CloudFlare acquires CryptoSeal (YC S11)
securitycurrent.com
securitycurrent.com
How exactly does Cloudflare afford to be a reverse proxy for millions of domains, at absolutely no charge? Are there some economies of scale I'm missing here? Obviously they make a good amount of revenue from their premium plans, but I suspect the vast, vast majority of all their users are on the free tier.
They're nearly an ISP at this point, so from a very naive outsider's perspective it sounds like they would be bleeding money from this approach.
You answered your own question.
They're nearly an ISP at this point
Not really, CloudFlare doesn't have any 'last mile' to pay for.
Even their higher tiers are pretty cheaply priced, including enterprise level: https://www.cloudflare.com/plans
People upgrade to get better service (including the missing features) not because of some artificial limit (like bandwidth). If you upgrade because you want to, not because you have to, you're likely a better customer.
It makes more sense to have flat pricing and to have feature that entice businesses to upgrade.
Also as far as I know once you get to something like 100Tb a month they will ask you or require you to upgrade. But thats still ridiculously high, the same would cost $12k on AWS.
*Edit: mixed higher and lower
higher surely? Lower response time == faster.
In my experience customers do a great job of self-segregating. If you offer "enterprise" as a tier, enterprises will generally pick it, even if the listed benefits are the same as another package. In exchange, they will expect enterprise services -- billing, guaranteed response, etc. No free lunch/get what you pay for.
The only corner case is when an important person at an enterprise customer has a personal account too, or when someone is really being a scrappy startup and trying to run something huge on a personal account due to not having the resources. Usually a good salesperson can handle both of those situations.
However, to my understanding, Cloudflare never requires that a site with a certain amount of traffic must upgrade to a certain tier. I believe there are many sites with lots of traffic volume that are still on their free tier. There are no bandwidth limits or charges at any tier.
But if a site gets a lot of traffic it's likely a business, and businesses have additional requirements. So, the paid plans become attractive (e.g. getting the WAF protection, or better DDoS protection, or mobile optimization, or SSL) and so people upgrade.
I'm guessing that there will be a handful of sites serving a LOT of data, and a LOT of sites serving very little data...
Another "secret" is CloudFlare doesn't do video (which is documented all over the product). Video is huge; every other kind of traffic combined is still pretty small compared to video.
http://www.theverge.com/2013/12/17/5217800/cloudflare-pledge...
This is a (mostly minor) security risk worth considering these days when not only are CAs semi-centralized but so are the certificates.
Another company doing the same is Google; they have a single certificate valid for all their properties (youtube, google.*, etc.), so that they can have a network in which SSL terminators are totally disjoint from the websites they proxy for.
As for the security, the certificates' private keys are fully handled by Cloudflare, and website owners don't get access to them. The security of a website sharing the same certificate of your website is immaterial for your security. You just need to worry that Cloudflare is not hacked, but that's part of the deal once you start using it anyway, it doesn't get specifically worse if you activate SSL.
I don't know if the TLS standard has some limit on the number of SAN, but there is a technical limit, because the certificate gets bigger and bigger (and thus connections slower and slower). Cloudflare probably has some per-certificate limit (e.g.: 100 domains) after which they simply begin creating a new certificate on a new IP.
I'm instead curious on how they plan to make SSL free for everybody by the end of the year. Possibly through SNI, but I'm not sure; I would say the CA cost outweighs the IP cost, but I'm not sure how the numbers for those services work out at CloudFlare scale.
Answer to the free question: SNI + IPv6. Hopefully one more reason for people to adopt IPv6. And limited IPv4 space is a much bigger factor for us than the CA cost.
* http://phoboslab.org/log/2013/02/how-much-traffic-is-too-muc...
* https://www.cloudflare.com/terms
Specifically, the Non-html caching bit.
In other words, if you are significant user of bandwidth...Cloudflare will charge you accordingly [and as you can see from the solution in the blog post, it is much cheaper to just rent a dedicated server than go through Cloudflare if you are willing to give up the CDN cache].
Cloudflare doesn't care about anyone using relatively small quantities of bandwidth because even in aggregate, they aren't costing Cloudflare enough to be a problem.
The other part is....
I doubt Cloudflare is paying "sticker price" for its bandwidth. Places like HE.net sell cheap bandwidth @ $.45/mbps. I wouldn't be surprised if Cloudflare has as good or even better rates at every POP they have.
You are probably thinking of the retail price of Amazon's bandwidth [which is like $.10 a GB. To give you an idea, at $600/mo colo with HE.net you'd have about $2,000-$3,000 worth of bandwidth at Amazon's prices depending on the usage pattern].
Looks like http://ourincrediblejourney.tumblr.com/ may need an update
I know you might not be able to talk about it much, but the article states "re-introduce a CloudFlare VPN service later in 2015" but I'm wondering, "Why late 2015?"
1) There are a bunch of other more-interesting and more-critical projects coming up. There is cool stuff still to be done in the VPN space, but the basics are out there now.
2) CloudFlare is already a huge network; it only makes sense to do something like a VPN if/when we can do it really well.
Now you have me looking forward to the CloudFlare blog post where they describe the custom/customized hardware they've put together for the VPN nodes. That will be some interesting reading...
CryptoSeal customers have been notified that the service is being shut down. For now. Both Lackey and Prince told securitycurrent that they would like to re-introduce a CloudFlare VPN service later in 2015.
The business managed VPN service was super easy to migrate; we had dedicated infrastructure for customers, so it's just a matter of transitioning that to a different ownership agreement in the same colo cage; the customers were notified in advance and are fine with everything.
This part made me curious:
> it is about getting into the VPN business.
If I remember correctly, CryptoSeal for consumers was shut down after concerns about the security/privacy of VPNs in general. Is Cloudflare in a better position to offer a secure VPN in the US? Maybe they have some better lawyers or infrastructure?
CloudFlare has some pretty amazing infrastructure, which they've blogged about -- great peering, lots of POPs, etc.
I was working on "how to do VPNs securely post-Snowden and post-Lavabit" after shutting down the consumer VPN service, which is both a technical and legal problem; we can definitely do it at CloudFlare.
I'm actually writing the post for Saturday; CloudFlare has a bunch of stuff going on this week so I've been pretty busy on top of getting some odds and ends resolved for this announcement.