CloudFlare and Google Cloud Platform
cloudflare.com
cloudflare.com
This is not a problem I expect to improve. As they start to cover all of the web, i imagine that it'll actually only get worse. Curious about how they see this progressing.
What's your recommendation as an alternative. Cloudflare is tempting if you are tight on resources due to free SSl, CDN, etc. and it is super easy to setup. I'd love to try out alternatives though, just as a backup.
They have often been short, but sometimes long enough to cause me to sit there and flip DNS for various end points away from them until the issue is resolved.
However we have found random areas to temporarily go down for random periods of times. You will not be able to see these downtimes if you are only checking from 1 location.
Further, it might be better to never serve sensitive financial data via a 3rd party server. That kind of data would be best served directly to the customer's browser from your server.
Better to just pay for Amazon CloudFront or something and set it all up myself...
Its best to use of them as a CDN, DDoS sink, and SSL. Their other stuff like FEO or their web app firewall stuff really isn't that impressive enough to be considered a reason for switching.
Disclaimer: I work in the web performance space, and used to work in the web security space. As a whole I'm not a fan of the "stick a magic appliance in front of a website to automatically stop [web security issues | web performance problems]" approach, whether from CloudFlare or otherwise.
Slightly more work but you control it. Cost is probably similar.
DDOS mitigation is harder and is definitely something CloudFlare does well enough to earn some market share, but wouldn't it be nice if we had a more global solution to this problem that didn't involve third party firewalls?
The servers, ssl and bandwidth costs alone would be more than their fees for any big site.
Yes, this is a security shambles - Cloudflare is officially MITM-ing your traffic. But given the HTTPS-only movement this is a perfectly valid solution for public websites. And this announcement actually makes a big difference because if your platform is Google Cloud, then the un-encrypted portion is now over a private Cloudflare-Google interconnect.
FWIW, I've been using Cloudflare for 6 months and haven't seen any drop-outs. It's improved latency, and the only issue I've had was it mangling email addresses in transit, to prevent scrapers. It took 3 minutes to find the setting and switch it off, so I'm OK with that. Although I would prefer things that modify your HTML should be off by default.
CloudFlare's complicity with ISIS, however, was what turned me off permanently. For those unaware, CloudFlare was providing proxy shielding of ISIS's propaganda websites. The CF CEO publicly refused to discontinue their service, taking an anti-censorship, pro-free-speech stance. His absolutist views didn't sit well with me and I consider their servicing of these domains to be aiding and abetting this criminal organization.
How do you see protocols (bittorrent or ipfs, for example) where content can not be removed as long as someone has a copy - are we better off without their existence in your opinion?
Is ISIS dangerous and deplorable? Sure. Are there ideas so dangerous that they do not deserve to be exposed to public discourse and judged on their merits? I don't think so.
I would oppose the government censoring ISIS; however, I would be proud of any company that refused to to business with them.
I would argue that the moral dilemma is different if you choose to allow ISIS traffic to pass through you, vs have them as a client.
For paid clients, I might be more sympathetic to the argument, but even then the (moral?) rules (for nonbusiness) are incredibly tricky to figure out and keep consistent. Selective enforcement is bad for everyone in the uncertainty it spawns.
Ever heard of this little thing called abuse reports?
I don't think they're choosing to give anyone specific a voice. I think they're choosing not to make judgement calls.
Once you start blocking anyone, you've weakened your ability to refuse to block others. You'd see greater demands for blocking Wikileaks, censoring articles like https://en.wikipedia.org/wiki/Illegal_prime, enforcing Europe's right-to-be-forgotten, etc. on the basis of "well you were willing to block ISIS".
I wonder why you oppose government censorship, if you applaud private businesses achieving the same effect? Certainly your reasons cant be the same as the post you're replying to[0], and so you're missing their point.
[0] in particular Are there ideas so dangerous that they do not deserve to be exposed to public discourse and judged on their merits? I don't think so.
Gagging these people certainly won't calm them down or stop their communication but it has a real effect on their recruitment, which is directly driving their combat operations in the Middle East and as a second-order effect, the flood of refugees to Europe.
Finally, there may be extenuating circumstances of which we aren't aware. Perhaps CloudFlare is granting them use of data in exchange for not cutting cables. When you're that big your presence is indistinguishable from the internet itself.
I cannot readily cite any scholarly papers on this subject; this is from my observations as a frequent reader of /r/syriancivilwar, jihadology.net, and Iraq/Syria-related social media content. The typical pattern is for ISIS to release a video to their propaganda sites and for jihadist social media users to tweet the link.
al-Ḥayāt Media Center (ISIS's media outlet) relies on the ease of distribution via protected (proxied) channels to reach their large audiences. The reach of this content would be more limited if companies like CF wouldn't shield it.
Might be that they were asked to continue to provide services.
Should an American business have an opinion on what Muslims, and other interested parties, ought to be viewing over the web with respect to ISIS? I would hope not. CloudFlare should not be in the business of judging whether Muslims and others are vulnerable to brainwashing from ISIS and need the protection of CloudFlare censorship, lest their fragile worldviews become corrupted.
Let the people of that region judge for themselves the future of their land.
As far as CDN service goes, free SSL and bandwidth and peering + all of their datacenter locations + DNS integration gives us better latency than pretty much everyone else we've tried.
We're a small startup and serve up about 3.5M requests through CloudFlare a day.
when we were using AWS CloudFront, our costs quickly escalated to $100/day as we brought on new customers. We switched over the CloudFlare and made that $100/day cost go away.
CloudFlare's free service has been amazing and we've had no hiccups with it.
We run Quizlet behind Cloudflare, and use Google Cloud for all our server infrastructure (>150 VMs). We've been very happy on both platforms. We'll be saving around $2k/mo on bandwidth because of this deal, and we didn't have to lift a finger. Yay :)
Happy to answer any questions about either platform.
Lots of space in this area.
http://wptavern.com/sucuri-is-building-a-comprehensive-alter...
Were there not search engines before Google? Isn't AWS the cloud computing "leader" while Google is trying to break into the space? There is no such thing as an obvious leader, only juicy prey waiting for the next hungry org to eat its lunch.
> I got the impression that making peering agreements with people on any sort of scale was a bit of a bear.
Hardly. Peering agreements are of similar difficulty level as any vendor negotiation, whether it be with a specific network or an interconnection fabric (IXP).
Name Server: CNS1.REDDIT.COM
Name Server: CNS2.REDDIT.COM
Name Server: CNS3.REDDIT.COM
Doesn't look like it from here.. ;; ANSWER SECTION:
CNS1.REDDIT.COM. 172246 IN A 173.245.58.24
Delegated to? OrgName: CloudFlare, Inc.
OrgId: CLOUD14
There we go! CloudFlare after all.curl -I https://www.reddit.com HTTP/1.1 200 OK Server: cloudflare-nginx
I'm interested. Please expand on the privacy point. I thought the general move to CloudFlare was a good thing for privacy, as it provides an easy mechanism for getting sites onto HTTPS without having every site to worry about managing certificates.
If you're sitting back in your evil chair, this is the perfect vantage point through which to intercept what seems like the majority of all browsing traffic in the world. Even if you're not planning world domination, this is an otherwise unobtainable amount of user metrics you can package up and sell.
Thus the evil guy sitting back in their chair is cloudflare or it's you for not configuring https between your app and them.
This may or may not be what you want/need.
The operating mode described by the comment to which I was responding, that of CloudFlare performing all steps of SSL termination, is one operating mode available. CloudFlare offers at least one other operating mode in which they are not responsible for all aspects of SSL termination. In particular, they offer an operating mode in which they do not hold private keys. This is referred to as "Keyless SSL". Thus the concern voiced by the comment to which I was responding, that of CloudFlare stripping SSL, is but one available option rather than the only available option.
Clearer?
And sometimes modifying is a desirable feature.
We use Google Appengine, and although they have an SSL solution, it was an order of magnitude cheaper and easier to use Cloudflare's SSL.
I'll qualify this by saying our site is public, so we only need SSL because of the HTTPS-only crusade. If you are serving sensitive data, you do need to spend that magnitude more money and time to set up your own SSL.
Those rely on a known DNS history from before CloudFlare was added to a domain. If bypass is a concern, changing the server's IP and making sure it never shows up in a public DNS record again solves things.
* Keep all subdomains on CloudFlare
* Don't use wildcard subdomains if you are not on Pro account
* Don't host mail or other services on the same server as your web server (email headers have origin IP)
* Never initiate an outbound connection based on user action
* Make sure that your web server and web application are patched against all known information disclosure vulnerabilities.
* Change your origin IP once configured for maximum DDoS protection on CloudFlare
Cloudflare documents it here: https://blog.cloudflare.com/ddos-prevention-protecting-the-o...
The public internet does seem to be shrinking, more and more closed data silos and now huge chunks of traffic going through a 'trusted' man-in-the-middle. From an individual sites standpoint it's amazing (and I use it for most of my sites), but the bigger they become the more juicy a target they are.
PNG alpha in particular was a nightmare for me. After that I knew to look out for the pain caused by occasionally-supported features in images.
http://caniuse.com/#feat=png-alpha
PNG alpha transparency was a problem with the decade old IE6. And even then IE6 worked fine with PNG8 images that had alpha transparency. IE7 and IE8 required a 1 line style attribute to work 100% with PNG + alpha, and IE9 did away with that need altogether.
Though I remember that sometimes previews (or was it layers) saved in the .tiff were making it 10x, 20x (not kidding) times bigger, so a special "save" plugin was done to filter these out, and on regular someone wrote a script to check for such.
They have a service that tries to perform loss-free optimization of served images. It's easy to disable, and should be disabled if you either already perform similar optimizations (optipng / pngquant, jpegtran, etc) or have images with annotations, color profiles, etc.
Has that changed?
Railgun is the single biggest improvement a dynamic web site can enable.
The biggest benefit is the established connection between the CloudFlare PoPs and your origin server.
The second benefit is the "compression" that is the result of each side having a shared dictionary.
But really, it's the open connection.
The things I tell my friends to use from CloudFlare:
* DNS
* Railgun
* Caching (my S3 bill is so small now)
* DDoS protection (I'm under attack!)
That's usually the order I recommend it too... Railgun is up there. After that list it tends to get more specific, about their web app and what works for them... but all of the above, just enable and use.
If you are on Chrome and install the Claire plugin then you can view Railgun information in the address bar: https://chrome.google.com/webstore/detail/claire/fgbpcgddpmj...
I'll enable it today and see how it goes.
And this: https://blog.sucuri.net/2015/07/malicious-google-analytics-r...
I and others that I know get this kind of referral spam on every single domain we have with cloudflare. I know DNS records are public, but is there something cloudflare and other public DNS hosting services can do to prevent this?
Google has to cleanup, but sadly, they haven't moved a bit since ages.
1. They are targeting domains specifically with cloudflare nameservers.
2. They are somehow obtaining a list of domains running on cloudflare.
Both these tasks are not hard to accomplish. And it is extremely irritating.
for (var i=0; i<100000; i++) {
ga('create', 'UA-' + i + '-1');
ga('send', 'pageview'); // But with a fake referrer
}
They do that a bunch of times per day from a bunch of different IP addresses. Adding host filtering to your properties on GA eliminates about 80% of spam which use this technique.It's possible you're being targeted due to being in a specific market or something, but it's unlikely to be related to Cloudflare. (At least I can't think of any reason why it would be related.)