3 ms·
> Generally the key you would give them is for, and limited to, the resources that they cache/reverse proxy That got me wondering: Why don't attackers then onl
by Perseids 12y ago
> Generally the key you would give them is for, and limited to, the resources that they cache/reverse proxy
That got me wondering: Why don't attackers then only DOS the dynamic pages? Those that can't be migrated easily, like the login?
- rdl 12y agoThe dynamic pages still go through CloudFlare; there's a Web Application Firewall which can block abuse directed at a specific URL, pattern, etc. The cache is only one part of the DDoS mitigation. (We've been working on a lot of great updates to the WAF for just this kind of thing) Generally with CloudFlare people put as much of their site behind the CloudFlare proxy as possible, for origin-hiding and other reasons, even if we can't cache it (yet).