Cloudflare had a partial outage
cloudflare.com
cloudflare.com
Should be back up everywhere.
Their phone line kept cutting us off and then the people there were not too helpful.
Alanis Morissette agrees that this is ironic.
don't you think?
It's bullshit all the way down.
Are there any companies left offering free DNS usable from Terraform that aren't part of the "Internet Five Eyes"?
edit: looks like Linode may be the next best 'not terrible' option
$ dig +short ns1.digitalocean.com aaaa
2400:cb00:2049:1::adf5:3a33
$ dig +short ns1.linode.com aaaa
2400:cb00:2049:1::a29f:1a63It's not infrastructure anymore, As there is a new PaaS startup every week offering distributed hosting and So why bundling in DNS, DDOS detection+mitigation, cloud workers... with it is so hard?
You can't build a Cloudflare competitor in AWS/Azure/Linode/DO/etc. You need your own data centers. Multiple of them across the country, ideally around the world if you want to serve the whole world.
This is insanely hard.
-
https://en.wikipedia.org/wiki/Economies_of_scale
As Cloudflare gets bigger, they can provide services more cheaply. This is because (a) they can more fully utilise their data centres and other physical capital investments, (b) they can divide their fixed software costs over more users and (c) they get process efficiencies and discounts with scale.
A new entrant will struggle to match cost unless they're able to obtain similar scale. The bigger Cloudflare gets, the bigger the scale that a new entrant needs to hit before they can match them on cost.
-
https://en.wikipedia.org/wiki/Network_effect
Second they're aiming to build a network effect through having huge number of locations. The more locations, the more appealing to new customers as they can be close to more users. A competitor will have to build a similar number of locations to match Cloudflare's proposition.
A new entrant cannot provide as much value, and therefore cannot charge as high a price, without building a similar sized network. This again requires the entrant to invest heavily before they can charge a similar price.
-
The combination of these two things mean that when Cloudflare is operating at a large scale with a large network it can offer a more valuable service (and charge a higher price) than a new entrant, and earn more profit because it can operate at a lower cost.
Also, Cloudflare has the option of lowering its price and still being profitable due to lower costs at its scale, so it can deter entrants from trying to compete by the threat of being able to lower prices below what is profitable for new entrants.
The only players who can compete may be those who already have comparable size - Amazon, Google, Microsoft, Facebook, CDNs, etc, since they will already have addressed the issues of scale and network effects. However, they may not want to cannibalise their existing markets. It will be hard for other new entrants to compete.
Others at best offer a limited trial plan, But most are just 'Speak to expert/ Contact us' for pricing which means haggling with a sales rep while we can just build things. Even the paid plans of CF is reasonable when compared with others with better features.
It's common to see CF being the DNS/CDN for applications across AWS, GCP, Azure etc. So perhaps CF being down affects more applications than individual cloud platforms?
And I'm saying this for the last time: no one type google into google!
The Cloudflare Dashboard is also no longer fully loading.
Sites are gradually reappearing as I type this. Some of my sites, and doordash.com, were returning 500 errors again just a minute ago. They just came back up, followed by the CF dashboard loading again.
They are not being honest with themselves here
They aren't saying they guarantee 100% uptime. They're saying they'll pay you for any downtime. It's literally the 3rd paragraph:
> 1.2 Penalties. If the Service fails to meet the above service level, the Customer will receive a credit equal to the result of the Service Credit calculation in Section 6 of this SLA.
(Most people I know consider them meaningless marketing BS that's really just meant to trick people or satisfy some make-work checkbox)
> Cloudflare ("Company") commits to provide a level of service for Business Customers demonstrating: [...] 100% Uptime. The Service will serve Customer Content 100% of the time without qualification.
This is a legal commitment to provide 100% uptime. They are guaranteeing 100% uptime and defining penalties for failing to meet that guarantee. The fact that a penalty is defined does not stop it from being a guarantee.
"Service Credits are Customer’s sole and exclusive remedy for any violation of this SLA."
I don't think you know what a guarantee is.
For example when you buy a new car you get a guarantee that it won't break down. Are they claiming it won't break down? No, of course not. What a guarantee means is that they'll fix it or compensate you if it does.
Also, SRE here but not for Cloudflare -- I've never seen SREs directly involved in externally published SLAs, they usually come from legal. We deal with SLOs on more fine grained SLIs than overall uptime
I made it to SLA (which I believe stands for service level agreement). What do the other abbreviations stand for?
SLO - Service Level Objective - the service level you strive for. If it's higher you have room for experimentation, etc.
SLI - Service Level Indicator - the actual metric(s) you use to measure a service level (latency, error rate, throughput, etc.)
SLO - service level objective, the stated availability (or latency or durability etc) of the service. Usually expressed as a value over a period of time (e.g 99.9% availability as measured over a moving 30 average). The SLO is measured by the SLI.
SLI - service level indicator. Simply, the direct measurement of the service (i.e metrics)
SRE - Site Reliability Engineer, usually a member of a team who is responsible for the continued availability of the service and the poor sap who gets paged when it breaches SLO or has an outage or other impactful event.
SLI: Service level indicator (Metric to measure the health of a service. For example successful requests per interval / total requests per interval.)
SLO: Service level objective (what performance you expect eg. the previously mentioned SLI is >= 99.5%)
SLA: Servicelevel agreement (legal agreement that defines what happens if a SLO is not met)
Entry[1] dated "Jun 21, 2022 - 06:43 UTC" has been edited to include more detail after they posted another entry at 06:57 UTC. There seems to be no indication that the message has been altered.
Currently text on the status page may suggest that they identified the problem immediately but it took about 15 minutes. Previously there was a text stating that customers should expect update within 15 minutes. Next message was posted 14 minutes after that but previous message was altered later and nothing indicates this.
Cloudflare, not cool.
he can also add an [edited] on that entry, among other things
Found it, https://news.ycombinator.com/item?id=31801947
edit: Not that I necessarily agree with the article even in light of there being an outage, cloudflare has been pretty good for us. Just thought it was interesting.
Not only the US.
Care to clarify so I could take the mandatory contrarian approach?
So yeah, how is a CDN centralizing your infra? You could just have your CNAMEs point to a different provider or directly to your gateways. Or you could even go down the multi CDN path, and have someone like ns1 automatically redirect your CNAMEs to an alternate CDN on a per-geo basis to overcome local failures.
It's just another SaaS component in your system. You could self host if you're willing to take on the ownership challenge, and at certain scale it would even be more cost effective.
Technically you could set up a separate DNS/failover somewhere else and use a backup reverse proxy/TLS terminator/CDN SaaS similar to CloudFlare, but then that somewhere else will be your point of failure.
But if you look at his math, it was correct. The era of client-server connected heterogeneous distributed Internet is just a side show today.
The solution has been centralization (clarification: big companies run their own caches and networks near users). and growth of caches and then Cloudflare taking care of the rest.
Centralization and growth of caches are on their face contradictory.
Perhaps you mean organizational centralization but that really has nothing to do with internet capacity demands. Your hot take isn’t so brilliant. What’s fundamentally wrong with edge distribution?
Yes. This is exactly what I mean. Big companies run their own caches and networks near users. Cloudflare takes care of the rest.
>What’s fundamentally wrong with edge distribution?
You incorrectly assume judgement from my part. My point is that things have changed. New problems arise in solution to old problems. Fragility from small number of organizations running their caches to solve bandwidth problem.
This is also important for countries with limited connectivity to the Internet, if the PoP in that country looses it's connection back to CF it shuts everything down, so even if the origin is in the next rack over from the PoP, it's un-reachable.
If you’re serious, you could probably automate this right now with your DNS provider and uptime monitoring.
There's a huge difference in changing nameservers for a domain and simply changing host records.
If you want CDN-independent automatic failover, look into anycast with two providers. If one of them is Cloudflare, use the tier that lets you manage your DNS elsewhere.
As I said to the OP elsewhere, he should be doing something like anycast to multiple CDNs if this is critical.
DDoS attacks are extremely common at just about any scale, even if you only have a few thousand users.
Cloudflare going down like this? Actually first time I remember it happening. There’s been downtime before but nothing so major.
It's trivial to scan the whole IPv4 internet to find out which IP you are hosting your site on.
On top of that, depending on your scale, can you take all the traffic on origin that Cloudflare currently offloads?
This is not really an extra or a nice-to-have, it might be more a hostage situation.
My company was paying $20 a month. We were heavily depended on CF, we'd have been happy to pay more.
But... the one feature we wanted was for our accounts team to have their own login so the ops team didn't have to download invoices every month. Nope, that one feature required an enterprise plan which they quoted $4,000 a month for.
Also in these days of remote work, it's a problem if the credit card details need updating - either you have to give the company card details over a slack call, or you need to give a card holder your root password.
I tried to exercise some restraint this time, but screw it. Here's another rant:
Beware of Cloudflare's tactic of luring people in to their CDN product with "free" bandwidth, and then locking useful features arbitrarily behind what I can only imagine is a thousands of dollars per month enterprise plan. Just look at their cache-purging page for a super obvious example of this (there are plenty more, way too many to list), everything other than basic purge by URL is enterprise only: https://developers.cloudflare.com/cache/how-to/purge-cache/
These days Cloudflare is literally my last choice for a CDN for my new projects. My new go-to is bunny.net, who charges a reasonable usage-based fee for bandwidth and gives you unfettered access to all the features they've built (and doesn't route your users to farther/closer nodes based on how much you pay: https://cloudflare-test.judge.sh/). Though I'd even reach for Cloudfront with their expensive bandwidth costs these days, because at least their pricing is transparent and scales smoothly with usage, and they don't arbitrarily cut you off from useful features that you might not know you need yet.
Even their bandwidth might not really be "free", since I've heard if you actually use any significant amount, the sales people will come knocking on your door to coerce you to get on the same enterprise plan or have your site taken down.
This would be best implemented by you. If the point is to avoid CF as a PoF, why would you rely on their infra to fail safe when something breaks?
1. I could see my site down, including cloudflare.com with nginx 500 errors, via Sydney AU
2. Logged in to dashboard (via Melbourne AU) that worked; and so was thinking it was an issue with Sydney Cloudflare My experience with Cloudflare has been in the past sometimes servers in some regions have issues and its a transient thing.
3. Status page showed no problems, so I went to "Contact support" and went around in circles (really frustrating) via the "Contact support" link moving me between Community forums, Support ticket, etc. I then see Chat is an option is available with a Business plan, so I upgrade to that, hoping for some real-time support to alert of the Sydney issue.
4. Return to the "Contact support" page after upgrading the plan, but the Chat option still not present on the support screen (and help articles say to return to support page and click "Chat" but it never shows up).
5. Come across https://community.cloudflare.com/t/cloudflare-for-teams-chat... searching for why I can't see Chat as an option on the support forum saying they're on paid plans with no chat support and its not showing up, so I just give up assuming its broken
6. Open HackerNews and see its at the top. A few moments later the status page reflects the outage.
I still can't see the Chat option so I've down-graded the plan again.
For example, they seems to have what I assume is a separated DB for CF users and CF support users, but with one shared login system. But if you end up updating your email on CF, it's not reflected on their support system and all your tickets are gonna be refused because of the email mismatch, completely disregarding the fact that you just logged in via your CF account. And no way to update it from the support part of course.
Like what exactly?
My Internet goes down at least twice a year and my electricity goes down even more, specially in the winter. So no, this is not more reliable than cloudflare.
Note that your home network could be good enough for a personal web site that nobody pays you to respect a SLA on.
Unless you have fallback with multi cloud deployments.
You seem to imply that the options are only cloudflare or your apartment. This simply isn't true: there are a plethora of companies that will lease you a dedicated box of some Us in one of their racks, as the sibling commenter replies. Alternatively, you can search for co-location services. Options range from 1U/2U co-location, to half rack units, to full racks, to dedicated areas of the datacentre ranging from cages to whole rooms (I've been in at least one datacentre where an entire room was under separate access control and leased to one customer only).
Usually datacentres are located quite strategically. For example the location of many datacentres in Zürich corresponds with two separate power supply grids that meet (so they can pull from both).
Some of the companies involved are resellers and don't actually operate the datacentres they use. Others actually do. Usually the service is more or less the same, from the point of view of renting a 1U, or co-locating one.
If you want reliability features of a datacentre, e.g. for your office services, but might move, you may find your local city surprising. In Manchester, UK, there's a large amount of dark fibre under the city (fibre that is laid, but not in use), owned by some of the DC companies. Sometimes you can connect your office to said datacentre via dedicated fibre.
Given the price and performance difference between bare-metal and everything else, I am puzzled as to why small businesses that do not need scalability do not go with bare metal. And given the speeds of todays hardware, if you are not doing something stupid and you have a B2B SaaS, it's really difficult to need "scalability" beyond several bare-metal servers.
To be clear, I do not consider my bare-metal boxes "reliable", I have a multi-server setup managed by ansible, with a distributed database, and I can take a single-node failure without problems. I also have a staging setup that can be converted to production quickly, and a terraform setup that can quickly spin up a Digital Ocean cluster if needed.
Linode is down because Cloudflare is down.
Can't login to their control panel, etc.
You'd need to go fully independent and roll your own, with zero dependencies, to really make this work.
For *most* web facing apps/sites, a site hosted on e.g. Linode like this, but not using Cloudflare, would be unaffected by such an outage.
Whilst the incident is happening you'll see the Cloudflare 522 page.
I'm assuming 98.84% uptime is a joke? Less than 4+ days of downtime is something I could manage from a home connection most years, if I had a static IP.
I do think there is some holistic overview of hosting stuff on the internet, where you could label each extra actor that can break things, mitigation strategies, and costs of such. Someone better than me would be able to place relative risk (and I think in that model laying out various provider uptimes/issues would be great!) and offer a smart way of dealing with the buy vs. build question on this.
I still have a fun memory of half of IBM Cloud's servers falling over, meaning that our production app was luckily still up but our staging server fell over. I could get to their website, but their login stuff was all messed up. I believe that one was also a "routing stuff got messed up" issue....
Not in my experience. Things break all the time, the difference is nobody notices because either the colocating ISP is too small or we are.
If you can live with dns round robin between the two, then you can easily host the DNS with multiple providers and avoid SPOF (could maybe host it on the two boxes you already have, too). You're still at risk of domain registry/registrar failures, and failures of their tld nameservers (very rare for well run tlds) and the root servers (not sure if they ever had a widespread failure). And of course, simultaneous failure of both locations isn't impossible, just less likely.
On Comcast DNS failures... Most of the recent ones I've heard of manifested as users on Comcast can't resolve X, but were really X had bad DNSSEC records and Comcast DNS refused to return records that weren't signed properly. It's easy to avoid that by not using DNSSEC.
In the general case of working despite bad ISP dns, you can't do much (anything?) for web browsers, but if you build apps, you can hard code fallback IPs for when DNS doesn't work... But you need to have IPs that stick around for the lifetime of your app downloads.
The internet is an interconnected web of dependencies. Unless you are Cloudflare/Akamai/Amazon/Google there is no self-hosted anymore.
You can host in your basement if you like but you're still dependent on your ISP.
Ironically this is exactly what increasingly centralisation weakens. The huge cloud providers have eroded "an interconnected web of dependencies" into few huge server farms servicing everyone else.
It's likely to be taken offline by yourself more often than not though.
(Also it doesn't help that uptime monitoring systems are usually stupid and love triggering on false positives)
Their status page is a joke, likely crippled to reduce legal liability, but at this point it's just an outright misrepresentation.
It's just Atlassian Statuspage, which is a manually-updated incident response system. Unlike AWS, Cloudflare actually makes an effort to update it fairly quickly, but it can still be slow-to-update when something is immediately wrong.
For their status page to be broken down into individual services and regions, I get the impression of some kind of automated monitoring.
The only service I saw get marked non-operational was their API, while their site and dashboard were not available at all yet marked as operational.
It's fairly standard practice these days for status pages to be manually updated. The difficulty with having them be automatically updated is that for it to be useful that system needs to have a greater reliability than the thing it's monitoring. The signal to noise ratio is otherwise a bit ridiculous.
It goes without saying that the monitoring system must be separate from what it's monitoring and must be more reliable. Compared to running a CDN for half of the internet, automated monitoring is table-stakes.
Edit: at least it showed there was a problem within <10 minutes, unlike other status pages that sometimes are green the entire time.
- Having issues connecting to GitHub (Could be they are using CF, or could be DNS issue - but I'm able to connect fine to Google services)
- Twitter loads, but all images fail to resolve
- https://www.cloudflarestatus.com/ loads very slowly, and no assets (CSS, images, etc) load
EDIT from CF :: The issue has been identified and a fix is being implemented. Posted Jun 21, 2022 - 06:57 UTC
Very interesting outage.
cloudflare.com was returning Connection Refused, then error 522 cloudflarestatus.com was returning Connection Refused, now can't even resolve the IP
My guess would be that a router misconfiguration is being progressively deployed throughout their infrastructure.
EDIT: Continues to look like a cascading failure across their network. 1.1.1.1 is now unreachable for me.
I say this because: (1) it eventually loaded for me after I tried a few times and gave it time to load, and (2) its certificate doesn't report to be from Cloudflare but other sites I've checked that are down do
Downdetector: ಠ_ಠ Well, this is awkward...
5XX Server Error Web server is returning an unknown error
There is an unknown connection issue between Cloudflare and the origin web server. As a result, the web page can not be displayed.
Ray ID: 71eac4764c149452
Your IP address: 2600:1700:22e6:2410:2271:5b09:2694:a035
Error reference number: 520
Cloudflare Location: San JoseEdit:- Found it from another user.,
Downdetector: ಠ_ಠ Well, this is awkward...
whereisscihub.now.sh (https://news.ycombinator.com/item?id=22409674)
https://github.com/aaronjanse/dns-over-wikipedia (https://news.ycombinator.com/item?id=22790425)
This feels like a bad config push.
In UK, good old bbc.co.uk still working fine...
Their core service (DNS and web proxying) should see an outage once every 10 years or less. Much like Google Search (which is a far more complex service).
Yet it seems we get an outage more frequently than once a year. In my opinion, that makes the service too unreliable to base my business off - it's not like I can failover to another provider while they're down.
I’ll start moving my sites away from Cloudflare soon. Not because it’s bad — in fact it has been amazing, but rather to decentralise.
Maybe, things are back faster than you could cover from any trivial issue.
All of my home's Ring cameras have been inaccessible this entire time. It's not that big of a deal for me because I planned for that eventuality, but a lot of people have not.
If you run a critical service (like Ring) and your infra is tied to CloudFlare - you're stuck! There is nothing at all you can do. That's freaking scary man. If I was working infra at Ring I'd much prefer to get paged and start fixing the problem. There are very few problems that can't be fixed in 15 minutes if you plan well for failover...
For anyone else needing their services, they are a perfectly reliable provider (most of the time). Would make sense to ensure a fail-over, though.
"But they're great", they cry, "why should I use anything else?"
*Including America's Cardroom, perhaps the biggest "offshore" US poker site. I can promise you that there are a lot of people who were playing in tournaments that are very unhappy right now. New York here.
Identified
The issue has been identified and a fix is being implemented.
Posted 5 minutes ago. Jun 21, 2022 - 06:57 UTC
Turns out no one will notice, as all of Shopify is down anyway ¯\_(ツ)_/¯
This means if your alerts are fired through them, you'll peacefully be sleeping through this incident unless your customers wake you up.
Subdomains aren't working though (e.g., https://sketch.nono.ma).
Update: It seems everything is resolving properly now.
EDIT: all flushed, Kickstarter works.
Users may experience errors or timeouts reaching Cloudflare’s network or services.
We will update this status page to clarify the scope of impact as we continue the investigation. The next update should be expected within 15 minutes."
Like I understand how websites can be served using a CDN and how a lot of the internet depends on that... but I don't see how gaming services like Valorant or cloud providers like AWS or chat room like Discord depend on Cloudflare.
Thanks!
But by now they offer lots of services, although I believe WAF and CDN are probably still the most important to many.
Question: how could be (temporary) DNS errors be made nicer?
My sites that are just using DNS are working fine, it's only those with the orange cloud, proxy turned on that are broken.
Prior to that, it was some time (in the "all my sites are wrecked" timescale) before the status page had any indication of an outage.
Then there was the CTO's (appreciated!) comment prior to the status page's second update with information suggesting this would be resolved soon (which IMO is the information everyone needs to report back to clients, bosses, etc).
That the status page was subsequently updated prior to OP's complaint isn't really relevant. It's still a point of discussion, whether someone comments immediately or later, right?
Once in a while web2 is going great with Cloudflare. Until when everyone uses it and it goes down.
But the Key/Value store that all cloudflare's configuration data lives on is giving 500 errors
Wow, for me it looked like the world had gone mad. This is a reminder to not only rely on 1.1.1.1 for DNS resolution in PiHole.
I host most of my services locally, but ironically could not connect to my own homelab. I use a dedicated domain with DynDNS and did not configure the network and DNS without reliance on external DNS. Surely it's infinitely more likely for me to make a mistake, right?
But we'll, can happen :)
Cloudflare.com now up, and websites are coming up, argo tunnels still down
You aren't the first to come up with the idea of a CDN traffic director (I built one), and you'll soon discover customers recognize you are just another single point of failure and not the solution. Best to focus on the things other companies in the space market on, bill optimization, latency optimization, etc.
Incident: https://status.gitlab.com/pages/incident/5b36dc6502d06804c08... with the latest update:
[Monitoring] Services seem to be back to normal, and we continue monitoring. Details in https://gitlab.com/gitlab-com/gl-infra/production/-/issues/7...
Edit: in belgium
And some work related systems.. but that's less important.
So I do think Cloudflare actually is a bit more decentralised than we give them credit for really.
Just the fact that they messaged here in the HN thread about what was happening, what they knew, and how they were gonna fix it. That's just _awesome_
Kudos to them. I can't wait to see their after report.
Wow, this dependency on cloudflare is wide.
How that SLA measures a 2 second outage for some customers is a separate thing, and sort of shows how meaningless these things can be on the internet (if you lose service for 10% of your potential customers is that an outage? How about 90%? How do you know how many were lost).
Their main site went down for about 20 hours a couple weeks ago because their hosting provider went down. They deployed an HTTPS only static site in its stead, so at first blush it looked like they deployed nothing. Great when you're trying to find contact information hosted on that site.
Their online banking site leveraged Cloudflare, so obviously they just rode that outage out with no notifications, etc.
What if for some reason a single /24 was unreachable from the site (say an errant route for 12.85.25.0/24 somehow got in the path). How would you even know that was a problem - how many customers are on that /24, how would I measure their failed attempts to connect?
I have a remote office in India on Tata. The other day it had access to much of the internet, but due to a fibre break in the Mederteranian it didn't have access to end points in Europe for a good 20 seconds.
However the other link on a different ISP remained working at that time.
Does that count as an outage? If I wasn't actively monitoring that link with a high resolution would I even know about it?
Insofar as proactively monitoring a single /24, you (probably) don't. I don't think it's (usually) a company's job to monitor their customer's ISPs. The failures that "my" credit union had were due to their own choice in infra (Armor, Cloudflare). When Sonic nuked my config on their DSLAM after some maintenance I raised an issue with Sonic not with whatever other companies became inaccessible as a result.
> Does that count as an outage?
My POV may very well differ from whatever contracts and SLAs you have in place, but yeah maybe. If you can't fail over to the alternative ISP then yes that's an outage. Of course a trans-atlantic fiber break would also likely be a lot more noticeable than fat fingering a route for a /24. And sure, I've been stuck at megacorp when the VPN started handing out addresses in a new subnet but our department's networking team hadn't caught up. That's why you listen to your customers instead of throwing out a "someone else screwed up there's nothing we can do" response.
Me personally I don't think that a 20 minute banking outage is a massive problem (I've long since moved my money elsewhere), even the 20 hour outage was relatively minor. It just speaks to the unwillingness of the credit union to be highly available. They knew of the Armor outage and didn't actually test the remediation. I assume they didn't know about the Cloudflare outage. Both worry me. What happens when they're faced with a total failure of their online banking system?
On my own network which I control I accept that if a circuit breaks I'll have a 1, maybe 2 second outage while traffic reroutes. For some of my services that's would be a problem, for others it's not. If facebook loads 2 seconds later, nobody cares. If the winning penalty in the world cup final blacks out, that's a big problem.
The OP says "not Cloudflare"; so probably Akamai, Fastly, CloudFront?
Sure, there are alternatives and not everything uses it, but if it's enough to greatly affect a large proportion of internet users, it's a problem.
Just like if google mail went away for ever. There are plenty of other email providers, right ?
Fun times.
We should really rethink that constant reliance on single point of failure.
Of course they offer a great product, that's how you create a monopoly.
CloudFlare should be run by the CIA or something - asthonishing MITM opportunities. The only clear sign the CIA is not deeply involved is that CloudFlare is far too competent.
I trust that the current leadership might not do something evil, but they are publicly traded. At some point a group of investors are going to figure out that merging Cloudflare with an advertising network would create a level of user targeting that Google and Facebook could never dream of.