though
- cassianoleal 18d agoNo, but nothing comes close to their breadth and scale.
- youngtaff 18d agoAmazon and Akamai is their scale, maybe Fastly too
- pocksuppet 18d agoThey are serving big commercial enterprises, ones the government already has direct access to. Cloudflare is serving the long tail.
- youngtaff 16d agoLast I heard (was a few years back) Cloudflare had more enterprise customers than Fastly Should be relatively easy to work out who uses what CDN I get your point about the long tail but what’s the value in a government MITM those?
- kakacik 18d agoIf you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one. Or clouds in general, its all wishful thinking and pinky promises.
- spacebanana7 18d agoWhat about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence
- tg180 18d agoPick your poison
- WarmWash 18d agoOne of them is just another arm of the government so all data is defacto government data, and the other releases transparency reports[1] [1]https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_CY2025.pdf https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_C...
- mitxela 18d agoYou have to be a registered Chinese business entity with a CCP director on your board to legally use that
- lukan 18d ago"We've known it has an always-on microphone and speech-to-text for over a decade" Literally? What is the reference here?
- a2ff6eeb0 18d agohttps://allaboutcookies.org/lg-smart-tvs-snooping https://allaboutcookies.org/lg-smart-tvs-snooping
- lukan 18d agoYeah, about those I know, but what about cloudflare?
- a2ff6eeb0 18d agoThey hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache and forward appropriately.
- lxgr 18d agoAlso to do DDoS mitigation. Being able to see the HTTP request, at least headers and path, greatly helps with distinguishing attackers from legitimate traffic. It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response. Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
- pocksuppet 16d agoAnd the best way to get people to let you do bad things, is to offer them something good, that uses the same mechanism. If I want to MITM the whole internet, what better way than offering free caching and bot blocking? I even get to charge the bots extra to bypass the block, and then charge the customers extra to block the bots that are paying extra to not be blocked!
- aranelsurion 18d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
- mopsi 18d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. That depends heavily on the kind of site you're hosting there. I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
- done_lurking 18d agoDo you really need Cloudflare for something like this?
- mopsi 18d agoIt's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site is handled by Cloudflare. And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
- mitxela 18d agoHe doesn't, but someone told him it was good so he uses it. This is Cloudflare's main audience, just like McAfee's.
- ExoticPearTree 18d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest. Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes. I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
- deleted 18d ago[deleted]
- petcat 18d agoThe NSA collects and archives all internet traffic it can access for future analysis. It's the purpose of the Utah Data center. https://en.wikipedia.org/wiki/Utah_Data_Center https://en.wikipedia.org/wiki/Utah_Data_Center
- p-e-w 18d agoThere’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic. Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that. BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
- jgtrosh 18d agohttps://en.wikipedia.org/wiki/Fairview_%28surveillance_program%29 https://en.wikipedia.org/wiki/Fairview_%28surveillance_progr... https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A Public information shows that the NSA has been active intercepting as much data as possible. It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
- Betelbuddy 18d agoOr they will dump your secrets into all Internet caches... "Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752
- strictnein 18d agoThe NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare. This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta. https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking-everything-how-has-nobody-seen-them-coming-3.html https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...
- celsoazevedo 18d agoThere's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting for the NSA there.
- strictnein 18d agoOf course, but the comment I was replying to stated: "the NSA learns everything there is to know about you and your customers" Which implies that they are looking at it all and records it. The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.
- pocksuppet 18d agoThey are actively scanning all of it, looking for interesting stuff.
- strictnein 16d agoHow do you do DPI on hundreds of PBs a day? Explain the process that would allow you to "look for interesting stuff".
- pocksuppet 12d ago
- milkshakes 18d agoif your threat model includes the NSA i don't think your choice of CDN is going to make a difference
- seki285 18d ago>talks about how bad Cloudflare is with imaginary threats >doesn't offer an alternative and leaves Every. Single. Time.
- Perepiska 17d agoAlso CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog. Also CF raise checks on pages that I opened few hours ago and reload.
- dizhn 18d ago> Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. You don't need to register your domain with them. Only make their DNS servers your domain name servers.
- jillesvangurp 18d agoTo be clear, we migrated our domains to them after moving our websites there, not before. Our old registrar charged more.
- ghoul2 18d agoI also believed that, but at least for India, this doesn't work in practice. Unless you atleast do the 25$ pro plan, cloudflare routes even india-to-india, hell, even mumbai-to-mumbai and aws_mumbai-to-cloudflare_mumbai traffic via Marsaille!! Not even Singapore. The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai. I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved. Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare). Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan. Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.
- piperswe 18d agoTransit in some countries, like India, genuinely is that expensive. Keep in mind it doesn’t cost Cloudflare any more to serve Indian traffic from Marsaille than to serve non-peered French traffic from that colo - they aren’t paying the cost of getting traffic between India and France.
- ghoul2 18d agoThe traffic still has to flow from an india provider to the international leg and back via the domestic provider. In anycase, then they should document it clearly that they have unacceptable insertion latency in india and the free plan is entirely unusable for india. Instead of advertising '10 pops in india!!'
- nightpool 18d ago
- matthewdgreen 18d agoRe: complexity. I used to find AWS unusable, then I realized I can just tell Claude Code or Codex to manage it. This makes it into an entirely different product, where "Cloudflare is easier" doesn't really matter. Now price is the only barrier.
- airstrike 18d agoCloudflare can also be managed by Claude Code or Codex, so for those instances in which you will personally have to go into the console to make edits, Cloudflare is still easier.
- snorremd 18d agoBefore I went European sovereign for my own personal stack I used Cloudflare for hosting static and somewhat dynamic websites and it has become really nice the later years. There is almost no mention of "regions" in Cloudflare. Your content and code runs globally by default. With traditional clouds you need to think about how you distribute your application. At least that is my experience. Maybe they provide global CDN for global distribution of static content. But serverless containers and databases more or less run in a single region by default. And if you wish to distribute stuff it is on you to plan the architecture behind that. Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well. A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.
- exfalso 18d agoWhat do you use as a European CDN atm?
- frevib 18d agohttps://bunny.net/ https://bunny.net/
- KronisLV 18d agoYou know, the pricing page lays the features out pretty nicely, surprised that they're not way more popular: https://bunny.net/pricing/ https://bunny.net/pricing/ Though I do remember some storage related complaints here on HN, other than that I haven't seen much about them on this site either!
- 18d ago
- jerkstate 18d agoyeah, I have been amazed at what I could do for free, and then amazed at how much more powerful it got for 5 bucks a months. Cloudflare is killing it in terms of value for small websites (and features and reliability).
- el1s7 18d agoGoogle Cloud and AWS are complex because they're meant for hosting complex apps and infrastructure, they're not really worth it for simple static websites.
- sinsterizme 18d agoI'd argue it's even more worth it for static sites, where CDNs and buckets will vastly out-perform hosting a static site on an instance yourself because of replication, caching, and geographic routing
- mitxela 17d agoBut they don't, because your bucket is still in a location, and goes through more complexity layers.
- ranger_danger 18d agoI cannot visit most crimeflare sites because I just get endless captcha loops.
- mitxela 17d agoThe trick is to use the most normal hardware, software and network connection you can think of. Which I assume you aren't doing for ideological reasons, which is fair.
- ranger_danger 17d agoMy ISP seems to frequently rotate IPs with other people who can't behave, so my IPs always have garbage reputation... that probably has a lot to do with it as well. How do I know this? I have received reports from various websites (and manually queried some public block lists/RBL/etc.) that my IP range was blocked due to all sorts of different things like open proxies, CSAM etc. even if I've never visited that site before, and I know just from being a neteng that that such traffic is not originating from my devices/router and I don't have any observably compromised devices or suspicious traffic when monitoring it.
- mitxela 16d agoThis is common for third-world ISPs. Cloudflare would never block, say, Comcast, but they have no qualms about blocking the few largest ISPs in Brazil because who cares about Brazil? Those countries also have IP address shortages because we refused to move the whole internet to ipv6 yet, and may share just a few addresses per city.
- MisterMunchkin 18d agoAWS isn't aimed at regular people, it's infrastructure as a service. You use it because you need a thousand servers, or a redundant system that can survive a data centre exploding. If you just need a single server that you don't care about then it's way cheaper to just own it yourself. You probably don't need 99.999999999999999% guarantees for your data, but if you're a bank then you do need those guarantees because losing all of your documents would be disastrous. Normal people aren't worth anything to them. A company might spend a million a month with AWS, to get that with normal people you'd need at least a hundred thousand customers. And those people are going to spam you with tickets and do silly or illegal things. They're just not worth it. They obviously won't turn money down, but it's not a growth area for them.
- epistasis 18d agoI 99% agree, but have conflicted felings. There's a mix of services. S3 is and was an amazing resource for normal people. Extremely reliable cloud storage for backup, for distribution, for anything, well, it's a dream. I prefer Cloudflare's offering there in every way, but AWS defined the product category (with its correspondingly ugly API like every single AWS service), and met a core need for many many people. With S3, if you need a ton of storage, it's a terrible deal, and you shouldn't use it. But for a couple hundred gigabytes, go for it. EC2 is similarly great for normal people as long as you only need a part-time server for a short amount of time. It's hard to beat with a VPS. Once you get into load balances, event queues, and all the rest of AWS services, well, that's all there to drive lots of money to AWS and to contractors and busy work. MAYBE RDS is a good deal for somebody who really wants to pay somebody else for a managed database. Which turns out to be a ton of users of databases!
- tjoff 18d agoCargo culting is probably the biggest reason people use AWS.
- pampas 18d agoRegistering domains on Cloudflare is great. They do it at cost as far as I can tell and more tlds have been added. I don't have to use a nasty local registrar with dark patterns anymore.
- mitxela 17d agoThey do it at cost with a caveat: you can only ever use Cloudflare for that domain. It's a loss leader.
- theamk 17d agowhat? their docs explicitly say nosy of them are not going tobe cloudflare-hosted > Cloudflare does not offer web hosting for most websites https://developers.cloudflare.com/fundamentals/manage-domains/ https://developers.cloudflare.com/fundamentals/manage-domain...
- mitxela 16d agoThey force you to use their DNS servers.