Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw? Do they just to a tremendous job of migrating sites from free to paid plans?
Did they have some crazy in to get cheap bandwidth? Did they bet big on bandwidth prices falling? Did they figure something else out that nobody saw? Do they just to a tremendous job of migrating sites from free to paid plans?
https://www.sec.gov/Archives/edgar/data/1477333/000119312519...
I was worried a bit when I saw the initial IPO that the free tier would leave (despite promises it wouldn't) but that doesn't seem to be the case. Literally the only bad thing I've seen on the site is recently you switched from recaptcha to a new one that I had a real tough time with logging in today - it was a bit glitchy on my pc. The only suggestion I thought of as well would be a simple "maintenance mode" similar to the "I'm under attack mode" which would allow those of us without super-ha to quickly toggle on something to pop up a "sorry server"/site is down form maintenance page without having to mess with our proxies/web servers.
Anyway I know this comes across as totally kissing-ass but I just wanted to say thanks to someone who actually works there. Everyone fat fingers stuff every now and again,don't sweat it.
I really liked the stories of his skill when he was in his prime. Very inspiring.
I'm not sure what to take from this. But thank you for sharing it
I wonder if there are any relationship between FTD and how clever a person or how much brain a person uses.
Robert Sapolsky - Phineas Gage and frontal damage https://www.youtube.com/watch?v=5wKDXzk8Wm4
In all, it was a captivating read.
To be sure (and for the sake of internet rando completenessism), it does look like CF waited until the original SGI patent on the technique ran out. :)
As ever, innovation was brick-walled until IP got out of the way.
That's right. See https://news.ycombinator.com/item?id=23860658
Right now: there is an issue with Safari users on the most recent iOS and OS X, where 3rd party cookies have now been disabled by default. We're working on a solution.
If that's your issue, you can fix on your side in the short-term by not using Safari, or by enabling 3rd party cookies.
(posted in case others are hit by this) using `requestStorageAccess()` on a user click event seems to work and that's what we're rolling out :/ https://gist.github.com/iansltx/18caf551baaa60b79206
I mean CDNs that will let you override the origin's cache instructions and do a decent job of DDOS protection, and whose feature list otherwise looks a little like Cloudflare's.
There are smaller CDNs out there. You can find them readily enough.
Which suggests to me that CDNs are already a commodity in some ways.
A second answer - there are a bunch of bottom-barrel commoditized pipe services. You likely haven't heard of them because they're so generic. They've existed before Cloudflare, and more will be created in the future https://www.citrix.com/products/citrix-intelligent-traffic-m...
Respectfully, the info in the S1 (flywheels, etc.) seem to be what sustains you _now_.
Maybe a better question is "how did you identify and kick off that flywheel?"
Market Opportunity
We believe our platform disrupts several large and well-established IT markets. The key markets that are addressed by our platform include VPN, internal and external firewalls, web security (including web application firewalls and content filtering), distributed denial of service (DDoS) prevention, intrusion detection and prevention, application delivery controls, content delivery networks, domain name systems, advanced threat prevention (ATP), and wide area network (WAN) technology. From our analysis based on IDC data, $31.6 billion was spent on those products in 2018, which is expected to grow to $47.1 billion in 2022, representing a compound annual growth rate of 10.5%. We also are actively developing new products to address adjacent markets including compute, storage, 5G, and Internet of Things (IoT) that are not included in the estimate of our addressable market.
I may not have a full scope of the history, but my own experience with DDoS protection was quite different. Whilst providers offered anti ddos protection through GRE tunnels and dedicated machines behind DDoS appliances and a heavy null route hand, Cloudflare had a simple few-click solution that worked at the web application level making things a lot easier and, also, allowing for features like caching, and thus, CDN benefit from a global network. Further, they've maximized performance on their machines, and as a result, Cloudflare is wicked fast.
Cloudflare does what it does really well and has built additional services on their global network that make a lot of a sense and provide a lot of value.
Hats off to CF.
If AWS was able to offer a single click "DDOS protection and CDN" feature with similar pricing and features as Cloudflare then I'd consider it since most of our infrastructure is on AWS but at the moment they don't offer anything nearly as competitive. Just the Cloudfront bandwidth costs alone would dwarf our total infrastructure costs.
My reservation with Cloudflare is the concept of letting a third party MitM my SSL traffic. That and it's more expensive than a cheapo CDN like Stackpath if all you really care about is CDN (and Cloudflare isn't even really a good CDN, just a quick hack to speed up small static files).
Perhaps I have overlooked something?
So in this way it's possible to setup CDN with shared SSL for purely static files but not the app server itself; you don't have to give the keys to the whole kingdom so to speak and it's cheaper than Cloudflare at the basic level.
I was under the impression that the same result could be achieved with Cloudflare, or indeed nearly any CDN. Was I mistaken? Though you may not actually need a secret, private subdomain for static files with all CDNs.
Again, please let me know if I've made a mistake somewhere. I'd love to learn something this morning.
static.domain.com (CDN subdomain with auto provisioned TLS)
static-uncached.domain.com (private pass-through subdomain when CDN is missing a file)
www.domain.com (app server hosted wherever)
You're right that you could do something similar with other CDNs including Cloudflare (you can just set the www subdomain to "bypass Cloudflare" to accomplish a similar result), but I'm not aware of any way to use Cloudflare on a domain without forwarding your nameservers to them, effectively giving them complete control over the domain. At least with Stackpath I can host DNS wherever and simply point the subdomains I want at them.
Also, by the time you do the work to split static files into separate subdomains you might as well go with a dedicated CDN. One of the selling points of Cloudflare is for sites serving everything on one subdomain that they can forward to Cloudflare and get caching without any work.
It requires at least the Business level plan, though.
Not even "exceptionally difficult", but flat-out impossible. From the perspective of an observer, TLS sessions are random data. The protocol is specifically designed to defeat attempts to replay data -- a CDN is indistinguishable from an attacker in that sense.
I wonder what the Venn diagram of people who insist every website must use HTTPS for privacy reasons and Cloudflare users looks like.
When a 3rd party has access to your keys, their responsibilities to you are spelled out in your contract with them. That's true for CDNs as well as hosting companies.
For most websites today if someone can intercept traffic somewhere close to the server they don't even need the keys, they can just fake responses to pass CA validation and issue valid certificates with their own keys and MITM like there is no encryption.
And coldboot attacks performed by a hosting provider staff of dumping memory and finding keys isn't that realistic of a threat, just like putting servers into a locked cage on someone else's property isn't much of a protection.
If you press F12 in your browser and navigate to some major sites, you'll notice anywhere between 1-5 different CDN domain names that aren't directly related to the original host in any way.
Suffice to say, that in over 5-6 projects I have added CF to, it's never worked out in my favour.
A million URLs isn't big?
That said bandwidth really isn't that expensive, at least if you're buying it at the scale that Cloudflare does. Many people seem to be used to the bandwidth prices of the large cloud hosters, which are really insane and have been marked up by a large multiplier to disincentivize people to transfer their data elsewhere for processing.
Bandwidth isn't expensive compared to what most people are paying for it. Cloudflare is paying for the infrastructure as it is to handle attacks, so why not use it? As long as it doesn't affect paying customers then it's great marketing.