Cloudflare Is Having Issues
cloudflarestatus.com
cloudflarestatus.com
Note: experienced it from the first row, cloud had an issue in a region with SSL...
Effectively unless they're down for more than a day, you're better off taking the hit and waiting for them to resolve everything.
lol. There's me worrying about a 2 minute downtime once every 10 years
I'm taking the piss too. Care to explain?
PS For a laugh (and I apologize for going dreadfully off topic), I asked ChatGPT a couple of questions regarding two mins and 10 years, just in case I'd missed a trick with your comment. I got two calculations within both answers that looked the same but have a factor of 10 difference in the result!
https://chat.openai.com/share/7aaa80e5-1c54-4ac2-9ddb-9e488d...
This is where it goes wrong:
"Total minutes in 10 years = 60 minutes/hour * 24 hours/day * 365 days/year * 10 years = 525,600 minutes"
"Total time in 10 years = 60 minutes/hour * 24 hours/day * 365 days/year * 10 years = 5,256,000 minutes"
LO Calc says that =6024365*10 = 5,256,000.
The worrying thing for me is that an awful lot of input training data might be badly wrong to cause this result or perhaps I've managed to excise a corner case in which case the training data is a bit too focussed in this particular regard. I suspect that arithmetic errors for these things will be awful because there are so many ways to screw up and the training data will have a lot of errors in it. Combine that with the number of subjects available and it will be a shit show.
As for GPT, it's not about the training data having errors in it - GPT doesn't parrot the training data exactly, there's randomness built into it (otherwise you'd always get the exact same output to the same input). It just generates a random plausible response, it doesn't actually know math.
To highlight this, I've just asked it the exact same thing you did, exact same words, and got an entirely different response (and this time it was correct): https://i.28hours.org/20230613-051307-0ae6.png
If DNS is up, you can change specific records to point to your origin or another provider instead of the proxy/CDN, provided that it can handle the load and doesn't need a setup similar to Cloudflare (i.e. repointing your nameserver).
?
But that doesn't mean Cloudflare is built in a centralised way (I assume it isn't), nor that there's something about the internet that is centralised around Cloudflare. Rather, people are choosing to include it as a dependency in their stack.
Here with Cloudflare, a single entity is responsible for the fix and will more or less fix the failure for every sites that uses it at the same time, by fixing it on their side. And website individually cannot do anything on their own.
So I would argue it makes sense to call that centralized, at least from a structural/operational perspective.
It is at the very least a form of contraction of the network.
> It is at the very least a form of contraction of the network.
I think it's that at most. No one has to use them, as they accelerate / enhance open protocols. That is the least lock-in one could hope for, so they don't contract anything in a negative way.
Contrast with, say, Etsy/Shopify, who actively try to replace the open space with closed ones.
If all those websites are using Flask, that would be the equivalent of centralising on Flask. The opposite of that would be many Flask-compatible yet unrelated other frameworks being used in parallel. A bug in Flask would not affect those not using that very codebase.
The centralisation people are speaking of here is the amount of people all putting their eggs in Cloudflare's basket.
I agree on the equivalence between this and Cloudflare use, but not that this should be described as centralisation, which is a particularly potent word on the open web. Popularity isn't the same as centralisation. Each website could rewrite to remove Flask if they wanted.
Another example: if lots of people watch Squid Game, that doesn't indicate a centralisation of television programmes. No options are removed. People are just choosing to do a similar thing, but not in a way that centralises anything.
Is a monoculture centralized? It doesn't have to be, and yet it can all fail due to a single fault.
If Cloudflare goes down, so does a significant portion of the web. Flask cannot have an outage like Cloudflare. All they can do is push a faulty update, but even then you can rollback or stay on the old version.
This is what was on the tip of my tongue. I'd argue you're missing the portion of control in this whole discussion, and how much process you can place in front of a component change.
If I have a flask dependency, I have a lot of control over this dependency. If flask screws up badly, I have many options: I can update. I can not update. I can downgrade. In fact, I could fork flask internally and fix it on my own and either be a good citizen and open up a PR, or I could be something else. I can test all of this in any number of environments before it hits a customer, and even more stages before it hits all customers.
With Cloudflare - or any number of Hosters as well, like AWS, Azure, Google Cloud, I have very little control. If I use Cloudflare as a CDN and Cloudflare goes down, I might not have the capacities at my upstream server to handle the load from all my customers, so I am down as long as Cloudflare is down. I wouldn't have the footprint available necessary to replace AWS in our own private DCs, even if we pooled all spare capacities - and then I'd still have to find a way to exfil our data from a downed AWS. (Which, yes, we have, but it'll take long hours)
And no matter how much I test, if my hoster fucks up, I'm immediately fucked as well, no matter what processes I might have. The only process around this would be provider independence, which is really expensive and a lot of effort even if you just have a luke-warm standby.
And you can do these things in parallel, unlike the Flask example, which you pretty much have to commit to using solely.
Remember when crypto promised a decentralized utopia of distributed systems that any interference wouldnt work, but slowly but surely it all congregated into a couple of oligarchical companies?
Surely by now the technology of the internet has matured enough that these conglomerates are going to do the same but with a bit less fraud involved.
Stop putting every-bloody-thing behind Cloudflare, and the problem solves itself. I don't know whether to laugh or cry when I read of someone on HN seriously saying that they need a CDN for their personal website, or that they really need to use AWS or GCP for that matter. We tech workers have lost the plot, and it's our fault it's all in the hands of the few.
BGP was standardized in 1989 and has been in use since 1994. The technology of the internet has matured in many ways, and remains almost identical in many others. Sometimes Microsoft is right, and backwards compatibility is the killer feature.
Cryptocurrencies promised many things but only wanted to replace oligarchical companies with oligarchical miners.
But if they fetch a lot of URLs from cloudflare and it takes 30 seconds to answer with a timeout instead of a http/200 under 20ms, then some architectural decisions that were sound under the latter case may make the whole system slow in the former one.
In other words, I wonder if going to fail fast would help the health of the Internet more than wait forever timeouts. Might reduce DDoS effects, too.
But it's very complicated and costly to setup, so almost nobody does this.
If you send all the same traffic, and probably more because of retries with shorter and shorter timeouts, chances are you are going to keep the system overloaded, never detect success and never return to default timeouts. Dropping most of the traffic, and then turning it back on when the system recovers can lead to oscillation where the system works enough to drive more traffic that overloads the system etc, but at least you're getting some processing done.
But if you are consuming a lot of API content, if you have crawlers or if you provide features like "get article title/summary/image/thumbs", at some scale it's an important decision to make.
I guess that comes with the type of end point in that network. A typical website, absolutely, yes, I'd agree. An API end point allowing requests of large data pools that might take a few seconds to generate but yet not a total time out would be acceptable.
If I were an SRE at Reddit, the day I got wind of the "we're making all subreddits private" thing, I'd double check that code-path to see what we were in for on Day 0. However, I am not.
Looking at Meta/Google/Apple's layoff packages of 6 months of severance, and factoring in $170k-$389k annual income at Reddit (per levels.fyi), I would hope they have enough savings to live off of for months if not years, to enable thtem to protest, should they so desire.
And the twentysomething kids on $200k on the west coast won’t be saving that money (if the number of Teslas on the road in Redmond is anything to go by): they have no reason to believe they won’t make the same kind of TC at the next job they apply for.
It’s not quite an alternative. It’s good though and I’d recommend joining once there’s another invite wave.
It's screaming along at 47KBsec.
I'll have it all in about two and a half hours.
Not sure if that is related.
And how do you know how many websites use R2 etc. so that you can jump to the conclusion that it’s not huge news?
Pedantically, it's true as soon as "count(issues) > 1"
Reductio ad absurdum can be used to demonstrate the logic flaw. Let's assume that one person using Dynamo DB got a 500 error response from a two successive API calls (so an error rate of ~4.0e-09). It would technically be true for the headline to say only "AWS is having issues." A headline like that is going to rocket to the top of HN, and it's not going to provide many people with useful information.
It's also silly. There's plenty of room in the headline to instead of "Cloudflare is having issues" to say "Cloudflare R2, Stream Live, and others are having issues."
It'd be even better if there were competition in this space, but there aren't too many options outside of cloud providers who are likely relying on the fact you might accidentally slip up one day so they can charge your credit card.
Again: you do not need Cloudflare for your small-business website.
Do you have any idea of how many requests can a shitty unoptimised website serve on commodity hardware? Judging by comments like yours, which seem to be the majority, I wonder if anyone with less that 15 years of experience is still able to write a website serving 10k users a day (1 request every 8 seconds) on a 2 core VPS without needing a CDN.
Let me spoil the black magic only greybeard seem to know: STOP. OVERENGINEERING. You don't need Cloudflare. No one cares about DDosing your website, you're not Reddit for Heaven's sake.
If you overengineer, at least quit all rushing to give your custom to the same company, making Cloudflare a de facto monopoly.
If you happen to have a popular CMS like WordPress on a cheap VM, odds are you are going to get DDoS all the time, even if you only have 100 legit views/day. Cloudflare will reduce this dramatically.
I would guess any site not using Cloudflare (or someone similar) is more likely overengineering. As always though, every case is unique & it depends.
First, setting up anything using some third party service like Cloudflare is already too much work and doesn't even work for many people in parts of the world Cloudflare has determined are undesirable.
Second, I can, have and do host popular CMSes on hardware much more modest than Raspberry Pi performance.
Third, "odds are you are going to get DDoS all the time"? Are you a Cloudflare shill? This is nothing but wildly hyperbolic. In a quarter of a century of hosting, I've had to deal with one specific DDoS actor. One.
How are you going to claim that "odds are you are going to get DDoS all the time"? Go ahead, provide evidence, although I'm sure you can't and won't.
People put up fake WordPress logins as honey pots. I'm not sure what to say to this. If you host a WordPress site you're going to get lots of traffic trying to take your website down unless your provider is helping you block it. If you go outside on a summer day, the sun is going to be shining. I have never had a WordPress site that didn't get a ton of bad traffic. If it lived on a cheap VM with a MySQL database, PHP & WordPress, it was going to be under stress at least a few times a year. Tossing Cloudflare on it takes less than 10 minutes & a few years ago was the 1 of the easiest/cheapest ways to get SSL on it. In my quarter of a century of hosting, I have had a lot of DDoS attacks & none of those sites got over 100k legit users a month. Most also didn't care about users outside their own country.
It doesn't matter to me if you use Cloudflare or someone else. I don't make money off it but I will admit it is one of my favorite providers by far. I do also really like how the executive team is personal, handles themselves online & reaches out to devs.
I have no idea how people putting up Wordpress honeypots is related to this discussion, but for everything else, you're advocating treating symptoms and ignoring the problem.
If you, or anyone else, want to run a Wordpress site and you expect a firewall or DDoS service to protect you from stupidity, it might work for a time, but it's not the best idea. If you don't rename your wp-login.php, that's on you. If you install 27 plugins that you don't really need then ignore the fact that they'll need constant updates, that's on you. But those are common sense things - again, the root issue should be addressed, so the symptoms never happen.
Also, if bots banging on your wp-login.php and/or "ton of bad traffic" are what you consider a DDoS, perhaps you really should consider basic site security. We call "a ton of bad traffic" normal.
I'd much rather a site that has fundamentally fewer problems than a poorly configured one that's "protected" by Cloudflare.
Oh - and what does "most also didn't care about users outside their own country" have to do with it? You're advocating FOR the idea of stratifying the Internet? Then I guess you really are a fan of what Cloudflare is doing!
Wordpress should integrate one of those "Wordpress to static site" plugins as the default because that's all 80% of the users need.
Folks pointing out that their Raspberry Pi self-hosted static site résumé can handle 500 requests per second are missing the point.
The Wordpress approach of dynamically composing every page server-side made sense:
* Before AJAX made personalizing the 'logged-in experience' easy even on a mainly static site
* When CPUs were so slow that regenerating, say, 1000 static HTML files just because you updated your footer or your "top stories" sidebar would take an annoying amount of time instead of what, 4 seconds now?
* Before spambots essentially made it impossible to host a comments section, and Disqus and the Facebook plugin became the defacto choice for anyone still brave enough to try.
Due to the above, I can't imagine using PHP or even some sexier-today technology to dynamically just-in-time assemble HTML pages that 99-100% of the audience will be viewing statically.
Please tell this to every junior/cloud developer/architect when it comes to microservices.
Flash forward about 8 years and I find myself using cloudflare to stave off the immense suffering of Azure/AWS by using R2 and Pages. As soon as more people find out how easy Cloudflare is and how much it can lube a product deployment, I expect a lot more of the internet to end up there by choice.
Cloudflare deployed my app better/easier than Microsoft was able to deploy it to Azure (Microsoft owns GitHub and Azure and still didn't have their shit ironed out...Cloudflare just works).
I had to tweak them both but Azure took hours and cloudflare was a quick, cleanly documented change.
I wish they offered a service to host my nodejs APIs.
I haven't read into why Open AI uses Cloudflare instead of Azure services but I find it very interesting considering their Microsoft arrangement.
- They want to save on bandwidth costs
- They have to deal with some level of DDOS or site scrapers hitting every page at once
- They want to block IPs, geographies, ASNs, etc. without editing a server config
- They want speed & server-sided visitor analytics, email routing, security settings, redirect configuration, and DNS all in one dashboard
- They want their vendor to arbitrarily deny access to customers and prospects
Maybe they have a 100% success rate at blocking actual threats but they sure do have a lot of false positives. I get blocked or forced into captchas at least three times per week.
I used to report it to the site admins, but among the few that responded, almost none knew how to fix it. I no longer bother, so I suspect that the less clueless admins have no idea how many visitors Cloudflare has driven away.
It's an acceptable cost, versus other ways of dealing with abusive traffic.
Hell, we (sysadmins, back when that was a term people used) used to just blackhole all the IP blocks associated with certain countries—made the logs so very much quieter, and this was back when the whole Internet was a lot quieter to begin with. At least CloudFlare's less blunt than that.
Failing to block abusive traffic can be really expensive. Detecting it is always going to cause false positives. Admins are OK with those as long as they don't cost more than implementing a system with fewer false positives would. A half-percent tax on revenue (to pick a number out of a hat) in the form of lost customers is a reasonable trade-off for a lot of companies. You've got to have pretty serious scale before it's worth investing real money to try to shave that down by a couple tenths of a percent (you'll never get it to zero, and only places like Amazon have the kind of scale that make it worth attempting to closely approach zero)
I have to assume jgrahamc was one of the flaggers, given their indignant comment at the top of this thread.
Could you send me an email with details you have available, (rayID, IP address + website, or HAR file) at amartinetti at cloudflare.com?
Edit: even if you just mean whitelisting their proxy ip... that doesn't do much good either. It's like asking to whitelist tor - those IPs are blocked because a good amount of spam or malicious traffic originates from them, not because there are x0,000 users on each.
> That's why it's not just browser, it's browsing habits based on your IP and location in addition to fingerprinting where appropriate
Mini is a barely configurable hosted browser with one IP, one location, and one fingerprint. It doesn't return anywhere near full HTML/JS/CSS, but highly cut-down code generated by Opera's server. Unless somebody has found a way to hack that server, I'm at a loss as to what damage it could cause.
This seems to me a case of sloppy use of overly broad security tools.
Maybe the right people are hearing, but they consider it a necessary evil of negligible impact (accurately or inaccurately). Or is stuck with Cloudflare, who says they'll take care of it. Or maybe the message is getting lost before it gets to someone who cares.
Same.
I get blocked on websites I have accounts on if I use a VPN. I'm not just a visitor, I'm a member, and still get blocked by cloudflare. Other times it's a small or local business and to me the website just looks down. Then, if I bother to think about and willing to drop my VPN, suddenly the website works fine.
Treating VPN users as hostile is getting really fuckin old.
You can turn this behavior off as site owner.
They don’t.
There’s a new, working CF WAF bypass published almost every day in the bug bounty hunter circles.
20 years ago I was beta testing a browser nobody's heard of and happened upon a mainstream PC accessories seller like pcconnection.com or the original cdw.com with a poorly designed site: malformed cookies, important information hidden inside nonstandard tooltips, etc. Don't recall their name, but they had domains for the US and Canada. I emailed them at least twice to point this out, but they blew me off. I was amused when they went out of business a few years later.
When you criticise Cloudflare, the common response is that the site owner has chosen to block this or that. I don't believe for a moment that Cloudflare offers a checkbox for "Spin the busy animation forever, never loading the site and never generating an error". This is what happens when a company dubs itself the Internet Police while not knowing what the f*ck they're doing. In the words of the Joshua AI from Wargames
"The only winning move is not to play."
I suggest that it's impossible to do what Cloudflare is attempting without false positives, but they haven't figured that out yet. And when you complain in their public forum, do they apologize and send up the flares? No, you're met with arrogance:
https://community.cloudflare.com/t/browser-integrity-check-b...
I wasn't caught in this particular dragnet, but had the same thing happen to me this past winter with the Iceraven browser. I did complain to one of the affected sites, who weren't particularly helpful, and the issue disappeared on its own about 2 months later. Maybe somebody did start a public thread with Cloudflare, but knowing the likely response, I held off restarting that fight.
I use the Opera Mini browser sometimes (not recommended), which apparently has its worldwide server/endpoint in the Netherlands. There used to be a US endpoint but no longer. If you're using Cloudflare to block European traffic for one reason or another, okay, I get it. If you're using Cloudflare to block "unusual traffic" like VPN endpoints (no idea how it actually works), it would take them two minutes to do a reverse lookup on the IP and see
109.211.145.82.in-addr.arpa. 13531 IN PTR h18-05-12.opera-mini.net
and simply whitelist the IP globally. But they haven't...while a little voice nags at me, reminding me this is supposed to be their day job.
On some level I'm okay with the status quo and letting my first paragraph scenario play out: smart businesses grow while idiots go bankrupt. With Chrome, Safari, and Edge controlling roughly 90% of the browser market, though, I'm not holding my breath. The rest of me considers this behavior anti-competitive and a growing civil rights issue. Imagine needing a toll road or ferry service to get somewhere but the owner tells you they don't like your car and please get another one. The average person would exclaim, "What? There's nothing wrong with my car!!" Ditto for whatever browser I choose. If it supports TLS 1.3 but doesn't like the web site's HTML/JavaScript/CSS, then maybe I'll consider switching...or maybe I won't. But that should be my choice, not theirs, and definitely not the choice of a middleman with delusions of grandeur. Web sites designed for use by the public need to be accessible by the public.
Easy SSL. Register domain at cost. Throw up static site on S3 equivalent (or app on whichever cloud), add Cloudflare and a couple redirects (no www to www, no ssl to ssl), done. It’s like gmail for simple web hosting. It’s also like early Google, friendly and useful and not trying to squeeze every dollar for shareholders and bonuses.
They lend us their very competent team at free or minimal cost. I totally get the single point of failure and monopoly but compared to AWS, Azure and Google complexity it’s a simple web app dream until I have time to care about certs etc.
Competitors need to build an easy alternative and get as good as the CF team. Which is way better than me at futzing with config I only touch once every couple years.
Sadly, that is the norm with everything since Shodan made it trivially easy to find out targets for websites. Once your hostname or IP ends up there, you will get blasted with exploits a couple minutes after a 0-day was published.
It’s much more efficient to just do “zmap | ./exp” than it is to query shodan, get a limited amount of targets, etc.
For the most part, the bandwidth doesn't matter, the sites are made for bots.
You can also manage all of your internet infrastructure (domains, dns, etc) under a single dashboard that doesn't suck. Pry it from my cold dead fingers.
Their product is excellent, and so easy to use. You push a button, and suddenly a whole class of difficult problems disappears.
It's very hard to fight against the urge to use it.
We can dismiss the problems all we want by saying "most people don't need it", but if they're using it, clearly they see a need and this has to be addressed not ignored. Which is why it's so hard to fight against the urge, so go ahead and use it if it saves you time and money. Until real alternatives exist, don't hinder yourself.
and a whole new class of problems appears
(my regular cloudflare outage is when they decide to add new "security" that the existing "disable security" page rules don't apply to, great for API consumers)
This corroborates something I read that I'm paraphrasing: If you want a successful business, solve a problem and sell it.
Between Cloudflare and LetsEncrypt I’ve never had to pay for an SSL certificate again.
Of courss, the easy to use interface was also welcome. Using their CDN for small scale or hobby projects is total overkill though.
It also seems to be something they've moved to flipping on by default.
Centralization is a problem if the Internet breaks without the "too big to fail" piece. I'd think as long as you can move your content and aim DNS at the new location, you can use those services without being enslaved to them.
sorry, just had a flashback...
Page load times are almost always dominated by the megabytes of images and javascript that everyone seems to include now.
It's a lot of work to detect bots, i use a bunch of tricks on a certain website that return an XML bomb ( to discourage bots)
Note: Google's Recaptcha wasn't sufficient
Then news came out that MasterCard was also having problems during the day.
And then Reddit, HackerNews (it was totally down for me, not just slow), and now Cloudflare!
PSA: if you browse HN in logged-out mode (e.g. a private tab), you can receive cached versions of HN threads that load much faster. The logged-in experience is currently worse than the logged-out: dynamic content generation for user-account stuff seems to be hitting a slow path on the server.
So, whatever market forces are going on for pilot labor in your little niche job are completely dominated by the airlines. Like you’d think banner towing jobs would be mostly affected by advertising trends, but they’re not. Passenger travel trends are way more important. (This is for the job market, not the business market)
Similarly, the flow from a way bigger site can overwhelm whatever you have going on.
Do we know if it is just like, one tall MySQL instance and a few RubyOnRails API instances? Not sure what would be used for "caching" as well.
> The load issues usually happen when a few popular threads have a really high comment count and dang usually has to enable pagination or other things to compensate.
Why not auto-turn it on at like 500 comments or so?
Two servers, one active and one standby. Both running Arc on BSD. No MySQL or Ruby.
Why not auto-turn it on at like 500 comments or so?
Best to ask dang directly on that one hn@ycombinator.com as I have never seen the code and responsible adults don't let me near their code.
(Besides, as Reddit is showing, do you want your discussion site run like a tech unicorn? Arguably things were better for users in the skeleton crew days)
I believe pagination does turn on automatically at 500 comments.
Also, new account creation in HN is broken at the moment.
...and I had to login just to say this...
It allows you to observe and query your state in dev and prod.
Take a look: https://durafetch.com
Azure CDN with Front Door
etc.
etc.
But more likely just kids with endless hacked IoT available to DDoS whatever they feel like.
Before IPv6 there were "internet weather" services, are they still around?