I am a plebe who doesn’t understand these things but what exactly does cloudflare do? I see it popping up more and more often redirecting before visiting a site. I assume that this has something to do with bot traffic? It seems like every mention of cloudflare is about how it ruined someone’s day.

  • Potatos_are_not_friends@lemmy.world
    link
    fedilink
    arrow-up
    42
    ·
    edit-2
    6 months ago

    Hard to answer your question because it’s a mixed bag.

    As tech gets cheaper, it gets easier and easier to do malicious things.

    On the small scale: I used to host my tech blog on a rinky dink raspberry pi.

    I was getting hundreds of funny bot visits a hour, as they try to pen test and find any vulnerabilities. And that was after I set up some tools to block weird IPs. Two years ago, I was getting thousands, and the numbers kept growing. It didn’t hit a point where user experience was taking a hit, but at some point it will.

    I could get a beefier system (more expensive), or I can just sign up for cloudflare. And now the management of that layer is handled by Cloudflare, so I can focus on coding.

    Now to talk About the enterprise level: same thing but hundreds of times more. We were actually getting DDos. We originally didn’t want to use Cloudflare, and instead use in-house solutions. But after a hefty trial and seeing our AWS expenses skyrocket, we swapped to Cloudflare.

    Signed up, swapped over to Cloudflare, and instant uptake. We are also paying a fraction compared to our in-house solution.

    It sounds like a freaking ad for cloudflare.

    But one thing I don’t like is Cloudflare can easily monopolize the internet. As we all switch, Cloudflare now has a lot of power to tell sites to fuck off if they don’t like their content. Cloudflare hasn’t yet. They keep up White Power websites and racist shit. But they have taken down calls of violence and online gambling.

    If you have your day ruined by Cloudflare, I’m going to either assume you run a bot network, you’re trying to do something incorrectly, or you are part of the dark web.

    • dustyData@lemmy.world
      link
      fedilink
      arrow-up
      21
      ·
      edit-2
      6 months ago

      My day is regularly ruined by cloud flare, and I don’t run a bot net. Because instead of doing their job they decided to declare my entire regional IP block a spam source. Now, no doubt there might have been one bad actor who used one IP in this IP block once. The entire block is for residential IPs though. But we all have to suffer degraded service because cloud flare can’t be bothered, and as a private user of the internet, I have no resource or place to complain. Not even my ISP has recourse because cloud flare answer is “we don’t care about your clients”.

      • bobs_monkey@lemm.ee
        link
        fedilink
        arrow-up
        7
        ·
        6 months ago

        Yeah it gets sticky like that with VPNs as well. I run an always-on VPN (PIA), and depending on which server I’m connected through, it’s either a good day or a bad day. Sometimes switching servers works, others not so much.

        • dustyData@lemmy.world
          link
          fedilink
          arrow-up
          6
          ·
          edit-2
          6 months ago

          Except that’s exactly how it works. Cloudflare keeps a record and rating of all IPs in the world. This rating determines the speed of response from the server and the number of security checks before traffic is let through to the protected server that is being queried. This rating is based on over 40 different surveyors that track and monitor spam mail sources, botnets, ISPs and data centers, and can flag IPs as bad actors. These records are available online.

          My ISP rotates IP addresses to clients every so often and after router restarts. One particular block is locked and throttled to hell. Sometimes, certain webpages stop working altogether for me, as if traffic is blocked. Or response speeds get excruciatingly slow. Every time it is because I have been given an IP in that exact IP block, tracing the hops shows that cloud flare servers are the bottleneck. Checking it on IP trust records confirms they are flagged as bad actors. It’s not my ISP nor their infrastructure, as using a VPN instantaneously restores high speeds and response times, and magically a cloud flare page shows up to check for a human.

          I have also checked directly with my ISP and they confirm that there’s absolutely nothing wrong on their end, it is cloudflare servers blocking the traffic to some webpages, nothing they can do about it. They have contacted them and they refuse to provide answers as we are in a country sanctioned by the US, so international commercial relations are hindered with bureaucracy.

          The worst part is that I can sort of bypass these problems with a VPN, but non cloudflare VPNs are also throttled and trigger anti bot checks every single time. So there’s no win for me. My ISP’s solution is to keep rotating IPs at random hoping clients spent the least amount of time affected by these issues.

    • quixotic120@lemmy.world
      link
      fedilink
      arrow-up
      9
      ·
      6 months ago

      Cloudflare has absolutely told websites to fuck off because they don’t like their content. They haven’t done it a ton of times but they absolutely have. No one cares because the sites they’ve done it to are toxic cesspool shitholes that, to be fair, the world is probably better off without. But each time it showed that cloudflare can simply wield its power if it feels like it.

      If your site becomes controversial in the future and is protected/hosted by cloudflare don’t be surprised if they suddenly send a letter saying “fuck off”. They’ve become arbiters of internet censorship and we have accepted it because the daily stormer and kiwi farms and 8chan are bad.

      The ridiculous part is all of those sites are still accessible; daily stormer and kiwi farms both still accessible from clearnet (iirc 8chan is tor only) so cloudflare dropping wasn’t even all that effective. Well funded hate speech found a way. But for the next ones that don’t have major alt right cash behind them to fund cloudflare alternatives they’ll just simply disappear. And then we will have the internet where corporations like cloudflare, who should absolutely be content agnostic, decide what we can and cannot see. You may think it’s fine right now because they’re doing it against websites that are admittedly gross and terrible, but what happens when they overstep and the line blurs?

      They should act like a proper tier 1 provider: find evidence of crossing a legal threshold, get a court order, and terminate service if something that bad has occurred. Anything less and they suck it up and honor the contract they signed. They haven’t, so fuck cloudflare. The internet is an amazing place but it’s also a disgusting abhorrent cesspool. Don’t get involved in hosting it if you can’t deal with that.

    • AnAmericanPotato@programming.dev
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 months ago

      If you have your day ruined by Cloudflare, I’m going to either assume you run a bot network, you’re trying to do something incorrectly, or you are part of the dark web.

      Or you are unfortunate enough to share a subnet with someone who got on Cloudflare’s bad side, in which case there is basically no recourse.

      There are a million legitimate reasons to use a VPN, for example, but Cloudflare doesn’t care.

    • asudox@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      6 months ago

      Just a few weeks ago, Primeagen read a blog about how Cloudflare threatened an online casino with taking their sites down if they didn’t pay them 120k$ in a day.

      • BaroqueInMind
        link
        fedilink
        arrow-up
        5
        ·
        6 months ago

        If you read about it instead of the headline you would have discovered that the casino was simply trying to take advantage of cloudflare in a similar fashion they had been doing to people gambling in their own casino, by leveraging the cheap tier cloudflare provided and slamming the network which was a detriment to other users with smaller bandwidth needs.

        Imagine a slow semi truck hogging a two lane road and getting mad at you for trying to go around him just to go home. Cloudflare said they had six months to pay for a higher bandwidth trunk or they can go fuck themselves. The casino did nothing for six months, so they got to go fuck themselves

        • asudox@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          6 months ago

          I wouldn’t really defend cloudflare here. Sure, the tier might have been a bit cheap for a big online casino with high traffic. However, cloudflare should have set limits in place or warn the casino beforehand and not just surprise businesses with great amounts of builtup “damage” money if the business was causing their network to “struggle”. The call they made with the CF sales team about the serious issue wasn’t a warning at all. According to the blog, they just asked if the casino considered the enterprise tier. Nothing about their networks struggling is said at all. Additionally their future calls were misleading and just tricks to get the casino to talk with the sales team. I’m not sure how CF’s fooling the casino here can be seen as something reasonable at all.

          They shouldn’t call it unlimited if they can’t handle high amounts of traffic.