This is not a problem I expect to improve. As they start to cover all of the web, i imagine that it'll actually only get worse. Curious about how they see this progressing.
This is not a problem I expect to improve. As they start to cover all of the web, i imagine that it'll actually only get worse. Curious about how they see this progressing.
Better to just pay for Amazon CloudFront or something and set it all up myself...
Its best to use of them as a CDN, DDoS sink, and SSL. Their other stuff like FEO or their web app firewall stuff really isn't that impressive enough to be considered a reason for switching.
Disclaimer: I work in the web performance space, and used to work in the web security space. As a whole I'm not a fan of the "stick a magic appliance in front of a website to automatically stop [web security issues | web performance problems]" approach, whether from CloudFlare or otherwise.
CloudFlare's complicity with ISIS, however, was what turned me off permanently. For those unaware, CloudFlare was providing proxy shielding of ISIS's propaganda websites. The CF CEO publicly refused to discontinue their service, taking an anti-censorship, pro-free-speech stance. His absolutist views didn't sit well with me and I consider their servicing of these domains to be aiding and abetting this criminal organization.
How do you see protocols (bittorrent or ipfs, for example) where content can not be removed as long as someone has a copy - are we better off without their existence in your opinion?
Is ISIS dangerous and deplorable? Sure. Are there ideas so dangerous that they do not deserve to be exposed to public discourse and judged on their merits? I don't think so.
I would oppose the government censoring ISIS; however, I would be proud of any company that refused to to business with them.
I would argue that the moral dilemma is different if you choose to allow ISIS traffic to pass through you, vs have them as a client.
For paid clients, I might be more sympathetic to the argument, but even then the (moral?) rules (for nonbusiness) are incredibly tricky to figure out and keep consistent. Selective enforcement is bad for everyone in the uncertainty it spawns.
Ever heard of this little thing called abuse reports?
I don't think they're choosing to give anyone specific a voice. I think they're choosing not to make judgement calls.
Once you start blocking anyone, you've weakened your ability to refuse to block others. You'd see greater demands for blocking Wikileaks, censoring articles like https://en.wikipedia.org/wiki/Illegal_prime, enforcing Europe's right-to-be-forgotten, etc. on the basis of "well you were willing to block ISIS".
I wonder why you oppose government censorship, if you applaud private businesses achieving the same effect? Certainly your reasons cant be the same as the post you're replying to[0], and so you're missing their point.
[0] in particular Are there ideas so dangerous that they do not deserve to be exposed to public discourse and judged on their merits? I don't think so.
Gagging these people certainly won't calm them down or stop their communication but it has a real effect on their recruitment, which is directly driving their combat operations in the Middle East and as a second-order effect, the flood of refugees to Europe.
Finally, there may be extenuating circumstances of which we aren't aware. Perhaps CloudFlare is granting them use of data in exchange for not cutting cables. When you're that big your presence is indistinguishable from the internet itself.
I cannot readily cite any scholarly papers on this subject; this is from my observations as a frequent reader of /r/syriancivilwar, jihadology.net, and Iraq/Syria-related social media content. The typical pattern is for ISIS to release a video to their propaganda sites and for jihadist social media users to tweet the link.
al-Ḥayāt Media Center (ISIS's media outlet) relies on the ease of distribution via protected (proxied) channels to reach their large audiences. The reach of this content would be more limited if companies like CF wouldn't shield it.
Might be that they were asked to continue to provide services.
Should an American business have an opinion on what Muslims, and other interested parties, ought to be viewing over the web with respect to ISIS? I would hope not. CloudFlare should not be in the business of judging whether Muslims and others are vulnerable to brainwashing from ISIS and need the protection of CloudFlare censorship, lest their fragile worldviews become corrupted.
Let the people of that region judge for themselves the future of their land.
They have often been short, but sometimes long enough to cause me to sit there and flip DNS for various end points away from them until the issue is resolved.
However we have found random areas to temporarily go down for random periods of times. You will not be able to see these downtimes if you are only checking from 1 location.
Further, it might be better to never serve sensitive financial data via a 3rd party server. That kind of data would be best served directly to the customer's browser from your server.
Slightly more work but you control it. Cost is probably similar.
DDOS mitigation is harder and is definitely something CloudFlare does well enough to earn some market share, but wouldn't it be nice if we had a more global solution to this problem that didn't involve third party firewalls?
The servers, ssl and bandwidth costs alone would be more than their fees for any big site.
Yes, this is a security shambles - Cloudflare is officially MITM-ing your traffic. But given the HTTPS-only movement this is a perfectly valid solution for public websites. And this announcement actually makes a big difference because if your platform is Google Cloud, then the un-encrypted portion is now over a private Cloudflare-Google interconnect.
FWIW, I've been using Cloudflare for 6 months and haven't seen any drop-outs. It's improved latency, and the only issue I've had was it mangling email addresses in transit, to prevent scrapers. It took 3 minutes to find the setting and switch it off, so I'm OK with that. Although I would prefer things that modify your HTML should be off by default.
What's your recommendation as an alternative. Cloudflare is tempting if you are tight on resources due to free SSl, CDN, etc. and it is super easy to setup. I'd love to try out alternatives though, just as a backup.