Frickin' Awesome: CloudFlare Automatically Learns How to Stop DDoS Attacks
blog.cloudflare.com
blog.cloudflare.com
I visited half the site trying to figure it out.
Also, this line really put me off:
> We have designed the system to scale with our goal in mind: helping power and protect the entire Internet.
I don't think anyone wants one entity having the ability to re-route a significant proportion of http traffic!
I undertand that you'd never ever say the words 'caching reverse proxy' to normal people, but if someone on HN asks 'what is this doing' you can probably feel safe to use the technical terms.
Good ad copy, if you're aiming at geeks and only geeks, doesn't spare the jargon.
I hadn't thought of this before reading this thread, but a great service would be something like Varnish that's backed by some CDN instead of a big block of memory. That way, we can get great performance out of sites that are low on memory and bandwidth, like your low-end Linode or Slicehost.
In addition, based on their size, they effectively are a CDN!
That is a very scary off-the-cuff assumption to make.
It is my job every day to "worry" about how PAAS providers might not be able to deliver services to my business.
We're now in contact with Cloudflare to see how we might progress, but understand that a random posting that says "don't worry" without any substantial background makes me worry.
I asked them how on earth they could provide a service like that at such a low cost, and why there were no bandwidth limits in any of the plans (bandwidth isn't free).
Their answer was that they couldn't tell me the answers to my questions as it would reveal business secrets or something to that effect.
At the rate of start-ups spooling up and shutting down these days, I wouldn't bet my site's DNS on a company that appears to have no sustainable business model, and is deliberately withholding information that I'd use to judge if they'll be around in 6 months time.
The anti-ddos functionality is indeed pretty cool. I guess the reliable detection of "anomaly" vs. "spike in traffic" is the secret sauce - but if not, would be entertaining to know more about that.
Also, they pass along a country header which comes in handy if you need to know which country a user is in without having to set up GeoIP and keep it up to date.
Oh plus they sent me a t-shirt.
It's worth it to switch to CloudFlare just for their DNS control panel; it's better than any I've ever used.
I wonder what the reasons are why my business is excluded from participating from initial sign-up? We are a highly trafficked site, so on the surface it seems to me someone might be talking to me shortly on the "up-sell" side of things. Agh..
Just a quick suggestion.... you might indicate that to the requestor instead of the generic "contact us" response. You could easily drive away someone who might want to POC your service but then ultimately decides to move on to the next task. And that someone could be a big guy.
Thanks again!
"One of our user's site was under a denial of service (ddos) attack earlier this week"
I like the distributed website caching for static pages. Would be interesting to have pay for what was served model . . .
But I guess these make sense only for static content...
What's the risk it misclassifies real surges in interest as illegitimate traffic?
Coming soon: Singapore, Dallas, Miami, Paris, Frankfurt, and London.