- Company has great initial product
- Company gets popular
- Shareholders demand infinite growth
- Company becomes rent-seeker
- GOTO 10
I'm with OP - a company that wants to insert itself in the middle of everybody's business is not being altruistic, they're playing the long game.It means "hi spending approver, I'm going to add $100 to our CF account" instead of "hi accounting+management+security, please initiate the process of evaluating new third party vendor Foo for use in my project, I hope we can get it approved and integrated into SSO sometime next month".
1. Due to AI, most of the software is going to be personal apps.
2. For personal apps, (even most commercial SaaS) SQLite is all you need.
3. The Javascript ecosystem is huge in terms of components, libraries. ShadCN and what not.
4. Cloudflare has workers, durable objects which is isolated SQLite, D1 which is isolated SQLite
5. You can run crons, long running jobs, cloudlflare has emails.
6. Cloudlflare has best in class open weigh AI models as API for cheap.
7. Cloudflare has amazing CLI wrnagler but upcoming cf is purpose built for agentic workflows.
8. The built in AI assistant is really really good in guiding you how to setup, architecture and work around limitations etc.
Combine all the above, in next 5 years Cloureflare is going to get stronger with more workloads deployed to it then all three hyper clouds combined.
Instead I put my API keys to cloudflare, set limits, and gave the agent the CloudFlare token, and in minutes it could contact tens of services.
edit: not to mention instead of loading balance to each service I could just keep balance on cloudflare that covers them all
Extremely hard to verify it's been done properly across a large organization.
Put it this way: I'd rather Cloudflare owns the Internet than Google, Meta, Amazon or Alibaba.
Cloudflare is however known to deliberately screw over some of their clients.
> I'd rather Cloudflare owns the Internet
I'd rather no one does, certainly not a firm that feeds into the NSA.
[0] https://blog.cloudflare.com/why-we-terminated-daily-stormer/
https://news.ycombinator.com/item?id=44150898 (2025)
https://news.ycombinator.com/item?id=40481808 (2024)
https://robindev.substack.com/p/cloudflare-took-down-our-web...
Reddit comments report more such incidents, with Cloudflare demanding an upgrade to Enterprise. This has also come up for other sites, such as gambling sites.
Also, Cloudflare implicitly screws over everyone by leaking data to the NSA.
I have always operated under the assumption that every cloud provider and telco does this, so this claim has always seemed very silly to me.
That said, these are US companies subject to FISA court orders and NSLs or National Security Letters. If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. Any idea that your data is protected because you're not even using a provider WAF or doing TLS termination for load balancing is a fantasy.
I control which DNS server I use. It is not relevant to the matter at hand.
> If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to.
You're confusing bulk data collection with highly selective court-ordered data collection. The two are not alike. Attempting to equate them is a dumb attempt at deception on your part. There is no obligation for a firm to share bulk web data with the NSA.
Which is easily sniffable, re-routable, and spoofable unless using DoH/DoT. Those lookups are plaintext. Keep in mind I'm talking about your cloud endpoint.
> It is not relevant to the matter at hand.
Metadata is relevant enough for the US government to drone strike, and relevant enough to issue a collection warrant if one were... desired.
> You're confusing bulk data collection with selective court-ordered data collection.
This is both bafflingly naive and dangerously arrogant.
Just one example, look up FISA Section 702. It does not require a traditional warrant to intercept data. To further this avenue for you, look up the 2024 congressional expansion of Section 702 (via RISAA). This was explicitly done to allow a much broader scope of classification and forced compliance with US intelligence, with extremely limited oversight, and a far reach (they were getting audit fatigue from submitting 702 requests, so why not just do the search and collection and have the courts deal with it later if it's a Real Problem(tm)). This collection doesn't just apply to the datacenter providers, landlords, etc now, it also applies to hardware vendors.
What am I preaching, exactly? I think you misunderstand.
All I'm saying is that if you want security, you will not have it if using another person's hardware. It's that simple.
And who even said we're talking about American ISPs and American clouds? I'm sure the NSA can get data from OVH, but not as easily.
Yes that's precisely how I want infrastructure to operate.
> Our terms of service reserve the right for us to terminate users of our network at our sole discretion. The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology.
> Our team has been thorough and have had thoughtful discussions for years about what the right policy was on censoring. Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network. We could not remain neutral after these claims of secret support by Cloudflare.
https://blog.cloudflare.com/why-we-terminated-daily-stormer/
Per Matthew Prince:
"This was my decision. Our terms of service reserve the right for us to terminate users of our network at our sole discretion. My rationale for making this decision was simple: the people behind the Daily Stormer are assholes and I’d had enough.
Let me be clear: this was an arbitrary decision. It was different than what I’d talked talked with our senior team about yesterday. I woke up this morning in a bad mood and decided to kick them off the Internet. I called our legal team and told them what we were going to do. I called our Trust & Safety team and had them stop the service. It was a decision I could make because I’m the CEO of a major Internet infrastructure company."
This is one of the best, most honest things I've seen a tech CEO write. Contrast this with Zuckerberg's mealy-mouthed weaseling about "policies"[1]. I wish more tech overlords had the honesty to say, "No, we are not a court. We are booting you because we don't like you."
[0] https://gizmodo.com/cloudflare-ceo-on-terminating-service-to...
[1] https://www.newsweek.com/read-mark-zuckerbergs-full-statemen...
The government always wins this given enough time.
Given the number of people on HN who report massive problems from scrapers and other bots, it sounds like if Cloudflare doesn't do this, someone else will need to. I might have thought bandwidth was cheap enough now for it not to matter, but I guess the bots are costing some sites a lot of money.
As for the bots, I thought the same thing, but it is indeed a huge problem. They've brought my websites down pretty frequently recently. I tried Cloudflare but visitors complained, and I think you can't win against the bots anyway, so I've resorted to performance improvements and serving every request.
- let more traffic in, eat the compute cost
- block larger cohorts of traffic, affect many real users
- babysit the rules to get them just right, lose time doing that
In my experience the residential proxies exist but are not that common and many aren't trying as hard as they could. It's really a war of which side wants to spend more attention on the problem.
Why would I use bonsai? Why not use ElasticSearch directly?