Why does every criticism of CloudFlare ignore the fact that they mitigate the largest DDoSes in the world in an age where DDoS-for-hire cost only a few dollars per minute? Nobody could do that on the budget of a 1996 local ISP with one or 2 part-time IT techs.
CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
No they did, but they changed their mind once people spoke out against it. They thought free speech absolutism would be good for PR, but it turns out that the general public hates bad people enough not to care.
This is BS. One quick google and selecting a result from the first page: <a href="https://zeusstress.com/" rel="nofollow">https://zeusstress.com/
They're good at stopping DDOS but they've never been the best at it. What Cloudflare has always done best is making SSL and DNSSEC as frictionless and pain free as possible. If TrustCor was trustworthy enough to be allowed to operate a root certificate authority out of a UPS Store at a strip mall in Toronto, then why not Cloudflare? The thing we've always wanted for the Internet is DNSSEC <a href="https://youtu.be/b9j-sfP9GUU" rel="nofollow">https://youtu.be/b9j-sfP9GUU which the major players like Google have stubbornly sought to avoid. Ideally Cloudflare would help enough websites adopt it that it'll become more practical for the rest of us to use.
> they mitigate the largest DDoSes in the world
> DDoS-for-hire cost only a few dollars per minute
I imagine those two are closely related. If not for Cloudflare and similar offers, we would spend more effort & resources on non-symptomatic treatment of internet-scale bad actors and its enablers (lately, more under-maintained "smart" devices than dumb modems, I hear). Every unresolved-for-years botnet is excellent advertising for CF, and they are not even paying for it. (We are all paying for it, dearly.)
Capitalism, starting the moment TLD registrars first bid for the monopoly to charge rent. And continuing today, where I think only Cloudflare offer below or at cost domain registration, charging nothing themselves and just passing on the other mandatory fees to the rent seekers. It has had centralization at its heart since the beginning, when someone had to allocate IP addresses and everyone else had to agree (or we would have internets and not The Internet), which enabled this. I wonder if it would have turned out differently if, instead of central IP address allocation, clients had generated a UUID and it was accepted on The Internet unless consensus agreed it wasn't unique? But I don't think we knew how to do that then and technical limitations. Heck, crypto export laws would have killed it and required a central authority to prove that a UUID was you and not an imposter.
You could also make the alternative argument: the internet as a truly decentralized network as imagined by nerds was never going to actually work due to its (now obvious) impact on the political economy of the world and its actors, and because fundamentally centralized economies of scale are how humans tend to organize society. So why are internet nerds on forums so narrow minded that they don't read understand this, because they don't read books? But both of these "arguments" are pointless posts designed to get head-pats, because everyone has made up their mind. Buy your DV certs from another ACME provider.
The internet was never meant to be decentralized. It was a project researched and started by centralized entities (DOD, ARPA) that wanted to maintain command and control authority for a single person (POTUS) in the event of a physical catastrophe.
It was meant to be resilient and have multipath capability to route around damage. Having command authority sourced from multiple places was never part of the goal, and, indeed, in the client/server model that has prevailed the entire time the internet has existed, nothing about the design of the internet has been explicitly created to allow for server or data redundancy or distribution.
decentralized != distributed
Indeed, on the "modern internet" (aka the last 25+ years), everyone uses NAT, which means that end to end connectivity is not needed or wanted by most users and engineers. This idea that "every host should have a public IP, and every host should be a server as well as a client" is just fantasy that has no basis in reality, either in intent, or in practice.
IPv6 isn't a fantasy though. True, it hasn't worked out as hoped, but regardless of original intentions, IPv6 does let each client also be a host.
bossyTeacher · · focus · HN ↗
thephyber · · focus · HN ↗
CloudFlare was launched as a stupid-simple CDN, but DDoS mitigation and bot reduction are actually valuable features for many websites. Sure, CF isn't the only business in this space, but most of their rivals are large enough to be in the S&P500 / Russell 2000, so it's not like garage startups are competing for this business.
"Was meant to be"
This isn't a law of physics. This was a starry-eyed hope by techno-utopians and academics when the internet was still 100% funded by Uncle Sam. When the internet moved out of its parents' basement, it had to grow up and get a job to pay the bills. Some people are fine with a SquareSpace webpage instead of running their own custom Apache httpd website on bare metal in a colo like it's 2005. The cost of maintenance and cognitive load is a cost we shouldn't ignore.
It turns out that economies of scale exist. The Internet doesn't need 10,000 small CDNs and they would all be inefficient and expensive if that was the distribution. Instead, there are a few large ones that can afford to colo in many geographically dispersed data centers and who negotiated bandwidth peering contracts for advantageous pricing.
bhhaskin · · focus · HN ↗
LoganDark · · focus · HN ↗
RVuRnvbM2e · · focus · HN ↗
Surprise! It's on crimeflare.
LoganDark · · focus · HN ↗
jart · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
nottorp · · focus · HN ↗
edelbitter · · focus · HN ↗
> DDoS-for-hire cost only a few dollars per minute
I imagine those two are closely related. If not for Cloudflare and similar offers, we would spend more effort & resources on non-symptomatic treatment of internet-scale bad actors and its enablers (lately, more under-maintained "smart" devices than dumb modems, I hear). Every unresolved-for-years botnet is excellent advertising for CF, and they are not even paying for it. (We are all paying for it, dearly.)
stubish · · focus · HN ↗
N_Lens · · focus · HN ↗
supertrope · · focus · HN ↗
zoobab · · focus · HN ↗
aseipp · · focus · HN ↗
sneak · · focus · HN ↗
It was meant to be resilient and have multipath capability to route around damage. Having command authority sourced from multiple places was never part of the goal, and, indeed, in the client/server model that has prevailed the entire time the internet has existed, nothing about the design of the internet has been explicitly created to allow for server or data redundancy or distribution.
decentralized != distributed
Indeed, on the "modern internet" (aka the last 25+ years), everyone uses NAT, which means that end to end connectivity is not needed or wanted by most users and engineers. This idea that "every host should have a public IP, and every host should be a server as well as a client" is just fantasy that has no basis in reality, either in intent, or in practice.
fragmede · · focus · HN ↗