All it will take is one major outage for everyone to see this is a bad idea.
Why trust a cloud provider who could go down and take half the Internet with it? Why centralize it that much where that is even possible?
All it will take is one major outage for everyone to see this is a bad idea.
Why trust a cloud provider who could go down and take half the Internet with it? Why centralize it that much where that is even possible?
Their position in the stack has a great deal of market relevance, which translates to risk if they realize that potential, because they could well end up being a critical part of more of the Internet than AWS is.
They are not mainly a CDN and aren't even particularly interested in competing with other companies that are mainly CDNs, which becomes crystal clear if you ever negotiate enterprise pricing with them. The CDN's just a means to an end.
Nb. despite all that their public-pricing plans are such excellent values (though, beware, last I checked the $200/m one was the only one with any kind of SLA whatsoever, and not an impressive one) that if I were creating a start-up CloudFlare might well be the very first service I signed up for. If you're a small fish it's damn hard to justify not using them. And the coils squeeze a bit tighter....
For many (most) use cases, CF will operate at a resilience and stability and professionality level far above what they can achieve themselves.
So the question seems to be does the internet going down at the same time outweigh the internet being down for larger periods in aggregate? I don't know, honestly - seems like a tossup.
Is there a better angle to view this from?
edit: My issues with centralization are more about privacy, incentives, points of authority/leaks/autonomy, etc. Downtime seems the least concerning to me.
Yes.
> If that's true for everyone, then the internet will, in aggregate, be down less with CF than if we distributed better.
That depends on what we define as “the internet”. If we use any single service as a point of measure, then “the internet” will have more downtime. But my desire to use the internet is very seldom to use one specific service. Instead, I want to accomplish a specific task, and if my usual service goes down, with any luck they will have a competitor which is still up. This is why I think this alternative is better; it will encourage competitors to exist, which will provide a level of redundancy above the simple network layer.
When something big like AWS goes down, it’s just understood by users that stuff is all broken everywhere. It’s not really an opportunity to get more users just because your thing is still up during this huge outage.
On top of that, if the alternative is less reliable than CF, any marginal gain in users during that outage (users that were only interested in your service because it was still up) will again be lost during subsequent outages for the exact same reason.
Obviously if you need uptime better than AWS, don't use AWS, or use AWS and someone else. The reason people are fine accepting this is because the impact of "50% of the internet goes down" is hilariously unimpactful - 99% of the internet is just not anything to care about.
It’s like with stocks. A single stock I own might go bust, but with a diversified portfolio, I won’t really care. But if ⅓ of all stocks go bust at the same time, that’s a market crash.
With a healthy dash of "What are people actually trying to accomplish?"
The weakness at hyperscale is that all products feel like some mistranslation of the generalized form of an HR request: almost for everyone, but perfect for no one. Probably because nothing less than a TAM of "everyone" moves their revenue needle.
It's actually kinda nice to have half the internet go down at once. People can just stop work, wait a few minutes, and it magically comes back up. Making downtime somebody else's problem is a huge advantage...
However, people continue to use cloudflare because it is easy, solves problems people don't like dealing with, and does the job. I don't know what the alternative pitch is to businesses so that cloudflare isn't so central to the internet.
The problem is that governments worldwide have done little to curb abusive behavior that makes this all but necessary to survive on the Internet:
- India (for US/UK based callcenter scams) and Turkey (for German based) don't do shit against scam callcenters. There have been multiple high-profile Youtubers making videos exposing these scammers and police there hasn't done anything, some have even boasted about having connections to bribed police officers protecting them.
- Russia, China, North Korea and Iran haven't been kicked off of the Internet despite both nations actively running hacking campaigns and sheltering hackers and "bullet proof" hosters.
- Western governments still don't mandate open source or at least audits for Internet-connected appliance software, which means that there are tons of devices (smart cameras, other smart home systems, routers, ...) out there that end up compromised, and on top of that residential Internet connection speeds routinely cross 100 MBit/s these days giving compromised appliances an awful lot of leverage for DDoS attacks (which is the chief use case for employing Cloudflare, AWS Cloudfront+WAF and others).
There simply is too much abuse in the system