Also, Google has 8.8.8.8 which could be for the same thing and has similar problems (large scale data collection, singe point of failure).
https://www.akamai.com/us/en/resources/brute-force-attacks.j...
I think it's simply that a lot more people have used Cloudflare because it has a free plan, whereas Akamai is expensive in comparison.
Dealing with salespeople is a massive PITA. They're not going to tell me anything that's not in the docs or support forums and I don't want to spend a week negotiating. I've seen many others make this point on HN over the years.
Maybe Akamai only focuses on large enterprise customers while CloudFlare also goes for the SMB market. IDK. The HN crowd seems to work at SMBs (startups included) or at companies big enough to operate their own CDN.
Obviously they must extract some value for the business but the experience of haggling with some sales bro to get a decent price leaves me so annoyed with services that I usually skip signing up when it’s the only option.
> Let’s talk about solutions!
No thanks. I just want to insert dollars and get the service.
A salesperson could at least ask 'what is a better price we can shoot for?' or 'what features do you really need?' whereas a visitor to a pricing page just disappears.
Your platform may have 1000's of features, not all of which all your clients want or can pay for. Packaging into simple groups may not possible until you have the volumes to figure out what works
Many clients need specific features that you don't have yet, pricing calculation becomes very complex, and depends on customer to customer as well. We will charge more to some customers simply because we know they need a lot of hand holding and special assistance
Note that B2C is totally different and unless you're doing some very high priced / bespoke delivery then you have to go cookie cutter.
Fuck you. Sell me boxes and tell me how much they cost. But they won't.
We sell incredibly complicated systems that necessarily interact with many other complicated systems. We don't work natively with all of them, and sometimes we need to do custom work. Not to mention that we need hardware in many geographical areas, yet still need to work when the virtual space doesn't line up with the physical space.
It's not as easy as "am I buying the small, medium, or large solution". Before you invest tens of millions of dollars into this one product, you need someone from the vendor to analyze your infrastructure and tell you if our product will work, and then how many you need to buy and where you need to put them geographically, and then how many hours of custom programming it will take to get everything working with the other systems.
That's far outside any definition of "salesman" I've ever heard. These people are project architects and their speciality is solution design. It's not a three-tier SaaS solution.
Is there room in this space for a new no-nonsense vendor? Someone who cuts out all the goddamn middlemen and just asks what hardware you want, how you want it configured, and quotes you a frickin price without all the bullshit?
Last project I could have spent that money to pay for 3-4 additional full time engineers for 3 years and built a better solution with open source because I still had to devote 2 plus myself to do integration. And then didn't have overpriced SMS for the next decade and licensing headaches and afford to keep at least 1 of the engineers indefinitely.
The problem is if you only need one or two servers that's too small for most vendors to bother responding. If you're buying 10 or more it can work well.
We'd actually love to be able to give you an "add to cart" price, but the reality is that most of our systems are configured to your specific requirements (with the exception of the FreeNAS Mini, which you can just add to cart on Amazon) instead of just "off the shelf".
It's actually not about trying to figure out how much is in your wallet, I assure you. In fact, we have one of the most transparent pricing processes in the biz. For example, we tell you your end price on our storage systems before a Reseller/VAR is even involved. We also fought the concept of having "list prices" for years, since we all know they're completely fictitious. However, it's something our F500, Gov't, and University customers almost always require so that they can measure and compare their discount.
Nonetheless, we do try to make the design process as quick and painless as possible for you, and regardless of whether or not you give us another shot, the feedback is always appreciated.
Cheers!
and they publish their pricing, no minimum purchase: https://azure.microsoft.com/en-us/pricing/details/cdn/
I’m clearly missing something, but why doesn’t that solve the problem?
And I’m keeping the scope of my comment on the technical side, and ignoring the business/antitrust potential.
As opposed to hosting everything on AWS, so half the Internet goes down when they have a no-so-uncommon outage.
I don’t think Cloudflare is that much of a bottleneck in comparison. Not to mention 3 points of failure is the definition of “not a single point of failure”.
google-public-dns-a.google.com 8.8.8.8
IPv6 address 2001:4860:4860::8888
google-public-dns-b.google.com 8.8.4.4
IPv6 address 2001:4860:4860::8844Is that specific? sure, but I'll tell you when I go to set a new system up I'm going to type 8.8.8.8 because it's what comes to my mind.
From their FAQ:
Does Quad9 support DNS over TLS?
We do support DNS over TLS on port 853 (the standard) using an auth name of dns.quad9.net. dig @9.9.9.9 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 3600 IN CNAME s-us-ca00.kvcdn.com.
s-us-ca00.kvcdn.com. 55 IN CNAME p-ussj00.kxcdn.com.
p-ussj00.kxcdn.com. 55 IN A 209.58.129.70
dig @8.8.8.8 icnerd-1e5f.kxcdn.com
icnerd-1e5f.kxcdn.com. 21599 IN CNAME p-uklo00.kxcdn.com.
p-uklo00.kxcdn.com. 59 IN A 217.146.91.55 4.2.2.1
4.2.2.2
For as often as I manually configure DNS (I use DHCP) it's not onerous to look up the IPs of whatever DNS is preferable for your purpose.edit: Depending on who you are this may redirect you to a search portal. Probably best to find an alternate DNS provider.
# dig +short this-should-be-a-nxdomain.com @4.2.2.2
198.105.254.11
104.239.213.7
They do it a little more cleanly than some other attempts I've seen, but there's still flaws in their approach. In particular, they will generate redirects for NXDOMAIN responses to certain records under domains that do exist: # dig +short why-does-this-resolve.example.com @4.2.2.2
198.105.254.11
104.239.213.7
Specifically, they'll generate a redirect for any record that starts with the letter "w". (No, I'm not kidding. Try it.) Other records generate a real NXDOMAIN. ; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @4.2.2.2
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12860
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
Contrast that with 8.8.8.8: ; <<>> DiG 9.9.7-P3 <<>> thisprobablydoesntexist.com @8.8.8.8
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 7991
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
The NXDOMAIN response is proper - the level3 DNS servers are just a faster version of my ISPs goal to garner ad revenue at this point.There is this comment from a few years ago, https://news.ycombinator.com/item?id=7120248 , linking to a blog post which is now only accessible from the Internet Archive, where a VP at Level3 stated they were public.
I use 4.2.2.x and I do get NXDOMAIN from them, and I'm not a L3 customer. I wonder if they respond differently depending on who you are...
; <<>> DiG 9.9.7-P3 <<>> @4.2.2.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10665
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; ANSWER SECTION:
thisprobablydoesntexist.com. 10 IN A 104.239.213.7
thisprobablydoesntexist.com. 10 IN A 198.105.254.11
;; Query time: 29 msec
;; SERVER: 4.2.2.1#53(4.2.2.1)
;; WHEN: Fri Mar 30 09:27:39 PDT 2018
;; MSG SIZE rcvd: 77Looks like I ran into that issue and went back to Google.
I just changed DHCP config to 1.1.1.1 :)
; <<>> DiG 9.9.7-P3 <<>> @1.1.1.1 thisprobablydoesntexist.com
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 28530
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1536
;; QUESTION SECTION:
;thisprobablydoesntexist.com. IN A
;; AUTHORITY SECTION:
com. 900 IN SOA a.gtld-servers.net. nstld.verisign-grs.com. 1522427379 1800 900 604800 86400
;; Query time: 33 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Fri Mar 30 09:29:56 PDT 2018
;; MSG SIZE rcvd: 132isn't that the recommended behavior? otherwise you can do a bunch nasty stuff like rebinding attacks.
https://www.ietf.org/proceedings/52/I-D/draft-ietf-dnsop-don...
At least I'm not paying Google to do the same, and I can trust that they'll send the proper results.
Use cases are different - Quad9 for "nasty" filtered and 8.8.8.8 for err probably not filtered.
Do it yourself otherwise.
https://www.quad9.net/faq/#Is_there_a_service_that_Quad9_off...
$ dig @9.9.9.10 +dnssec +short verisignlabs.com
72.13.58.64
A 8 2 3600 20180413202737 20180330202737 31485 verisignlabs.com. KrnT9i6qytaYWDZWThBmBwc6anOmawNxJTxmSlpaY3L7Yfupga9FS70l 8nMVp8ggbEtA+CnS9AbNwObkPaYvk3nFpDvo4C+2hg+PECsP1HVTgGxl G3eblfnYAMNfYzLYlfUnSBgM7kLSIXY4rLBxsl01KiPJYezNhmQ53KYf ygs=Take your 1.1.1.1, 8.8.8.8, 9.9.9.9, maybe your ISP DNS, etc., check against them randomly to try and avoid giving any one of them all of your DNS request traffic, maybe look up the same address on two of them to confirm that you're getting the same destination from both?
That's a DNS service everyone would love to use, right?
I suspect that the whole reason why 8.8.8.8 is a Google DNS server is that they were originally only 4.4.4.4 until someone Chinese pointed out that 4 is an unlucky number. :)
Cloudflare gets a lot of press and is doing great things; I’m not concerned about them being a single point of failure on the internet.
The number of sites on Cloudflare is a pretty small fraction of the internet as a whole.
It's definitely possible Cloudflare may go the way of Google at some point in the future, but right now, I'd rather have the former than the latter involved in my Interneting. And in this case, it's a new/additional option, a second point.
In general, in distributed systems a number of inconveniences arise as a natural cost of the distributed nature of the system.
This creates a tendency for a critical mass to circle around a single central entity that uses its central position to provide convenience and further creating a "distributed in theory if you really want it but not really" environment (example: Github).
Not really super related to Cloudflare, just a general observation.
They offer/sell a service that is built using those technologies. People go to them for the convenience you mention. If there were other convenient ways to use those services people would use them as well.
... and there are! Github has competitors (Gitlab, bitbucket, ...) and GMail has competitors (Fastmail, hotmail, yahoo, and a bazillion others). Maybe it doesn't feel like they have enough competition, but if they actually turned git/email into "distributed only in theory" then there wouldn't actually be competition.
That's far from the perfect opposite of “distributed and open”, since these habits can be more fluidly shifted and alternate versions of the convenience processes can exist in theory, but it's also far from what I usually hear people implying when they expect things to be socially distributed as well as technically.
(I'm told that GMail similarly changes the nature of email by making it socially unsafe to operate email addresses in certain ways, but I believe this effect is weaker and I don't have real experience with it.)
Do people here actually think about the alternatives when they complain certain systems are too centralized?
If you stop using Github/Gitlab/Bitbucket today, you won't be able to collaborate because you no longer have a way to do the things Github lets you do. This isn't Github's fault.
Git is decentralized in that it has logic that allows multiple upstreams/downstreams. It's not magic. It's not "blockchain" or whatever.
Github is not decentralized, it's a SaaS product which offers git-compatible and svn-compatible repository storage, an excellent UI, comments, reviews, issue tracking and a bunch more. FOSS developers are asking you to create accounts to Github not so you can download their repository (you don't need to!), but so you can actually use the contributing tools on offer.
Sorry, I realize this isn't the tone you want to hear, but these comments about "centralized systems in decentralized worlds" are just so empty and meaningless. There's a few projects out there which actually try to solve the abstract issues you mentioned by, for example, adding comment/review metadata to git repositories. But you still have access control to take care of and at the end of the day, you need to trust some party; just like at the end of the day, with DNS, you have to put in a couple of IPs that you trust to provide you with good results.
Yes, you have to create a Github account to contribute to some projects. Has nothing to do with git, has everything to do with being able to use the services that Github provides. What is it that you're actually suggesting?
FTFY
Git works without a website just fine. Linus manages one of the largest Git repos purely via e-mail.
And you can do the same. Sure, Github/Gitlab/Bitbucket is more convenient, but you can just put up a Git repo with a static website that says "send patches to <mailinglist>" like it's 2003.
[1]https://addons.mozilla.org/en-GB/firefox/addon/decentraleyes...
They booted the daily stormer, knowing full well the ramifications:
https://blog.cloudflare.com/why-we-terminated-daily-stormer/
"Get out of the way so we can DDoS this site off the Internet."
Matthew Prince basically said "this is dangerous" and a month or two later that exact decision was being used against them in court to take down a copyright infringer.
Not saying one way or another about it being a good or bad decision, but they definitely knew they were setting a scary precedent when they did it.
Let me spell that: A W S