Hacker Newsnew | past | comments | ask | show | jobs | submit | viraptor's commentslogin

I wish. Not only do they sometimes randomly fail, Google search console will not tell your why. I've got a site with a sitemap which passes in every validator I could find, yet Google doesn't read it and GSC just reports "error" without any details. Google is big enough to go "we don't care, it's your problem".

Lots of people will run http over the tunnel rather than https, so that actually comes out cheaper for CF overall because they don't have to start new TLS sessions.

This is not how things work and no company providing online services for money would rate limit like that. This would do nothing for real world DDoS. You're in "not even wrong" territory.

And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.


Yeah, of course if you're a large service, stuff that works for SMEs isn't gonna work for you...

If your problem is AI crawlers, then simple rate limits help, I've helped countless of businesses with this already. For the ones that it isn't enough, you continue adding more roadblocks. There is no "one size fits all here" and that you seemingly is under that belief, leads less credence to what you're saying, not more.


Brother if you have the solution, start a company.

There are people willing to throw money at you.

But Free is hard to beat with a global presence.

And please listen to what others are saying here, there's a lot of experienced people here. It is no longer 1998, 2008, or even 2018. The traffic a basic website experiences now is a massive increase, especially for those well SEO'd and using TLS.

Also you said this:

> CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.

Origin obfuscation.

Also greatly helps to protect it directly from various attacks and scans, especially in our new LLM driven security world where new 0days are being found constantly. How much at risk are you willing to put the SMB?


It's also a great protection racket. They host many DDoS provider sites and protect them from law enforcement.

Someone's eager to downvote this, but it's been known for a long time and still happens in obvious ways. First page of results for booter services contains https://zeusstress.com/ which is hosted by Cloudflare (yes yes, ceo will send lawyers to say they only proxy not host - doesn't matter in practice)

Unfortunately that one's on the operators. I can complain for days about CF, but nobody is forcing the companies to default to giving everyone a managed challenge page. Some do, because either they don't care or don't realise the extra cost.

> We sent a ticket that activating some of their services instantly caused bad bots to scan our site

You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.


> you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you

This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.


> Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.

But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.


It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service.

> and I don't think people should default to trying to prevent them.

It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.

Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)


I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada:

https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...


That graph is useful for the people who think DDoS is the biggest issue or even a big issue typically: https://www.bdc.ca/globalassets/digizuite/55250-canadian-sma... "Percentage of Canadian small businesses that have experienced a cybersecurity incident"

The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.


What exactly are you arguing? I already said 5%. Your personal experience of DDoS being super rare doesn't seem to match the real world.

Literally the graph you posted agrees with me. Most "cyber attacks" are phishing according to that graph, which I'd argue is less of an technological attack and more social engineering.

Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.

> Your personal experience of DDoS being super rare doesn't seem to match the real world.

What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.


For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days.

Wouldn't most udp reflection attacks be bigger than your pipe?

Is that still a thing? What are they reflecting from? Where are they getting unfiltered uplinks?

Not as common anymore, but the guy I responded to mentioned 30 year history.

Dozens and dozens of times. And having the bigger pipe has always saved it, along with the supporting infrastructure to churn through that traffic.

> But again, those sort of attacks seem to happen seldom

[citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.


It depends on what you're trying to serve, but it's used to either save you money or as an insurance (or both). You don't need a CDN overall. But if you grow large enough, at some point you'll run into one of these three situations:

- Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead. (Where the cache size is larger than anything you'd want to support yourself. For example, if it's <1G and survives your service restarts, you may want to do it yourself)

- Your customers on the other side of the world start complaining that the resources take ages to load.

- Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.


I'm not sure one can fail this test. You can follow "wolf is not real", you can follow "wolf will eat the goat", or you can say the task is ambiguous. I could easily defend any of those.


The LLM passes my test if it calls out the ambiguity or just goes with it and responds with a 3-crossings solution. It passes if it doesn't just plainly ignore this one sentence.

It's such a strong test in my opinion, because all the words and phrases for the well known river crossing puzzle are inside the text. The original puzzle probably appears in the training data over and over again, but probably not my version.

"If it looks like a duck, swims like a duck, and quacks like a duck, then it probably is a duck" is what weaker models seem to apply. But my test isn't a duck. It's extremely easy for a human to catch the ambiguity, but surprisingly hard for many LLMs. I think GPT 5.0 Thinking was the first model I couldn't trick into not noticing the ambiguity. 4o and 5.0 instant fell for it all the time.


Save your time - this is not real. The requirements are impossible and there are many other issues with the post.


That's why the nerd technical stuff isn't all that interesting to me; it's likely useless. But the idea that more democracy = better is an insidious one that I see often. Democracy is a means that applies in specific conditions. Self-determination is the good we're seeking. This should be obvious but somehow is not.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: