Why people are still using and promoting Cloudflare when the company is repeatedly trying to position itself as an internet gatekeeper?
There is already a consensus that internet gatekeeping is bad for people, so why people are volunteering for this?
This company already has a tremendous control over what people can or cannot see on internet since a lot of websites use it has CDN, but there should be a limit on what companies can do or cannot.
In this particular case, we have blind people blocked from internet, and it doesn't matter if this is not on purpose or it is just a side effect, because in practice they are been blocked, and yet something like this is unable to make a scratch its reputation.
I like Cloudflare, because it provides some very essential services with free tiers. It is big enough, so I can trust them. I can be sure that they won't inject ads into my HTML pages. I can be sure that their DNS will not replace NXDOMAIN with fake ad responses. I can be sure that they won't log my VPN traffic trying to extract passwords or something like that.
For sure I don't support their decision to ban blind users and hope to see that resolved. But that's not enough to change my mind, not even remotely.
> I can be sure that they won't inject ads into my HTML pages. I can be sure that their DNS will not replace NXDOMAIN with fake ad responses. I can be sure that they won't log my VPN traffic trying to extract passwords or something like that.
But they have built the perfect shim in the middle to do ALL of these things at some point in the future.
The only thing preventing it is a handful of moral executives, who someday will move on or retire. At that point a smart Wall Street type is going to figure out that a merger between CloudFlare and $adnetwork is going to generate a shit ton of money (think Google+DoubleClick).
I don't doubt that CloudFlare is full of smart well meaning people, but what they have built is a ticking timebomb. The solution is to have ten CloudFlares so that the path between consumers and websites isn't regulated by a single organization.
Edit: to be clear, the internet was successful because any host could talk to any other host. If people did dumb shit you could work around it in creative ways. Even in the most oppressive countries censorship is still bypassable. CloudFlare's business model is centered around convincing companies to effectively disconnect their services from the internet so they only talk to CF servers.
And yet Cloudflare is just one of many massive internet companies. Are you going to say the same about Akamai? What about all the ISPs and exchanges in the middle? What about all the clouds and datacenters?
The reality is we live in an interconnected world where everyone uses hundreds of vendors to live and work. There's a certain amount of trust involved, backed by business relationships and the law. It's not perfect but it works just fine.
If you really think Cloudflare is excessively risky then of course you don't have to use it, but it's a strange conclusion to arrive at after looking at their actions all this time.
CloudFlare positions itself as an all or nothing frontend to your site, not just a CDN you offload assets to. Even sites that fully front themselves with a CDN you can still poke around and find the origin servers.
For example you can drop requests to fbcdn.net (which last time I bothered to check was a good mix of Akamai) and still make a connection to Facebook itself and at least logged in and view HTML.
Obviously ISPs, internet exchanges, datacenters, and clouds operate very differently. But I imagine you know the difference.
What are you trying to say? You can use Cloudflare in a variety of ways, just like any other CDN.
My point is that there are lots of vendors with lots of control involved in pretty much every business transaction. There's nothing special about Cloudflare in this regard, in the same way you trust your bank or ISP or power utility or office custodial staff. Risk management is a mature process; no wild conspiracies required.
I was with you up until "The solution is to have ten CloudFlares so that the path between consumers and websites isn't regulated by a single organization."
This is hardly a solution, it just spreads the pain around. A solution would be a democratically planned organization, or group thereof, which is responsible to all shareholders including users, employees, executives, and investors.
Basically all of those companies are regulated, and none of them can cut you off, because you did something stupid. You can even murder someone, and they can't cut you off.
Well yeah, sometimes. In some countries (i believe france), they can only limit power to lightning (a couple of hundred watts limit, so not totally off) if you don't pay, and if your only cooking appliance is using electricity (electric stove), they can't even limit that.
> The solution is to have ten CloudFlares so that the path between consumers and websites isn't regulated by a single organization.
There are! Cloudflare is by no means the biggest CDN provider - plenty of others exist out there. Akamai, CDNs from Google/Azure/AWS, Fastly, at least.
What makes Cloudflare so unique in it attracting criticism like this? They're just a bog-standard CDN, the likes of which has existed long before Cloudflare. Is it just because they're the most "visible", having a free plan that people use?
The Cloudflare captcha is ridiculous really and makes sites completely unusable with a VPN. I even get captchas for different pages on the same domain! It used to be you only got captcha for form submissions. But somewhere along the line you started getting it for simply visiting web pages as well. Part of me wonders if I'm just getting played by these companies into labelling all their ML training sets for them.
There's not really any "lock-in" with CloudFlare, though. It'd take me a day, at most, to move off of their free services.
They provide me a lot of value right now, for free. If they ever started doing something shady, I trust that people like you would cause enough of an uproar/pushback that I (and other site owners) would find out about said shady activity... and then move off CF.
I'm not as concerned with the what-ifs of what a company could do in the future as I am with their track record so far.
To me saying any $X big company is a ticking time bomb is nonsense.
The fact is, a number of companies control a huge number of eyeballs. An unethical exec taking advantage of that would cause enormous PR nightmare. If you're making money with a great brand reputation, you don't mess with the recipe.
Yes, they do mess with the recipe. They've got money to mask it out and assist with conditioning the population to the new norm. And they can do this cause the service is sticky. Mass client exodus is very unlikely. And the ones that move out for morals are quickly replaced.
We have plenty of historical data to draw from here. Cynicism is the rational approach.
Corporations (beyond a certain threshold of market control) doing shady, consumer hostile things for profit is the norm. So I don't think the ticking time bomb concept is nonsense at all.
As a recent example, Google was an overwhelming net positive for years. They genuinely made the internet better. But the day they went public their eventual abuse of their market position, intentional or not, became inevitable. We're only in the early stages of seeing what that will look like.
Asking questions about whether we want to help give companies the market position to become abusive makes the most sense early, not after it's already happened.
Perhaps I wasn't clear. The fact that some corporations do shady things does not mean it is inevitable that all corporations do it.
I'm arguing against the logic: "every big company always ends up being a den of advertising evil". Cherry picking examples like Google is not proof of this.
Not every company is Google or Facebook. Is Apple selling its soul to advertisers tomorrow? Is Netflix going to insert ad breaks every 5 minutes any day now? Is Tesla going to have you watch an ad every time you start the car?
I'm not sure how we got to it being strictly about advertising. Nor did I say 'all'. But the vast majority of corporations with the market power to leverage in shady ways for profit, do in fact do just that.
> I can be sure that they won't inject ads into my HTML pages.
But they will harass your visitors with captchas for no good reason. I also sometimes run into Cloudflare's "this website is using a protection service" with no way around; it turns out it's a geoblock because it does load just fine when I use a VPN through Germany.
The internet was meant to be decentralized. The IP addresses were meant to be used for routing and for routing only, and otherwise treated equally.
>But they will harass your visitors with captchas for no good reason.
The other fun part about those captchas is they also gatekeep blind people in a way. They're using a service called HCaptcha which doesn't offer an audio alternative like ReCaptcha does. Instead they give you an "accessibility cookie" delivered to your e-mail address, which you can then use to automatically pass the captcha. (Very useful for everyone btw; give it a try.) The problem is that this cookie--and the e-mail address it's attached to--allow CF and potentially HCaptcha to track you around the internet. There's no way to anonymously browse the net through TOR or a VPN unless you create a throwaway e-mail address for that session.
HCaptcha recently expressed interest in creating a text-based alternative, but I wonder how this will stack up against modern AI. For now, it doens't bother me because I don't encounter it often and I have throwaway e-mail addresses, but it's just one more step I have to go through to remain anonymous where any sighted person could just click the traffic lights.
Depending on the service you're offering, it can make a ton of operation sense to simply blanket-ban a whole bunch of IP blocks, including some that correspond to certain countries. China and Russia, for instance, will provide nearly-zero income but a substantial percentage of exploit attempts, stolen credit card use/validation attempts, et c., for some companies. Just banning them might make a lot of sense.
I do some backend work for a small company that sells a downloadable software product.
As far as we can tell no one in China has ever bought our product in the ~15 years it has been available. None of our pages are localized for China. If someone in China wanted a product that does what ours does there are Chinese companies whose products are cheaper and probably better for Chinese users.
Yet last time I checked something like 95% of downloads of our product came from China. I took a bunch of IP addresses from the download logs and looked to see if I could figure out something about these downloaders.
All of them seemed to be at hosting companies, not end user machines. Looking at nearby IP addresses to see what else is hosted at the same hosting company they were mostly scam or borderline scam sites or porn sites. The later was a bit unexpected because at least according to Wikipedia porn and any involvement with it is prohibited in China.
I don't see any good reason I should not block Chinese downloads. We have to pay for the bandwidth they use, they are extremely unlikely to generate any revenue for us even indirectly, and they are coming from sketchy commercial IP neighborhoods rather than end users.
>What if I want to just look at a product with no intention to buy it?
Then they want you even less.
In any case, if a company doesn't want to do business with your country, that's it. What matters whether you want to buy it or not? (Not to mention a lot of the abuse towards developers comes from no buying customers as well - people who want some feature added "before they buy", who just use the trial or free version, etc.).
You can always find a competitor company that does serve you.
International customers are more trouble than it's worth when you're a small company and you as a seller are the one who absorbs the loss in cases of delayed, defective, lost or damaged items.
I find it deeply ironic and a little sad that you cite the intentions of the original designers of ARPANET and the Internet, then describe about how you've commercialized the Internet.
I'm talking about one use case of Cloudflare I've seen. I don't think I can be held responsible for the commercialization of the Internet when I make and freely distribute monkey movies.
If 99% of spam/abuse came from one location, and it wasn't a place I offered a service to at all, I could use something like Cloudflare to restrict their access.
Europe has GDPR, and a bunch of american news sites (even articles posted here) just block you, some even without giving a reason ("this site not available in your country").
> But they will harass your visitors with captchas for no good reason.
It is up to you to harass your visitors or not. CloudFlare does not enforce it. You can disable the firewall if you don't want that kind of protection.
They enable what exactly? It's a useful tool and should definitely be activated in some use cases.
We might argue about whether it should come turned on by default or not, but as far as I remember the default setting is not a strict but a moderate protection level anyway.
Not sure what point we're trying to make here. Any other firewall/CDN/WAF enable you to do the same thing, to the point of many also providing ready-made protection profiles... what makes this specific member of that group special? Can you clarify?
The Internet wasn't meant to be used for outrageous amounts of fraud and abuse. Sometimes you have to put a captcha on ASNs or CCs because many of them simply don't care about keeping the bad guys off their networks.
Be careful with that. To be trustworthy, a party has to be willing and able to act in your best interest.
As a company (or any group) grows, their ability increases, but beyond a certain point, history shows that their willingness to act in your best interest decreases.
For companies and countries this trend often correlates with political and/or economic power being concentrated among a few individuals.
Wow geez. There's been a lot of BS being thrown around about Cloudflare. I don't work for them, but I have been following the company for years.
On Cloudflare being a gatekeeper: yes, if you care about load, cost, and attacks, you need one. Cloudflare offers real value to their customers by providing these services. Will that lead to Cloudflare controlling the web? Well, you've got a number of direct competitors (Akamai and Fastly, to name two) in addition to the CDN offerings provided by cloud providers. Cloudflare isn't the first CDN, isn't the largest, and won't have a monopoly on being an internet middleman. Compare Cloudflare's network (https://www.cloudflare.com/network/) to Google's (https://peering.google.com/#/infrastructure).
On the necessity of gatekeepers on the internet: this is the way the internet works. You are responsible for peering with the rest of the worls at a physical location and dealing with the traffic that comes your way. If you want to be close to your users (to avoid bandwidth bottlenecks and provide lower latency), you need to install equipment all over the place and peer with other networks. If you want to deal with bad traffic, you need the capacity and software to handle/filter it. You can always build your own CDN if you want, but the only way to deal with these issues is a CDN. Maybe if the internet worked differently things would be different. But that would be a huge change, especially since someone has to foot the cost of building these services. I guess you could somehow distribute the cost (though I don't see how), but you'd also have to someone deal with the management and development of said infra, and I have no idea how such a thing would work without a central entity being responsible.
Eh, gotta call this out. The Internet is designed on an end-to-end principle, and at each layer the endpoints are expected to mediate behaviour via protocols.
By this architectural standard, middleboxes (including all HTTP proxies and CDNs and what have you) are kludges. They are not "how the internet works", they are the antithesis, they are symptoms of emergent pathology. These are barriers to federation and distributed systems, both enabling and enabled by centralizing forces that divert individual autonomy & value to institutional & commercial interest. They are evidence for Further Research & Development Required, and my belief is we'll eventually solve these problems at the end-to-end protocol level.
As for Cloudflare, particularly, their business strategy is to drive down the marginal cost of their own bandwidth, for use in revenue-bearing services such as DDoS mitigation. Every service provided for "free" (some of which, at the free tier, will increase your site latency and lower your visitor count, by the way) works to increase their volumes for use as leverage in peering negotiations. As ever, "free" = "you are the product".
> The Internet is designed on an end-to-end principle
Yes, this is true, and the end-to-end principle is great. But it's not always straightforward to follow, and certainly is not a religion. In the end, no one cares about the end-to-end principle. They want systems that are flexible, robust, and high performance. In some sense, it's a lot like simplicity. You try to and make your design as simple as possible, but sometimes, you have to have complexity. It's not ideal, but it's not a deal breaker either.
Additionally, you have to ask the question: what is an endpoint? "A" server, or can a distributed system be seen as an endpoint? After all, a single server is a bunch of independent components communicating with one another (via infinity fabric, PCIe, etc), so why would it matter if we spread those components across machines (and spoke RPCs, RDMA, whatever)? To me, a service running in a data center with a load balancer in front is "an endpoint" and no real violation of the end-to-end principle is taking place.
I think extending the definition of "endpoint" to everything behind a CDN is a stretch too far, but ultimately, I think "endpoint" isn't really defined well-enough to be the unit we talk about.
On the contrary, these are not muddy grey area topics that are open to barnum statements, gaslighting, and misrepresentation, such as:
> In the end, no one cares about the end-to-end principle
This assertion couldn't be more wrong. I care; many others care; caring about the architecture of the Internet did not die with John Postel.
> you have to ask the question: what is an endpoint?
No, we don't: it's covered in networking 101. Any party in a layered protocol whose interactions are opaque to the layers below and transparent to the layers above. And they're defined by those interactions, not by their implementation.
A CDN is a forward caching proxy for content layered over HTTP, and that's all that matters when it comes to realising their emergent properties. Don't be hypnotized by the shiny dangly extras that the providers wave around hoping to distract attention from what they actually offer, or why they do it, or the consequences.
I didn't mean to offend, sorry if my statement rubbed you the wrong way.
All I'm saying is that users of a system don't think about design principles, they are there for the developers and operators to manage complexity and meet higher-level objectives. They can do this even if they are not followed 100% perfectly.
Sort of, but nature / decentralization / emergence is messy. The internet still works pretty well without rigid intermediaries (besides unavoidable core routing paths and root DNS), but that open property is also what enables people to easily disrupt things, like with DDoS attacks.
In a hypothetical distant-future anarchistic society, it's very likely you're still going to have private security forces, analogous to Cloudflare's security offerings, and some of them will probably grow to be quite big.
Attackers have an asymmetric advantage. One person with a gun can quickly terrorize or kill a lot of people, and one kid with $10 on their parents' credit card or access to a botnet can instantly bring an organization's web presence to its knees at the click of a button or input of a command.
I definitely agree that any one entity controlling too much of the access route is a concern and a risk, but before Cloudflare it was Akamai. If they never existed, Akamai and CloudFront would be the de facto oligopoly. If Cloudflare dies, someone else will probably gain a similar market share.
You can try to make security enforcement as decentralized as possible, like Bitcoin tries to. But, it was probably inevitable that a few huge mining pools would come to dominate, just like a few big security/CDN companies have.
It's plausible that there could be future solutions that will offer similar security and performance and resource-conserving benefits for free without requiring any private intermediates, and I'd happily recommend them over Cloudflare/Akamai/etc. if they existed and were as good or better. They just don't seem to be here right now.
My point was: I see no reason why we couldn't accomplish everything Cloudflare does without a central authority. Markets are able to solve just about any problem without any central person pulling the strings. Case in point: the internet.
I'm speaking specifically against the statement that Cloudflare, acting as a central authority, can solve problems that cannot be solved without a central authority.
There’s nothing about capitalism that prevents, or is anathema to companies, organisations or individuals from collaborating or pooling resources. Communism is a specific political and economic system with explicit and deliberately coercive communalising policies. It doesn’t have a monopoly on community forming or coordinated community action or the pooling of community resources though.
Because without CloudFlare we would: Pay thousands in bandwidth costs per month; Double or triple our servers to handle peaks (they cache and serve the HTML for us); Be down constantly because of DDOS attacks.
Cloudflare detects the DDOS and will block it, notifying you by email. We almost never use the Under Attack Mode unless it's actually affecting us.
The biggest thing we do to help ourselves when we're under attack is making sure that the pages being ddosed (homepage, etc) is being cached by them. There will always be some requests that CF doesnt block, so the cache ensures they get served by them.
> The biggest thing we do to help ourselves when we're under attack is making sure that the pages being ddosed (homepage, etc) is being cached by them.
What about pages which can't be cached? For example an updated comment feed? How would you deal with dynamic data?
People who DDOS sites usually attack the homepage.
If they attack a dynamic page, check if you can cache them for 30 or 60 seconds. Pretty close to real time.
If you have cookie based authentication for those pages, its going to be difficult to cache them at all though. Which is where SPAs come in useful since auth is client side.
By that logic, every one who bought Teslas in the beginning helped pay for the later customers. That's just how almost all industries work - insurance companies being a big one.
I pay nothing, so I’m obviously not a customer. If Cloudflare decides to stop hosting my site free of charge, I will have to find another host. In that sense I depend on them. Is that what you meant by dependant?
When you pay for a service, you have some leverage with them. You funded part of the service, you're a stakeholder. If they mess up, they lose your business.
That’s arguable. If the free plans help cloudflare grow its brand and customer base and is an effective marketing tool, then it’s helping cloudflare become more profitable. That might make cloudflare a more scalable and efficient business, driving down its costs per customer and enabling lower prices from scale efficiencies.
This is a well known economic effect. I can’t demonstrate it’s the case with cloudflare but it’s quite possible and even likely. Even if it’s not actually driving lower prices, customers can benefit if their service provider is more economically healthy.
Their "self serve" tiers, and especially the $200 one (the only one with an SLA at all) are really, really good value, is why. Depending on your needs, their enterprise offerings are, too. And boycotts are, broadly, not effective enough to justify any personal risk/harm/expense at all.
1) Blind people are not "blocked from the internet". This is an accessibility issue with one of their security products. It's no different than an employer using other security measures that might limit usage for certain people, but it's the employer who makes the ultimate decision.
2) The reason people keep using Cloudflare is because it has the best product suite and pricing. There are competitors but none have approached the same features or (ironically) accessibility as CF.
3) Mission statements are nothing more than politics and PR. People put entirely too much faith in corporations and their associated mottos as if they're divine principles to live by. It's up to users to make their own rational decisions by weighing the risks, and in that regard, Cloudflare has actively helped fight censorship by helping improving connectivity and access to software, information, and privacy.
But they can. They just can't read the information because the software is not fully compatible yet. What if the screenreader software didn't exist or wasn't working? Are you going to make the same complaint?
> "People use cloudflare not because it is the best product"
Care to share some evidence? Are you just assuming you know better than everyone? The company didn't reach $35B market cap because of a free tier (which is also considered part of the product by the way).
> "says their PR is very effective."
Actually, I said PR should be ignored and you should instead look at their actions, which do back up what I claim.
It sounds like you're completely unfamiliar with the company and instead have some irrational vendetta against them. Not sure why, but it certainly doesn't lead to any productive discussion. Let's end it here.
More and more, "because security" has become the go-to reason, almost a thought-terminating cliche, for destroying freedom and privacy. It's really disturbing to see.
There is already a consensus that internet gatekeeping is bad for people, so why people are volunteering for this?
This company already has a tremendous control over what people can or cannot see on internet since a lot of websites use it has CDN, but there should be a limit on what companies can do or cannot.
In this particular case, we have blind people blocked from internet, and it doesn't matter if this is not on purpose or it is just a side effect, because in practice they are been blocked, and yet something like this is unable to make a scratch its reputation.