Cloudflare’s service’s questionable practices
devever.net
devever.net
I personally love Cloudflare. It's made a ton of stuff a lot easier for me as a developer. Sure, there's some downsides... but that's true with any service. (And a lot of the complaints are opt-in features that the web developer enabled)
It seems the author only has problems with Cloudflare almost completely because he uses Tor. Unfortunately, most Tor traffic is malicious (94%, by Cloudflare's count), and the whole point of Cloudflare is to prevent malicious attacks.
Anytime you do something for privacy (block ads, disable JS, use Tor), unfortunately things won't always work exactly how you expect.
Lastly, it ends with a weird conspiracy theory... "It is probably a US Government-attached intelligence agency". Okay.
Partly because they use Tor, partly because they use a browser which supports neither Javascript, frames, nor images (i.e, Lynx). What both of these things have in common is that they are problems of the writer's own creation.
Also, Cloudflare's email address munging is optional. Web site operators can (and usually should) disable it.
Technically it the developers whose sites don't degrade gracefully who created the problem for users. JS, images, frames, and trackability are not required to deliver much of what people want out of the web.
I’d probably buy now.
And I wouldn't even need any of the newer features (even though I love Access). WAF, CDN and DDOS protection on a free plan for hobby projects would already be enough.
In the same vein there are thousands of users complaining on Twitter[1] -and everywhere else- every day about the captcha CloudFare forced upon them
[0] https://security.stackexchange.com/questions/154975/what-is-...
[1] https://twitter.com/search?q=Captcha%20cloudflare&src=typed_...
- The bulk of the funding for Tor's development has come from the federal government of the United States, initially through the Office of Naval Research and DARPA.
https://en.wikipedia.org/wiki/Tor_(anonymity_network)
- Using Tor gets attention to you
https://www.trustedreviews.com/news/nsa-use-linux-or-tor-you...
I guess he's trying to be snarky here, but it's obvious their business is to prevent DoS attacks against the server by malicious clients.
I imagine the extremely large majority of clients [fully-featured modern web browsers] can get past the captcha (or JS challenge), therefore it's only a 'DoS attack against the user' in the small amount of situations where the user's client/browser doesn't have the technology required to solve the captcha (or JS challenge). If lynx or other non-JS browsers had a surge in popularity and CF's enterprise customers complained, you can assure they would have a solution out within a week that would not require JS or cookies.
It's a rather typical blindness of US (and to a lesser degree EU/AU/.. ) companies, which by design or accident care mainly about US and other rich country users.
Maybe that's the problem, the current scale of the internet and of human civilization means it's nearly impossible to use fairly-accurate humans for these types of things; the only option for managing something that works for the entire world is by turning to error-prone computers that we can only bet on someday being as good as humans at making decisions with the full context provided.
In that case Cloudflare enables them to do it but I wouldn't call them responsible.
I must assume that he does not know this, and if this guy doesn't, then how to calculate the odds that X percent of Y (how many people are sharing what they read through cloudflares pipes everyday?) - how many people don't know they are being spied on and info about them is being sent to others because a host is routing through cloudflare?
But most commonly Cloudflare just blocks access to what should have been a static version of the website in the first place.
You make it sounds like it's actually very expensive to generate every single page. If so, you're doing the caching wrong. If not, then you don't really gain anything by blocking access to a few users to a static version of your website.
Source: I run a website with 400k pages; out of a single machine that I pay 30 EUR/mo for. It's kind of annoying when random Tor clients spam the hell out of my access_log. But is it worth blocking them to clean up my access_log? Not really.
I have a single server on another continent, yet my pages load several times faster than any of these Cloudflare-powered websites served from another part of town.
Let's Encrypt itself is an artificial construct that your homepage would hardly benefit from, and where Cloudflare reaps the most benefits from by having it be a selling point that noone outside of commercial entities ought to need in the first place.
websites in fact should stop using cloudflare, however the rant displayed here is irrelevant.