6,077 karma · joined February 14, 2011
"We definitely care about abuse generated by Workers."
That may be the case internally but it's not as evident through support. I base this on their ability to answer security-related questions, diagnose odd behavior, or mitigate problems. FYI, we are paying for your highest tier of support.
"it should be treated as if they were running their bot on any other cloud provider and making requests across the internet."
Part of this is how Site Analytics and WAF analytics represent worker data (or don't). Even though the worker modifies the contents, the IP is passed through as the end-user IP (at least the way we use them). These analytics systems need to do a better job of identifying anything worker or tunnels related. If this were being done through AWS it would be evident. We can use various mechanisms to mitigate this, but I wanted to clarify why abuse through Workers is different for our implementation.
Also, the process to block non-zone workers was undocumented, and it took a couple of weeks for someone to dig it up and only after several trials and errors. Support wasn't sure it would work, and there was no other documentation (at the time).
We have yet to get an answer about the high volume of tunnel requests from specific goes.
Combine this with the opaque stack you have that causes odd situations. For example, I added a worker that automatically retries 500 errors from the origin. Simple enough. This breaks Zero Trust, though, and causes a redirect loop. There may be documentation somewhere, but there isn't a good breakdown of how Zero Trust fits into a customer-defined worker, and a redirect loop is undoubtedly a poor failure mode.
There is a world of difference between the information you have and may provide as the Technical Lead of Workers, and what I'm getting via support or raw documentation.
I could provide you more information offline if you want.
Edit: Let me just add the other recent thread [1] regarding redirect loops in verification is par for the course. We had the same issue and tried for weeks for progress or resolution. The issue was never resolved, nor could we get information on why the failure mode was so poor, etc. That ambivalence adds up to expecting general ambivalence or inability to make meaningful progress. At some point, you say to yourself, "Why waste my time talking to support and putting in much effort and getting the run-around."
(!cf.bot_management.verified_bot) and (cf.bot_management.score lt 10 ) and len(cf.worker.upstream_zone) gt 0 and not cf.worker.upstream_zone in {"<zone>"} and (not ip.geoip.asnum eq <exception as>)
https://twitter.com/Andercot/status/1686215574177841152
National Lab (LBNL) results support LK-99 as a room-temperature ambient-pressure superconductor.
Simulations published 1 hour ago on arxiv support LK-99 as the holy grail of modern material science and applied physics.
Right or wrong, it's hard for developed economies to destroy their economies while China (and others) are rapidly making the problem worse. [1] Progress is being made through:
"The Climate Action Tracker says that between 2015 and 2022 China's greenhouse gas emissions increased nearly 12%, while U.S. emissions declined some 5%. China's methane emissions rose about 3% from 2015 to 2021, the latest year with good data, while the U.S. cut them by 5%." [1]
[1] https://www.wsj.com/articles/john-kerry-china-climate-econom...
[1] https://developers.cloudflare.com/workers/learning/integrati...
On a side note, I'm trying to imagine what "sensitive" code would be read, incorporated into an LLM such as Co-pilot, and somehow have any meaningful impact to me once incorporated?
* its been around 2 years since our last use as a paying customer. YMMV.
I've been WFM for 7 years now. I don't think RTO is a bad thing, but its all situational. How silo'd are projects and how much inter-team coordination do you need? How long is your commute? What kind of person are you (some people just work better in office environments)? Do you need physical access to equipment? The list goes on.
Being fully remote has allowed flexibility for team members to relocate without being forced to leave and thats been the biggest advantage. Going from a FTO to WFO or RTO is a big transition that requires re-defining workflows and communication mechanisms. Products like Zoom and Slack have made that far easier, but the bigger the organization, the harder the transition.
Personally, I miss having an office. I've lost human connection by being isolated at home that isn't replaced with normal social interactions. Maybe thats just older men not making time, but office space traditionally filled that role for me.
I'm holding crypto because I think it's neat, but I'm also holding it because there's little I can do with it... i.e., lack of general utility, yet.
* I've been using various CDN's since the 90's, and I'm currently a Cloudflare Enterprise customer. However, Cloudflare, not without its faults, is still the best option out there.
"We build and run our own servers. In datacenters."
Is this a selling point today? Suddenly their background in on-prem architecture, operations, security, and network management becomes very important.
We have been the recipient of many invalid notices to Google. Google publishes the details via Lumen but makes it impossible to reasonably analyze the data. 1) They hide the sender info. 2) They make you validate, via email, for EACH DMCA you want to view. In other words, they claim transparency, but practical use isn't possible. They also don’t publish DMCA’s against sites like YouTube.
Are they talking about the lack of an EOD or something more fundamental to the power system? It almost seems like you need something external to the facility in case of a fire where it's unsafe to enter the building.
I'm not sure why this is a big deal though, this is why Amazon has multiple AZ's. If your in one AZ, you take your chances.