Turns out half the internet has a single-point-of-failure called “Cloudflare”
easydns.com
easydns.com
Screen readers, the programs that use synthesized speech to tell us what's on the screen, cannot read images. Good captchas usually have audio equivalents (which come with their own set of problems), but this one doesn't. If you're blind and flagged by Cloudflare for some reason, you're cut off from accessing half the internet, potentially critical banking/governmental/medical/communications/educational services. We rely on the internet way more than our sighted peers, so this is very important. This has recently happened to me on a few sites, fortunately not critical ones, but it was not a pleasant experience nonetheless. CF engineers, please fix this ASAP. I'm surprised there still isn't a huge lawsuit over this, as this is clearly violating all sorts of laws.
At the same time, if Google is advertising Recaptcha as accessible and it's not really, then they need to be held accountable for that, because that has a real impact on huge swaths of the internet, and especially for sites that try to do the right thing and find out Google has screwed them.
In the world of licensed contracting you absolutely do. If you provide a contractor specifications that result in a code violation, they have to tell you no. If they don't tell you no then you, the non expert, are reasonable to assume what you asked for is acceptable. If they actually build the thing, they are liable for the violation of code.
The last thing we need is to hand out more excuses to evade accountability and responsibility for making the world worse.
> The last thing we need is to hand out more excuses to evade accountability and responsibility for making the world worse.
I'm definitely not advocating that. I'm more advocating that you can't leave all this to someone else entirely. Even if you pay someone for a turn-key custom website and make sure it's accessible, there's no guarantee it still meets standards a year from now, just as if you pay a contractor to build a ramp for you that perfectly meets standards. Things change, and people need to pay attention to the things that matter to them to make sure they follow the law. Whether that's occasionally checking it yourself or paying someone else to do so (and thus ensuring it happens), it still needs to happen.
We must stop giving excuses to the massive centralization, to the enormous companies that step in and rent-seek what is supposed to be a distributed system.
The most powerful tool we could have to get a proper internet back is the simple concept of accountability. If I was a bakery and I made a cake with poison because I was specifically asked to do so by a customer, I would still be accountable for the dangerous thing I made.
Stop making excuses for these companies with basically infinite money. They are the last ones who need it. What we all need from them is accountability.
This also goes for section 230 protections. We do not need Twitters and Facebooks and Hacker Newses and other such companies that would supposedly not exist without section 230 protection. It's clear now, in retrospect, that accountability is far more important than the license to grow enormous without any responsibility for the toxicity your giant bloated corpse of a business unleashes onto the world.
Anyone making a captcha product can and should be expected to make it work for anyone. And if there is basis for lawsuit, it should be the maker of the broken thing that faces it.
Hell, sue them both. Neither entity deserves a free pass. They both had a part to play in the exclusion.
As human beings first and programmers later, we should understand that people with disabilities exist and assistive technologies need attention.
Why, as decent human beings, don't we do something nice without the push of laws, for once?
I would argue that this is the case, yes.
> If so, then yes, enforce them
If only I could.
I don't think that is will be common in the wild, but it is an argument against regulating captcha providers rather than websites.
You can go the Google route and choose accessibility and security, do massive user tracking, and don't even show CAPTCHAs at all for normal users. HN users probably see a lot, because they use some anti-js or anti-tracking stuff, but normal users don't.
You can go the Cloudflare route, requiring users to solve visual challenges, sacrificing accessibility, but keeping security and privacy.
You can also implement audio CAPTCHAS, which are easy to solve for robots, get accessibility and privacy, but less security.
This is not the case. After just a few captchas the audio challenge will be locked off no matter what browser you use.
> and don't even show CAPTCHAs at all for normal users
You see them in firefox from the start as well as on chrome after around the 2nd or 3rd captcha, this is with the default settings + ublock origin on both browsers.
Cloudflare switched to using hCaptcha a couple months ago, I think and I only just noticed that they do not offer an audio-based captcha.
However, hCaptcha integrates with Privacy Pass[0], and you can top up your tokens by solving a captcha at [1] and [2]. What you could do (and I realize this is far from ideal), is getting a sighted friend to solve a couple of captchas so you have enough tokens to last you a couple months.
The problem is hcaptcha, the solution is stop using hcaptcha. Not placate and evade with work arounds you wouldn't even suggest to non blind people.
Also this ask a friend solution is like telling someone in a wheelchair to ask a friend to help them up those steps instead of just installing a ramp.
You don't get to take over half the internet and just ignore social responsibility.
People call for this all the time when a major security vulnerability is discovered. The difference is in how the community views it.
Cloudflare should weigh harm of blocking access to the Deaf community warrant the harm of removing a captcha that doesn't support them. They should have done it when they chose a captcha that doesn't support the Deaf community.
As technology comes to mediate every avenue of life, we need to recognize that technology only has value in its positive effects on people's lives. A security vulnerability is bad because owners may lose control, property may be lost, crimes may be committed. Usability vulnerabilities can deny services essential to their users. You're totally correct that there is no magic solution, but to say that we know which imperfect solution is preferable is incorrect.
It's not possible for a dev to go back in time to before hcaptcha was created or when CF decided to switch to them to create said ramp, so until it's built, workarounds are the only real thing a community member can offer someone in the short term.
So, with that in mind, knowing where we currently are, not where we'd like to be in an ideal world, what, exactly, do you want to be done right now by members of the community?
It's not like we can all go in and change the Cloudflare code to stop using hCaptcha. The most we can all do is give alternatives and workarounds while pushing on Cloudflare and hCaptcha to support this scenario. Which is all being done in this thread already.
My personal opinion is that it's better to use hCaptcha. I wasn't aware that they don't support audio. I think a better approach would be requesting hCaptcha to implement the missing bit.
Giving less control to Google is better. Given the widespread tracking they have access to right now.
I agree, and I could’ve been clearer. The Privacy Pass workaround shouldn’t be necessary and we should demand Cloudflare do better.
(To avoid any doubt: I’m not affiliated with Cloudflare in any way, other than that I’m a customer on their free plan.)
You're responding to a rando on the internet, not the CTO of Cloudflare. Your parent is just trying to offer help to OP, and you're mad because you assume he is a Cloudflare dev? Even if he was, it's not like he has unilateral control over product decisions.
...and they're ignoring the law in many place.
[1] https://en.wikipedia.org/wiki/LightHouse_for_the_Blind_and_V...
[0]: https://github.com/privacypass/challenge-bypass-extension/is...
[1]: https://github.com/privacypass/challenge-bypass-extension/is...
Another user mentioned the Privacy Pass solution: https://news.ycombinator.com/item?id=23902870
While Privacy Pass is not perfect, we are working towards getting better. I'm not in the product flow for accessibility, but if you have ideas outside of audio that you believe would be able to distinguish between yourself and a robot, I'd be happy to discuss via email to ensure that we can get a solution for you and anyone who can reasonably interact with a computer.
eta: you can email me directly at work via: josiah@intuitionmachines.com
often it's easier to just use a website as api instead of using some broken xml nightmare that requires knowledge of the database tables.
If the concern is rate limiting then just rate limit the website. And if you don't like people operating websites with bots then I don't know, maybe stop making websites.
This is a no-win situation. I’m not convinced it’s possible to have ones cake and eat it too, here. Someone upthread said “security, privacy, accessibility, pick any two”, and I have yet to see any evidence of a third option.
Captcha will stop saving money, if the captcha becomes so ineffective that the short-term and the long-term downside (annoying users who are subjected to captcha) exceeds the cost saving ("cost" here is potentially many different things - it could be quality of service for normal users, it could be opportunity cost, it could be the cost of serving the traffic like network bandwidth or cpu or database capacity).
Are there not "ML techniques" for visual captchas too ?
With more and more powerful models like GPT-3 coming along every few months, Even if the accuracy levels are less for visual over audio today how long do you think that is going to last ?
I would say given the choice for a number of people the accessibility is more important than loss of privacy. At least it is choice they should have instead of shutting them off the internet.
There are.
> how long do you think that is going to last?
I don't know. So far it hasn't been difficult to recognize the garbage traffic when we take the time to look. And attackers always make it easier by releasing github source and / or announcing their results on Twitter.
Do your devs or product people ever use your own product? That’s one of the first things I’d notice and fix.
In the future, if you've got a bug that's preventing you from doing your thing, we have bug reporting instructions: https://www.hcaptcha.com/reporting-bugs
ETA: two different people have tested on Chrome and Safari on iPhone 6S locally, and can't reproduce. Please take a screenshot and provide more information to: https://www.hcaptcha.com/reporting-bugs if you want to get this fixed.
As someone that works in ed tech - anyone that supports higher education is required to support screen readers etc. If any of those sites are using cloudflare that would block them from being compliant pretty seriously.
This issue is mostly unnoticeable, as long as you're not considered malicious to Cloudflare, everything works perfectly and passes accessibility audits. When something weird happens and Cloudflare flags you, you cannot access the system at all.
For those doing accessibility audits out there, this kind of issues might be worth looking into, as they're very non obvious and very critical.
I might recommend reaching out to the CEO, Matthew Prince, with a succinct explanation of your problem and I would be surprised if that by itself does not kick off some serious positive action!
Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw? Do they just to a tremendous job of migrating sites from free to paid plans?
https://www.sec.gov/Archives/edgar/data/1477333/000119312519...
I was worried a bit when I saw the initial IPO that the free tier would leave (despite promises it wouldn't) but that doesn't seem to be the case. Literally the only bad thing I've seen on the site is recently you switched from recaptcha to a new one that I had a real tough time with logging in today - it was a bit glitchy on my pc. The only suggestion I thought of as well would be a simple "maintenance mode" similar to the "I'm under attack mode" which would allow those of us without super-ha to quickly toggle on something to pop up a "sorry server"/site is down form maintenance page without having to mess with our proxies/web servers.
Anyway I know this comes across as totally kissing-ass but I just wanted to say thanks to someone who actually works there. Everyone fat fingers stuff every now and again,don't sweat it.
I really liked the stories of his skill when he was in his prime. Very inspiring.
I'm not sure what to take from this. But thank you for sharing it
I wonder if there are any relationship between FTD and how clever a person or how much brain a person uses.
Robert Sapolsky - Phineas Gage and frontal damage https://www.youtube.com/watch?v=5wKDXzk8Wm4
In all, it was a captivating read.
To be sure (and for the sake of internet rando completenessism), it does look like CF waited until the original SGI patent on the technique ran out. :)
As ever, innovation was brick-walled until IP got out of the way.
That's right. See https://news.ycombinator.com/item?id=23860658
Right now: there is an issue with Safari users on the most recent iOS and OS X, where 3rd party cookies have now been disabled by default. We're working on a solution.
If that's your issue, you can fix on your side in the short-term by not using Safari, or by enabling 3rd party cookies.
(posted in case others are hit by this) using `requestStorageAccess()` on a user click event seems to work and that's what we're rolling out :/ https://gist.github.com/iansltx/18caf551baaa60b79206
I mean CDNs that will let you override the origin's cache instructions and do a decent job of DDOS protection, and whose feature list otherwise looks a little like Cloudflare's.
There are smaller CDNs out there. You can find them readily enough.
Which suggests to me that CDNs are already a commodity in some ways.
A second answer - there are a bunch of bottom-barrel commoditized pipe services. You likely haven't heard of them because they're so generic. They've existed before Cloudflare, and more will be created in the future https://www.citrix.com/products/citrix-intelligent-traffic-m...
Respectfully, the info in the S1 (flywheels, etc.) seem to be what sustains you _now_.
Maybe a better question is "how did you identify and kick off that flywheel?"
Market Opportunity
We believe our platform disrupts several large and well-established IT markets. The key markets that are addressed by our platform include VPN, internal and external firewalls, web security (including web application firewalls and content filtering), distributed denial of service (DDoS) prevention, intrusion detection and prevention, application delivery controls, content delivery networks, domain name systems, advanced threat prevention (ATP), and wide area network (WAN) technology. From our analysis based on IDC data, $31.6 billion was spent on those products in 2018, which is expected to grow to $47.1 billion in 2022, representing a compound annual growth rate of 10.5%. We also are actively developing new products to address adjacent markets including compute, storage, 5G, and Internet of Things (IoT) that are not included in the estimate of our addressable market.
Bandwidth isn't expensive compared to what most people are paying for it. Cloudflare is paying for the infrastructure as it is to handle attacks, so why not use it? As long as it doesn't affect paying customers then it's great marketing.
I may not have a full scope of the history, but my own experience with DDoS protection was quite different. Whilst providers offered anti ddos protection through GRE tunnels and dedicated machines behind DDoS appliances and a heavy null route hand, Cloudflare had a simple few-click solution that worked at the web application level making things a lot easier and, also, allowing for features like caching, and thus, CDN benefit from a global network. Further, they've maximized performance on their machines, and as a result, Cloudflare is wicked fast.
Cloudflare does what it does really well and has built additional services on their global network that make a lot of a sense and provide a lot of value.
Hats off to CF.
If AWS was able to offer a single click "DDOS protection and CDN" feature with similar pricing and features as Cloudflare then I'd consider it since most of our infrastructure is on AWS but at the moment they don't offer anything nearly as competitive. Just the Cloudfront bandwidth costs alone would dwarf our total infrastructure costs.
My reservation with Cloudflare is the concept of letting a third party MitM my SSL traffic. That and it's more expensive than a cheapo CDN like Stackpath if all you really care about is CDN (and Cloudflare isn't even really a good CDN, just a quick hack to speed up small static files).
Perhaps I have overlooked something?
So in this way it's possible to setup CDN with shared SSL for purely static files but not the app server itself; you don't have to give the keys to the whole kingdom so to speak and it's cheaper than Cloudflare at the basic level.
I was under the impression that the same result could be achieved with Cloudflare, or indeed nearly any CDN. Was I mistaken? Though you may not actually need a secret, private subdomain for static files with all CDNs.
Again, please let me know if I've made a mistake somewhere. I'd love to learn something this morning.
static.domain.com (CDN subdomain with auto provisioned TLS)
static-uncached.domain.com (private pass-through subdomain when CDN is missing a file)
www.domain.com (app server hosted wherever)
You're right that you could do something similar with other CDNs including Cloudflare (you can just set the www subdomain to "bypass Cloudflare" to accomplish a similar result), but I'm not aware of any way to use Cloudflare on a domain without forwarding your nameservers to them, effectively giving them complete control over the domain. At least with Stackpath I can host DNS wherever and simply point the subdomains I want at them.
Also, by the time you do the work to split static files into separate subdomains you might as well go with a dedicated CDN. One of the selling points of Cloudflare is for sites serving everything on one subdomain that they can forward to Cloudflare and get caching without any work.
It requires at least the Business level plan, though.
Not even "exceptionally difficult", but flat-out impossible. From the perspective of an observer, TLS sessions are random data. The protocol is specifically designed to defeat attempts to replay data -- a CDN is indistinguishable from an attacker in that sense.
I wonder what the Venn diagram of people who insist every website must use HTTPS for privacy reasons and Cloudflare users looks like.
When a 3rd party has access to your keys, their responsibilities to you are spelled out in your contract with them. That's true for CDNs as well as hosting companies.
For most websites today if someone can intercept traffic somewhere close to the server they don't even need the keys, they can just fake responses to pass CA validation and issue valid certificates with their own keys and MITM like there is no encryption.
And coldboot attacks performed by a hosting provider staff of dumping memory and finding keys isn't that realistic of a threat, just like putting servers into a locked cage on someone else's property isn't much of a protection.
If you press F12 in your browser and navigate to some major sites, you'll notice anywhere between 1-5 different CDN domain names that aren't directly related to the original host in any way.
That said bandwidth really isn't that expensive, at least if you're buying it at the scale that Cloudflare does. Many people seem to be used to the bandwidth prices of the large cloud hosters, which are really insane and have been marked up by a large multiplier to disincentivize people to transfer their data elsewhere for processing.
Suffice to say, that in over 5-6 projects I have added CF to, it's never worked out in my favour.
A million URLs isn't big?
> We must be your domain registrar for this to work...
IIRC, Netflix OSS published some tools quite some time ago to support multiple DNS providers but I don't know/remember if they tackled the availability problem. The question comes down to build vs buy and whether the solution is general enough to warrant an Open Source Software solution.
> The only requirement to use Proactive Nameservers is that we have to be your registrar, because we need to connect to the registry to update your nameserver delegation.
So I guess technically this could be achieved with an API for your domain settings.
The classic way of doing this is AXFR (your own DNS server is a "hidden master" and the DNS providers are the slaves).
The problem is you won't be able to have redundancy at the registrar level, but that has historically at least been less of an issue.
The magic happens at BGP level.
I considered CF as a domain registrar, but they don't allow setting the NS records. So you must use them. (They basically use sane no-nonsense domain registration as a way to gain leads for their main product. Pretty smart actually, because it's a great high-level add-on for their main product, but they just went ahead and made that the bait for everyone.)
Anyway, ideally, if you add 2 separate sets of NS servers to your NS records then you eliminated this SPoF, great. Sure, it's your job to keep them updated, and in sync (preferably, to avoid problems like half of your users landing on a different CNAME/IP/etc).
And recursive nameservers will handle the failover.
What are the brands offering DNS at a flat rate over anycasted IP over a few continents?
Most of the offers I see are per query at high rates. Setting up my own ASN to do this would be too expansive in IPv4
There's HE.net's free DNS, and though they don't explicitly advertise as, it's anycasted. (Check via https://tools.keycdn.com/ping , try 216.66.80.18 [ns5.he.net].)
https://www.cloudns.net/premium/ seems to be quite affordable with no query limits :o
You could do it with BGP, but it is non-trivial and you need your own ASN to do that.
In theory they could simply create a few subsidiaries, let's call them saferDNS1,2,3 and have them build completely different redundant DNS architectures, and add then add the resulting nameservers.
That said, it'd be good to see an actual domain that uses this "proactive" feature to see what easyDNS is doing.
So if you have Cloudflare + (ex:) NS1, and you're using Cloudflare for caching, you need your NS1 records to return Cloudflare proxied IPs normally, but origin IPs under failure conditions. That's a lot of infrastructure.
It also fails completely if you're relying on Cloudflare for DDoS protection and IP obfuscation because a failure means your origin IPs get exposed. That's assuming Cloudflare DNS being down means Cloudflare proxying is down too. It might not be the case, but I think you'd have to plan for it.
Then there's also Cloudflare's detection of nameservers. I haven't tried it with more than Cloudflare's nameservers set for a domain, but if your domain doesn't actively use their nameserver they'll drop your site from their system. So, at the very least, you can't use Cloudflare as a secondary DNS provider (at least the last time I checked).
Of course CF doesn't support anything like this, but it works well (because they use quasi fixed, static anycasted IPs for the HTTP(S and TCP?) proxying/load-balancing too), even if it's hacky as hell.
If they have any active verification of nameservers, and if they disable the proxies if they detect something bad, then ... it won't work obviously :)
But technically there's nothing amazing in being a registrar of a domain. So both CF and easyDNS are just stubborn in the name of user experience (consistency).
... all in all, working around any SPoF (reliably) will usually require exponentially more resources/engineering/care.
That's a huge negative and I can't believe they think it's a good marketing point. I don't want a patent encumbered, non-standard solution for critical infrastructure.
> We must be your domain registrar for this to work.
So they're updating the domain record at the registry level to facilitate failover? That's the only scenario I can think of where they _need_ to be your registrar. Assuming that's the case...
I've always seen 24-48 hours quoted as the worst case wait when updating nameservers at the registry. I've never seen an explanation of how it works, what's allowed to be cached, how long it actually takes to update, etc.. How do they do it in a way that's suitable for failover? Do they have a special SLA with registries?
How would the registries handle a deluge of nameserver updates? Imagine a Cloudflare scale failure and corresponding registry updates. Would the registry servers be able to handle it?
I'd love to see a technical explanation of how their proactive nameservers system works.
I gave Cloudflare a fair shake. But after hearing their lies way too many times, I'm calling them out for being deceptive and unscrupulous.
After being told that sites pretending to host Adobe Flash updaters and pretending to be Bank of America can't be taken down by Cloudflare because of their rights to free speech, I knew their attempts to pretend to be one of us, attempts to pretend to care, were nothing but bullshit.
They claim they don't host. If hosting DNS is not hosting, then what do you call DNS hosting? You literally CANNOT use their abuse web form to report domains which use Cloudflare just for hosting DNS. They do not handle abuse sent to their abuse email address (they simply send a form response saying to spend ten minutes filling out their crappy form that has all sorts of problems).
Of course, their web proxy services are also "not hosting", even though they're protecting all sorts of scammers.
So why should we think they're not bullshitting us when they run 1.1.1.1 and tell us they're not logging? Why should we trust them more than our ISPs by running DoH through them?
They WANT us to be dependent on them, because the more control they have, the more money they can make. It's dangerous, and they've shown they have no honor.
I've genuinely tried to correspond with them on Twitter, and they excel at not answering the question asked but instead just diverting. It's scummy, unprofessional behavior and I encourage everyone to consider whether they deserve anyone's data or business.
I think this is an important point about CloudFlare that can't be made often enough. It's been some years since I first noticed, and it seems as true today as it was then: wedging themselves into core Internet services and data flows seems to be an intentional part of CloudFlare's strategy.
There is no case given the architecture of the Internet where one company need be exposed to so many traffic flows from millions of people. The search engines got there first and we eventually stopped complaining, but this does not make it any more justifiable to copy the model.
What reason would a company have for desiring this outcome? We know Google can detect and predict flu outbreaks. Imagine what is possible when you have every click on every target web site.
There is a fair chance their data is already approaching the comprehensiveness of Google, and I'd be surprised, if not disappointed to learn they were not already working on unannounced (now or eternally) internal intelligence products based on that data. There are simply too many pockets who would be willing to pay for it.
Remember, carriers and service providers not allowed to decided what to do based on content?
https://www.fastcompany.com/90312063/how-cloudflare-straddle...
https://blog.cloudflare.com/cloudflare-and-free-speech/
> the company serves at least seven groups on the U.S. State Department’s list of foreign terrorist organizations, including al-Shabab, the Popular Front for the Liberation of Palestine (PFLP), al-Quds Brigades, the Kurdistan Workers’ Party, al-Aqsa Martyrs Brigade, and Hamas.
> CEP has sent letters to Cloudflare since February 13, 2017, warning about clients on the service, including Hamas, the Taliban, the PFLP, and the Nordic Resistance Movement. The latest letter, from February 15, 2019, warns of what CEP identified as three pro-ISIS propaganda websites.
All this while routinely censoring other sites. Their actions are very different than their words.
“ This question assumes the answer. A website is speech. It is not a bomb. There is no imminent danger it creates and no provider has an affirmative obligation to monitor and make determinations about the theoretically harmful nature of speech a site may contain.”
Their only use is to suppress speech.
The problem with near market monopolization, oligopoly, even the singularity, the fail-case is catastrophic and may even wipe out decentralized, diffused, dispersed, decoupled system solutions that can't make it due to so much relative size from the big fish that it squashes them along the way. The bigger the ship the longer it takes to turn.
This Cloudflare issue is like the recent Facebook SDK startup crashes where everyone has a single point of failure on Facebook SDK where people should be using or able to use the OpenGraph API directly as they need which is more robust to the app that uses it, it won't crash on startup.
In business it is a goal to centralize to grow, in nature and robust systems it is more differentiation and decentralization to survive. There will always be a push and pull between these two forces.
Systems and markets are like gardens. The garden must be maintained, new seeds planted and helped to grow from small to mid-sized, mid-sized plants the bulk of the garden, and then the larger plants need to be culled back when they get too big to not take the mid-sized and then all the resources from the new seeds/small plants. The problem is we have allowed the top end to take over the garden and when they fail they fail spectacularly. The bigger the scale the bigger they can fail.
How would you even set such a thing up? I fear that you might get a couple of collusionary companies that bail each other out and smaller providers might just be left out to dry…
I do love using CloudFlare for DNS, lots of great features and generally works well, but I wish they would support AXFR for the lower tiers. I've been working on a solution for this using the CloudFlare API, but we'll see how well it works out.
However, cloudflare decision turns cloudflare "free" offering into a free SPOF. They should extend this offer to their free users, who could then use the secondary DNS that most hosts/domain name sellers provide for free to the IP that is proxified by cloudflare. It could even be limited to the case of proxy or cloudflare DNS failure, so that cloudflare could still price discriminate (make AXFR fail, unless cloudflare is down, like a dead man's switch)
That's all they did. They weren't a mail host or provider, there was no UI, nothing. All they did was allow you to specify them as, well, a secondary MX, so if you were offline they'd cache your inbound email until you were back. Simple. Efficient.
> At easyDNS we experienced so much pain from this reality that we created a system to automate flipping DNS providers at the first sign of trouble.
> We call it Proactive Nameservers, and we’re the only company in the world doing it for some reason. Maybe this is because in order to provide a service like nameserver failover, it means a company has to admit to its customers the reality that their own nameservers may at some point, fail.
Yes there are a lot of smart people at FAANG and Cloudflare corp.
There are a lot of just as capable folks not driven by job addicted meme.
Technically there’s no reason the web couldn’t be replaced with 1:many via Wireshark key sharing based access control to local content.
But via Wall Street, along these very particular rules, is how we are told to trade information. How is that not a planned economy?
Not just by doing what we’re clearly interested in doing naturally.
Make no mistake: big corp isn’t making us login at gunpoint. “They” didn’t do this. “We” did this.
You needn't use your real name, of course, but for HN to be a community, users need some identity for other users to relate to. Otherwise we may as well have no usernames and no community, and that would be a different kind of forum. https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
How so?
On a century scale individual murderers aren't a huge concern to society because they are either dead or infirm by then.
I think for the sake of a diverse community and economy, monopolies should be difficult to achieve even naturally.
But for this specific example, a robust technical redundancy doesn't stop CloudFlare from going out of business. A technology company going out of business is pretty much the norm. Incumbents are a relatively new phenomenon for technology (sans some key exceptions), and I don't think CloudFlare is an incumbent. They are an accessory, and your business would probably run without them.
Cloudflare has had network affects from integration with wordpress and cpanel too I believe for some time now.
without cloudflare your site can be taken offline by any random person willing to spend $20 for ddos sellers.
The free plan is a pretty big moat imho, especially if 'half the internet can fail..' - I doubt 10% of those sites would be using cloudflare if there was a monthly fee pushed on them.
Admittedly, my cloudflare usage is only about 30 sites, so my data point is small. The few hosting and design clients I have and their budget constraints are not indicative of 'half the internet' - but I don't believe fortune 500 and SV sites are either.
There is no cloud monopoly either. Customers can choose from AWS, GCP, Azure, and several others.
The problem is not market concentration. There are plenty of options. The problem is customers choosing to put all their eggs in one basket.
The DNS is part of the load balancing, they serve different IPs based on location of the DNS query.
Edit: Apparently they do support a CNAME configuration if you pay for one of their business plans. That gives you the option to quickly switch away (if your TTL is low enough) but will impact performance by having to fetch the CNAME every 60 seconds.
But I'm pretty sure they use DNS do other loadbalancing and DDoS mitigations.
For example, if a site is under attack, they can send it to different IP addresses to keep it away from other sites. Or if someone is directly targeting a cloudlflare IP with a DDoS, they can redirect all sites to other IPs and just blackhole that IP.
Shouldn't be too hard to build an abstraction layer that updates them all when you need to make changes.
It makes sense that cloud companies are inclined to keep customers from giving money to competitors, but they way they sell it and structure services, reserved instances, and enterprise discounts is such that you basically are putting all of your eggs in one basket.
Nobody got fired for buying IBM, until they did.
One of the selling points of cloud providers is managed services like SQS. If you run a multi-cloud architecture, you either can't use managed services, or have to build abstraction layers on top of them (and only use the features that exist in both cloud providers' versions of the managed service).
If you want to use a managed service that only exists on AWS, then that's obviously incompatible with a fully multi-cloud architecture.
And this is, of course, why they do everything they can do discourage it. Because if you do that, not only are you not reliant on them for availability, you can switch more of your business to the other provider(s) based on current pricing, and they do not want that big time.
If you make the engineering decision to go multicloud for whatever reason those are inherent trade offs you need to be aware of. They have their own agenda of course in addition to any actual fundamental "real" in bulk efficiencies that price reflects.
Until relatively recently absolutely none, and now almost none of the tooling allows effective multi-cloud or hybrid cloud/private.
Basically the cloud providers work very hard to prevent the commodification of their services with special incompatible service offerings, lock-in, interdependency, deep and opaque APIs for integration, and networks of training and certification that position change as a direct threat to people's job security.
Cloud providers today are basically Microsoft in the 90s.
Much as open source challenged Microsoft, I would say that the world now needs open infrastructure tooling that positions hybrid and multi-cloud as first class infrastructure architectural cases in order to displace established cloud provider hegemony. Even then we will have to fight the hardware and real estate economies of scale available to large established cloud providers.
I wrote some observations about this space based significantly on HN community comments prior to the rise of Docker a few years ago: http://stani.sh/walter/pfcts/ ... click 'original' ... the conclusions still seem timely.
Until relatively recently, the cloud didn't exist.
Depends:
> IBM and other mainframe providers conducted this kind of business in the following two decades [after 1961], often referred to as time-sharing, offering computing power and database storage to banks and other large organizations from their worldwide data centers. To facilitate this business model, mainframe operating systems evolved to include process control facilities, security, and user metering.
[…]
> In 1998, HP set up the Utility Computing Division in Mountain View, CA, assigning former Bell Labs computer scientists to begin work on a computing power plant, incorporating multiple utilities to form a software stack. Services such as "IP billing-on-tap" were marketed. HP introduced the Utility Data Center in 2001. Sun announced the Sun Cloud service to consumers in 2000.
[…]
> In spring 2006 3tera announced its AppLogic service and later that summer Amazon launched Amazon EC2 (Elastic Compute Cloud).
I went ahead and bought calls ahead of NET earnings next month. Cloudflare is becoming an increasingly bigger part of the internet backbone. Purely speculating here, but I wouldn't put it past AWS or another large player acquiring them soon.
I really hope it doesn't come to this sadly. I'd be okay with DO or somebody who isn't as massive doing a merger. Maybe they can pull resources to make each other even successful and maintaining reasonable independence.
Careful about this methodology. Some services at my org were impacted despite not being direct CloudFlare customers. They had external dependencies that used CloudFlare.
e.g. NPM.js uses CloudFlare DNS, so services which needed to talk to NPM.js weren't able to do so.
Internet™ by Amazon.
I really hope it doesn't come to this. I assume such a move would create a vacuum for a competitor. Not everyone wants to be completely owned by AWS.
Made me chuckle, as it gave me the image of a large server in some massive server farm glowing red, then bursting in a massive burst of light as dozens of bearded Sysadmins run out of the building screaming.
It's absolutely true that if us-east-1 in AWS has a bad day, a significant fraction of the American digital economy will shut down. For some companies, the same is true of Azure and Google's various comparable offerings.
I read your post as skeptical. Why would you be skeptical? If you care about keeping your product up, you absolutely should have a fallback for cloudflare if you're a customer of theirs. Now, you might not care (and actually, for most folks I submit you need not care), but the folks making sure Ambulances get timely push notifications and realtime driving instructions probably care quite a bit.
A steel chain made of links has as many SPOF as links.
The Physalia paper is a wonderful read that explains both the justification and high-level approach to implementing said isolation [1].
Another great example is shuffle sharding [2], notably used in Route53.
The end goal of this is that aws outages would be isolated to subsets of aws customers where possible. So instead of half the internet failing it's only 10% (obviously the exact numbers depend heavily on implementation).
[1] https://assets.amazon.science/c4/11/de2606884b63bf4d95190a3c... [2] https://aws.amazon.com/builders-library/workload-isolation-u...
My sincere thanks to John and all the PortableApps.com contributors.
First of all "I use easyDNS so I didn't notice it at all tbh" is not only a childish assertion, it's borderline a falsehood. You DO NOT offer the same services, nor the same scale. (No, VOD would not work if your VOD provider used Cloudflare's offering.)
Second of all, as some have noted in other comments, you are very welcome to get just as big as them if you can offer similar (excellent) service and similar extremely competitive pricing. Otherwise, keep working on your offer and stop going for low hanging fruit like bashing the competitor for an outage when they literally might handle 1000x your traffic, and perhaps offer 20x the services your offer.
Just a little rant ...
This is obviously subjective, but to me it didn't come across as "they suck use us" but rather pointing out the inherent flaws in this quite popular SPOF and cautioning to avoid it.
otoh it’s just marketing, and CF is no stranger to it, so i think it’s fair.
For whatever reason there's this modern idea that if a company A is paying money to company B for a service, that company B will handle all the 'hard stuff' for them.
The end result is we have a lot of applications/infra built with SPOFs, in some cases known, but in many, swept under the rug and abstracted away to passing the buck in case of a large failure (i.e. major AWS/Cloudflare/Azure outages).
You also see this at times when vendors pitch internal software solutions. I've been at more than one shop where a vendor's 'silver bullet' turned into a SPOF time-bomb because nobody considered this company's solution could fail. After all, the sales presentation said it had %nines%!
1. no one's going to blame me if my app goes down when half the Internet is also down but they are going to blame me if my custom solution to the same thing causes an outage,
2. there's no way my custom solution is going to achieve the same uptime. AWS/Cloudflare/Azure are not perfect, but whatever I roll for myself is almost certainly going to be much less perfect.
The thing that they're bashing is not the mistake, which happens to everyone. They're bashing SPOF:
> EasyDNS was unaffected because while we do use Cloudflare to soak up large DDoS attacks against our nameservers, we don’t use them across all of our nameservers. I think somewhere in my book I wrote “DNS providers have a near-pathological aversion to SPOFs” (Single Point of Failures). Maybe only we do.
You indicate they said " "I use easyDNS so I didn't notice it at all tbh" but NO WHERE IN THAT ARTICLE was that statement
The actual quote is
"We’re familiar with Cloudflare’s DDoS service for DNS providers, because we use it ourselves. Fortunately easyDNS was not impacted by the outage (I didn’t even notice it, tbh),"
This is a MUCH different statement than you attempt to cast out as call "childish". He is stating that the services they use of CloudFlare was not impacted by the outage
Guy at work... coffee cup on a tablet he's using for a coaster... except he's also drinking whiskey from a beautiful crystal glass... there's a folded paper airplane... there's just so much to unpack here, it's pretty hilarious.
And he has left the stopper off of the decanter like some sort of animal.
I think we are supposed to believe that the person here was just dicking around online, fiddling with paper, finishing his morning coffee, when all of a sudden he gets an email asking if anyone knows what's going on with the website.
So he stops what he was (not) doing, puts down his coffee, and starts poking around. At which point he realizes he needs something stronger than coffee. As he is pouring his glass he is confronted with the true horror of the situation, drops the stopper on the floor and just holds his face wondering why the Universe hates him.
I wonder if we can get JJ Abrams to option the movie rights.
Wait, why? [0]:
> Proactive Nameservers is a patent-pending system that optimizes the nameserver delegation for your mission critical domain names.
Oh.
Compared to the endless content marketing Cloudflare posts [1]? It's an ad, but they're still right. That's just good content marketing (informative, relevant, and perhaps you buy something because of it).
It won't just be one single website that goes shitty with blockages and manipulation and censorship. It won't even be just the web. When Cloudflare achieves their goal of deep packet inspection at every peering and transit point it'll be the end of the internet as we knew it and the slow transition to just another cut apart "China-net (tm)".
Let's also not forget Cloudflare in particular have been accused to host/hide the very bad boys that make protection from DDOS necessary in the first place. Whether or not that is the case, a quasi-monopoly leaves customers with no choice.
[1]: https://petri.com/microsoft-google-and-others-invest-in-clou...
But a lot of small torrent websites and such simply won't load without JS and specifically CF code. It's pretty crazy. Luckily I don't use any of those bEcAuSe IlLeGaL but still, I find it really depressing, especially when webtorrent, IPFS etc are available, and frankly many of those pages will never have to bear a load that makes CF a requirement.
It's worth noting Cloudflare also supports secondary DNS, but only for enterprise customers: https://blog.cloudflare.com/secondary-dns-a-faster-more-resi...
They were a PITA to work with when I used them in the past but if they are really that good in service availability, you can have some justification for their overpriced service.
What’s really puzzling is if the same companies spend money on active/passive failover for application and database servers while overlooking DNS single point of failure.
"Well, what do you want it to be?"
Give me a number and I'll tell you how much it will cost and how long it will take to get there.
Here's my work around:
1) open developer tools 2) refresh page 3) move tab into a new window 4) find a blocked resource in the network tab of developer tools and open it in a new tab 5) verify humanity 6) repeat step 4 and sometimes 5 for each resource the page requires 7) move the problematic site out of the new window and close all of these tabs at once
It is a terrible experience. CF devs and publishers have no idea how inconvenient their service is. I wonder if they have ever lived in a region where every ISP is both incompetent and listed in the CBL?
I frequently skip sites that use CF. The captchas are obnoxious.
The entire concept of a webapp firewall seems a bit backwards to me. Developers should fix their insecure applications.
Yes: as the weblog post points out, you can have EasyDNS as your master with their multiple DNS servers, and then also have (e.g.) Route53 slaved to EasyDNS and have those in addition to EasyDNS in your records.
DNS servers have had replication for decades.
I don't see the centralization as a positive, but I'm wondering what percentage of the websites that were taken offline see themselves as having no choice but to use Cloudflare in order to prevent themselves from being taken down anyway from malicious actors instead of by accident.
It seems unlikely because my phone can access sites on wifi fine, and again my Mac doesn't appear to have any malware.
Could it be that the outage is somehow relate to Cloudflare putting these captchas up as a precautionary measure?
Another good DNS option is dnsimple.com or, indeed, EasyDNS. For even more redundancy, use one provider as your domain registrar and another for your nameservers (and set short TTLs for your zones so you can re-point IPs quickly if you need to).
For the other things Cloudflare offers on their free tier, I'm not sure what good alternatives exist (there must be some, I'm just not familiar with them outside of the obvious AWS alternatives).
Edit: one caveat with above advice, I have no idea if netlify use cloudflare behind the scenes...
Edit 2: For other options, checkout https://www.cdnperf.com/ and https://www.dnsperf.com/
Full disclosure, I work at Google on the SRE team for Cloud CDN. If you want a credible alternative for the CDN part of Cloudflare, our product is extremely fast. We were all very sad for Cloudflare and watched the whole affair closely, as we've got a few customers that use our services alongside Cloudflare's.
Copy editors are cheap and your reputation shouldn't be.
I would applaud them, but I wonder.
My Unbound resolver round-robins DNS-over-TLS requests, between Cloudflare & Quad9. Cloudflare's outage never impacted us that I could tell.
Nevertheless, I am reminded that I ought to add a couple of DoT providers (who aren't Google). Not sure who else came online since I setup.
Rather than admitting that your customers need to maintain a business relationship with your competitors, you need to admit you need to maintain a business relationship with your competitors. That we need a moral equivalent of underwriting in the cloud space.
You can add another system in parallel as the vendor of the product suggests, or you can improve the resilience in the redundant system.
To make a hyperbole: my galera cluster is failing, its a single point of failure, so I setup a cockroach cluster in parallel.
In a way, it is right, as there are failure modes specific to the individual systems, but I think, it is incorrect, to label that a SpoF.
I am not a cloudflare customer but my all websites failed that day. The reason was digitalocean uses cloudflare, I use digitalocean. So apparently I depend on cloudflare.
The other one is called AWS.
It's a learning process for all involved, really.
From the affected parties point of view, well, they should diversify their network a bit better. End users should hold those companies feet to the fire, not Cloudflare's.
Maybe, but making mistakes is far from negligence. Besides which, if a single person can accidentally break your system, at least at Cloudflare's scale, that's an organizational failure, not a personal failure.