CloudFlare: A website security product accidentally makes sites 60% faster
thenextweb.com
thenextweb.com
Their value proposition is completely absurd ("protect websites from hacking"), yet they're still around and get quite a bit of seemingly expensive PR-spin like this article.
Who pays for the "accidental CDN" that, according to the article, pushes as much traffic as the 10th largest website on the internet? Their optional $20/mo subscription plan can't possibly cover that.
The company is only sitting on around $2 mm in funding (if memory serves me) so it's either making a decent sum of money from people who find value in that accidental CDN or it's going to fizzle out quickly due to lack of funds.
The thing that you have to keep in mind is that (likely) the vast majority of its customers aren't on the same level of technological prowess that you have. CloudFlare is aimed at people who run sites and just want them to be easier to run while working better and being safer. There's a lot of money to be had from a service that can fulfill that request.
Oh, and as for the expensive PR-spin, this is the first time I've heard from CloudFlare in 8 months, even after specifically asking them to get in touch with me. If I'm not mistaken, the company has done very little PR. They've gotten attention in a way that many people seem to have forgotten -- by having a good product.
Like many others, I hadn't heard of CloudFlare until it started showing up all over Twitter (and the Internet in general) in relation to LulzSec.
I'm glad you guys got some nice exposure, and I might start using your service myself soon!
"Some of the biggest sites on CloudFlare do well over 10M page views per day."
Given the current plans are FREE and $20/mo, it would see that there is not a limit at this point.
I also inquired regarding the Enterprise services and was told it is strictly a matter of additional features being made available, not related to traffic or usage.
They use VigLink to add affiliate tags to the external links of the sites that use them.
For Amazon at least, intercepting and tagging URLs is in violation of the Associates agreement, and if detected Amazon will not pay these fraudulent commission claims.
If the URLs are being tagged with the Associates account of the web page owner, then this auto-tagging is a CMS feature, which is reasonable.
If the URLs being tagged are content created by NOT the website owners (like, say, forum posts), then we might be back in fraud territory.
This is actually an optional service (Outbound Links) that can be turned on or off (opt-in by default). No affiliate links are added without turning the feature on.
Some mangled affiliate links cover the cost for 10th largest traffic site nowadays?
Referring someone through an Amazon link doesn't just credit you if they purchase that product you linked to - it credits you for any purchases they make during the cookied period. And for the whole amount of the checkout.
A couple months ago I made over $150 with that same amount of traffic because someone bought a MacBook Air (~$50 in commission), some fancy espresso maker (~$20) and a bunch of other things. Amazon has mastered the art of the upsell.
We're not going anywhere:)
For the HN crowd, understanding what pieces are in play would help a great deal. I figure it's probably a nice cache + CDN service?
I'll admit that I don't get your security claims -- it seems like entirely the wrong layer to deal with security issues.
It would be awesome if this explanation was on there under "technical details" or something.
They are freemium because they need to collect as much traffic data as possible to learn to identify threats. Same reasoning as Akismet spam filtering started out with. They also have enterprise level plans, which probably drive more revenue.
Plus, they are only 7 months old. Kinda early to be hatin', no?
Then there's a CDN / caching aspect. If you don't want to bother configuring your own cache servers they'll handle it for you. It sounds like they even try to figure out what's static content even if you don't set your cache headers properly, which is slightly risky but probably ok for a lot of configurations.
And they'll do something similar to SPDY for you ("Rocket Loader" https://www.cloudflare.com/press/2011-May-25-cloudflare-rock...)
I'd at least consider setting it up for my personal website/blog.
Oh, don't forget that they can also probably make a good amount of money selling aggregate data and statistics (like Mint).
For example, I just picked this mouseover that interested me:
The threat challenge page stops known threats and alerts infected humans that they need to take action.
Is there anything that elaborates on that? From a security perspective, I'm drawing a blank as to what a reverse proxy filter is achieving there. You're rewriting html destined for ddos zombies?
What other characteristics can you detect? Can't really look at IP address, since ISPs such as AOL use the same IP address for the same user. Can't look at headers or referral strings since those can easily be faked. Also search engines such as Google have been known to use non-Google IP's to check if a site is cloaking or not. And you say you analyze the reputation of an IP - IP addresses for users change all the time. And many scrapers do use data farms/cloud services such as AWS, but a lot are moving to European data servers as well, and these IP addresses are harder to get reputation for (they're not in ARIN, etc).
If anyone is interested in the very limited data, it is at http://isitupordown.appspot.com/v/urbad with "ActualServer" being the VPS itself, and CDNCache being CloudFlare.
Not sure how this stands against a DDoS.
One of the side benefits was their one click "apps" where you can install Google Analytics, etc and manage it from one place.
I did have one question that I didn't see a clear answer for. If I am using Amazon's Cloudfront for many of my images, how does the Pro account handle the caching of these seemingly conflicting services?
Since configuring with cloudflare on May 26th, I've had 26,133 page views, 368 from crawlers and 755 from bots.
Without cloudflare my average page load time is 2.66 seconds. With cloudflare my time is 1.55 (my google pagespeed score is 97/100: http://bit.ly/k3MDGk)
Out of 125,183 total requests, 72,405 have been saved by cloudflare.
10GB of bandwidth has been served since that time and 4.9 has been saved.
Cloudflare makes my site 41% faster as well.
I was getting hit with a lot of exploit attacks, mainly from China, so I was glad to see I could block by IP, IP Range and Country in their Threat control Panel. I'm aware that's not a foolproof method but it helps.
link to my site: http://www.alphavr.com/tours/properties/virtual/240
But I'm going to hook up my nearlyfreespeech.net sites up and see how things go.
Here's the ones I've found so far:
http://news.ycombinator.com/user?id=lionheart
http://news.ycombinator.com/user?id=lionhearted
http://news.ycombinator.com/user?id=theli0nheart
http://news.ycombinator.com/user?id=ligerhearted
Any others hiding in the woodworks that wanna show themselves?
That's not an anti-spam product, that's hosting.
Don't get me wrong, I love the idea of your product from the very beginning, but don't say that you do things when you don't.
Example: 1. Registrar could be GoDaddy. 2. Hosting is at BlueHost.
Adding CloudFlare would mean: 1. Change authoritative nameservers at GoDaddy to us. 2. Hosting doesn't change at BlueHost.