like I wonder if Hetzner has any way to legally force them to stop misclassifying their IP
like I wonder if Hetzner has any way to legally force them to stop misclassifying their IP
My favorite is trying to go someone's random blog with like 5 posts (because they have a singular post about the technical topic I'm trying to figure something out about) and I can't access the site because Cloudflare has decided my locked-down Firefox ("resist fingerprinting" + strict privacy mode etc.) running on OpenBSD is somehow malicious. So much for the open web. (nevermind the audacity that "we can't spy on you sufficiently" is enough to serve a 403 Forbidden response header)
Maybe if people knew about alternatives, they would use CF less. I wouldn't use them at all (and don't; I switch when my hoster cannot handle the attack which happened once only).
https://www.techradar.com/news/best-ddos-protection
https://www.gartner.com/reviews/market/ddos-mitigation-solut...
https://expertinsights.com/insights/top-distributed-denial-o...
No idea about the content of those links, but considering the amount of research I do before selecting a colo provider, it'd be trivial in comparison to research a DDoS protection service.
So basically the choice is cloudflare if you are not cashed up enough. So nothing to do with lazy; there are no other viable options for most if it's a large attack.
It's like doing research for colo, like my example. If you have the need, then a couple of hours of research is well worthwhile. I don't have the need, so I'm not going to do it now, but that's how one starts.
The colo example is apt - colo providers that don't have pricing are invariably too expensive, so I skip them, but there are plenty of others to check out that aren't Cloudflare. The one article I skimmed even says whether the providers are pricy or affordable.
Nobody needs Cloudflare. If (most) people were aware of how much Cloudflare breaks visibility across the world, they'd likely avoid Cloudflare, too.
That was like ten years ago though. What are some good alternatives?
We did try, casually at first over the years, then intensely as a focused effort over several weeks, to little effect. We tried blocklists, fail2ban, firewall rules, heuristics, CDNs, other non-Cloudflare services, etc. It cost us dozens of hours of labor and thousands of dollars of other service provider fees, but the spam didn't abate much. It was causing excessive server load, many credit card authorization attempts (they didn't go through, thankfully), sometimes fake PO orders, screwing up our analytics, etc.
Then out of desperation, we found Cloudflare. It took maybe half an hour to set up, cost $20/mo at the time, and overnight all our spam problems stopped. For a small business, it was a godsend, freeing up our devs to work on actual features instead of fighting bots all the time, and saving us thousands of dollars in hosting fees.
> By filtering, you've become unreachable by much of the world, spammers or not.
But... that's the whole point! We weren't some huge enterprise SaaS trying to advertise to the whole world, just a small US-only business. We had no business in China, Russia, India, etc., where most of the spam was from. We tried in vain to block that traffic on purpose, but couldn't easily do it until Cloudflare.
Then Cloudflare let us flip a toggle... and it all magically worked. Our staff was much happier, our actual customers never noticed (they were all US/Canada based, or rarely Europe), nobody ever complained, and we saved thousands of dollars a year.
It's not just about DDoS (which we did get on occasion, and our host did help us with) but the consistent drive-by bot scraping, pen testing, port scanning, etc.
Cloudflare sometimes gets a lot of hate here, but for small website operators, they are a HUGE lifesaver. I've never actually heard a complaint from a real customer about this, but even if we hypothetically lost a handful, the time and money saved not dealing with spammers is worth it to many businesses.
The internet has long since stopped being the open wonderland where everyone is nice and contributes positively. The overwhelming majority of it is worthless bot traffic, and you could make an entire career out of trying to prevent it... or just give Cloudflare a few dollars and a few minutes. Sorry, I don't see them as evil, just... practical? Useful?