251 comments

[ 0.24 ms ] story [ 17.9 ms ] thread
Bunny.net is a good alternative - they don’t have CF depth of offerings but are getting there
They don't have Cloudflare Tunnels which is almost too good to pass up.

I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.

If you're not paying, you're not the customer; you're the product.
You don't pay with money, you pay with the curses^H^H^H^H^H MITM.
They're fine for a CDN but overall their offering surprisingly immature IME. The devx for their hosted scripts/database just isn't there, and e.g. they only allow one global API key with full permissions, etc.
Yeah noticed the key thing too - that seems quite dangerous for things like DNS challenge
Like bunny.net - its still tiny compared to CF but hopefully they will grow and won't adopt the crappier bits of CF.
I tried them with our small company. They seem ... young. Support on discord is not something I can sell to our owners. We sent a ticket that activating some of their services instantly caused bad bots to scan our site, and never got a decent reply on that. Their attitude does not inspire confidence and for that reason we scrapped them as an option. Never actually found a good European option besides them, which is sad.
Like, the bad bots you see when they get an https cert issued and it becomes visible in the public logs, or something else?

Agree discord sucks.

> We sent a ticket that activating some of their services instantly caused bad bots to scan our site

You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.

There is a normal support ticket system not on Discord, which they loudly advertise for having a very good response time. The Discord server is not the primary support method
We use them en they have improved a lot in the last year. For edge services they have all the important thing like ddos protection and edge scripting. There is no replacement for Cloudflare Tunnel, but frp [1] is a good alternative.

We don’t miss Cloudflare one bit.

[1] https://github.com/fatedier/frp

Bunny is the MVP among these European alternatives. It's not just a CDN, it offers Cloudflare-style Edge scripting, Edge workers, databases (Sqlite compatible) etc.
MVP would be widely understood on this forum to mean "Minimum Viable Product", I don't think that's what you meant. Options are always good to have.
true, but MVP -> most valuable player might be even more common on the internet, interesting conundrum tbh haha
I feel like your site needs a CDN, it takes over 40 seconds to load your front page from the EU.
Since it appears to have gotten hugged to death - https://web.archive.org/web/20260908084626/https://ciphercue...

Not really unexpected, US domination of "tech" is near total, even if the sustained political will exists (and I'm not sure it will for long enough) unwinding that is the expensive work of years/decades not months.

Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

Personally I think we absolutely should, I just don't think we will.

Barring them doing something so egregiously awful we don't have the choice, Governments can move fast when they want to but efficient government scares the shit out of me because it rarely happens outside of a genuinely serious crisis.

> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

I'm thinking the opposite might be the way to go here.

We already know that "retaliation" comes from the US government regardless if you did something or not, so most of us (Europeans) have stopped pretending there is a way of preventing it.

Even more, if we piss off Trump enough, he might be dumb enough to try to block European access to CloudFlare, or something similar and maybe even dumber.

So with this, maybe the goal should actually be to try to piss off Trump and the US administration as much as possible, in order for them to start reacting and cutting off some stuff, so we (again, Europeans) basically gets forced off CloudFlare et al.

Lots of companies already finished moving away from storing their primary data in the US, lots of companies is in process of doing so (albeit some look like they'll take forever) but also lots of companies still aren't prepared for the future, would be nice if US government could make the decision a bit easier for them to make :)

While I theoretically agree, the issue is that Trump will connect economical issues to blowing up NATO Article 5, leaving NATO completely, or retracting intelligence or Starlink for Ukraine.

So for the most part, the EU has to work slowly and under the radar.

That said, my worry is that we'll be back to business as usual if the midterms look favorable. Even the urgency present during January's Greenland threats was gone after a few months. I fear that we don't have the long-term focus and planning to make sovereignty really happen. But I'd love to be surprised.

> So for the most part, the EU has to work slowly and under the radar.

How convenient. If it wasn't for the US, the EU would work really fast and in the open! That is totally believable.

That's not what I said. Both can be true at the same time: the EU works slow; political repercussions requires the EU to work slow (regardless whether they are slow or not).
Case in point: Trump just banned imports from Canada because they didn't cave to his extortion.
Trump doesn't need to block European access to Cloudflare when Europe already blocks European access to Cloudflare on weekends. In Spain and Italy. And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
lots of efficient government happens outside of a serious crisis, but then you don't notice it.
Yeah, I think only in crypto the non-us providers have a leg up, because running a node just needs an instance.
Compared to the Spanish empire, Napoleon and Hitler the Americans are but whiny children. It would be one last hurrah for my country to break away.
>> US domination of "tech" is near total.

Not quite when considering China having the tech freedom they wanted. Also switching internet services is far easier than switching physical supply chains. The only thing that might be hard to switch is the part of the interent backbone infra that is controlled by USA.

> Personally I think we absolutely should, I just don't think we will.

I think many millions in the EU want to. The problem is that the current EU "politicians" are just US lobbyists. You can see it when Leyen signed the surrender treaty with her Overlord-buddy Trump. You can not fix the EU with such lobbiysts in place - and it's not just Leyen alone. Look at Merz - the guy basically is a tool used by US companies. He is not the brightest but very loyal to the USA. More than to the people who voted for him (and now curse themselves for having made such a big mistake).

> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

You mean the US government working towards the interests of its people and economy? Which government wouldn't? It's kinda what we want it to do.

I don’t want my government to be a corporate controlled army for the big corps in my country.
I think if you think it's in the interest of the people of the USA for the country to be a cynical, overt, quixotic, childish bully on a global basis, including acting as goons on behalf of tech companies, that's an opinion you are certainly entitled to.
> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

It's not the so-called retaliation of the US government that leads to European inefficiencies like paying notaries thousands of euros to read out a contract to you (several discussions going around about this in Germany recently).

This is ultimately just a boogeyman. European governments love to blame someone else for their inefficient and bureaucratic processes that stifle innovation and are slowly becoming the laughing stock of the tech world.

If they really want a thriving tech industry, EU should:

- Normalize laws and regulations relating to commerce and online activities throughout the EU. Get rid of the notary crap. While you are at it, get rid of the impressum (why the fuck should I need to post my home address on my website?).

- Ensure that these normalized regulations are available in the tens of languages across the EU

- Invest heavily in telecom and data center infrastructure and software on a European-wide basis. The current AI bubble will likely pop but data centers and such can be reused for EU-based cloud services.

- Invite the UK back in once they are an actual economic powerhouse that can speak with one voice.

Of course none of this will ever get done because EU bureaucrats would rather be in a perpetual hand-wringing mode while blaming the Big Bad US Boogeyman for all their problems.

Upstream of all of those things is whether it's an actual priority for the ruling classes, or not. The politicians and bureaucrats are downstream of that, and physically incapable of wagging the dog.
That notary thing is very stupid but just one thing - let's not pretend the US doesn't have stupidity on that level too. DMV lines, anyone? One voting booth for an entire city because it's majority black?
Obviously, the US has lots and lots of stupid things.

The difference is that you typically don't hear "Oh we need to make slow progress on making voting easier, because the EU will retaliate". That would be absurd. We recognize that it's our own fault, i.e. the politicians that we are voting in.

Ironic that an article about a CDN was hugged to death. The free plan with a couple of caching rules could have sorted that.
I'd also be interested in share of companies using a CDN in the first place. UK has 17k sites, while France and Germany, so countries with about equal and higher population than the UK, have only 4k and 6k sites behind a CDN.

I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?

I'd be interested in what data they're using in the first place. It looks like their data is behind a paywall.

Also, funny that their page with for "Companies running Cloudflare" says there are only "887 European organisations using Cloudflare."

It’s a limitation of their dataset. If you take all domains, it definitely creates a different picture.

For both France and the UK, less than 15% of sites are behind a CDN. For both, around 95% use Cloudflare.

So in terms of percentages, there’s not much of a difference.

> The front door is not the whole stack

Hey Claude, can you move the ciphercue blog to Cloudflare so it can deal with traffic from HN?

On a more serious note, Cloudflare comes packed with features even on its free plan which makes it useful for any size website. For a real business it's one of the cheapest options for DDoS protection on the market. Some years ago you would have paid a fortune for Akamai or Level3 to help keep you online and now you can get by on a $200 a month plan for a small business.

Do you get paid commission for comments like this? Genuinely feels like an ad-read
I was explaining why I believe it's a super popular service. I have no affiliation or stock, just a regular user.
I think they articulated the underlying issue well. Cloudflare is too attractive for individuals and small businesses. For instance, my personal website has a healthy amount of traffic, but means nothing at CDN scale. I considered moving to a EU CDN company, but they all have per GB/TB pricing. It would cost me nothing now, but what if my site comes under attack or someone starts hotlinking a large file? So, I stay with Cloudflare because with their free plan I don't have to worry about such contingincies.

I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.

My PM buddies speak like this about any subject.
> now you can get by on a $200 a month plan for a small business

You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.

> you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you

This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

I think their delusion is probably in what they consider a small business. A lot of people on here, given their work experience, think of small as something with a few hundred employees.
Given that we're on HN I probably should've said startup, though depending on the business itself it's not unrealistic for some of those 200-400 employee companies to sit on a free Cloudflare plan if their entire website is static + a back-office CRUD app.

If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.

> ... think of small as something with a few hundred ...

Yes, plus a strong bias toward IT-heavy businesses. Vs. if my company is doing commercial landscaping, or machining gears for automobile transmissions? Several hundred employees still gives me no reason to pay much for web hosting.

> Most websites don't need a CDN nor DDOS protection

A CDN not, and certainly not a global one.

But unfortunately, you absolutely need DDoS protection, especially as a business. Too many shady actors and skiddies pulling off extortion/protection racket scams - a complete and utter lack of telco regulations, AI, tons of unsecured IoT devices and shitcoins truly have made for a terrible mixture.

Sure, a 50€ a month server at Hetzner, OVH or whatever is more than enough to host a website. If you're not running some NodeJS garbage, a 5€ VPS can be enough. But at the first sign of you being targeted by a troublemaker, your hoster will cut you off just to protect their other customers.

The internet is a dangerous place and some people will be dicks even if you aren't making any money. Most hosts will show you the door the someone puts their crosshairs on you. Some small businesses like gaming are disproportionately effected.
Nobody needs DDoS protection... until they do. It only takes 1 disgruntled person with a few dollars to take down a cheap server for days.
If it's one thing I learned from my old web hosting business, it's that any website can be in immediate need of a CDN or DDOS protection at any given time. It's the only business where my customers were randomly attacked for seemingly no good reason. It's also why I got the hell out of that business.
Naive question: How important is it to use a CDN in the first place? Why can't you just serve the content yourself?
Depends on your use case.

If you have a very inefficient backend (maybe legacy project?), you have massive amount of traffic (say 100K req/s or above) or you really must have sub-500ms latency absolutely everywhere in the world, then it might make sense to slap a CDN (or similar) on top of that.

In pretty much any case outside of that, it makes no sense to waste the time, money or effort on CDNs. But, all the CDN companies seemingly have convinced half the internet that you absolutely must use a CDN, otherwise you'll get hacked/broke/killed/sent to the moon, and they've been successful with this campaign too seemingly.

How does a cdn makes you backend faster or your latency better ? I thought it was only for distributing static assets and managing DDOS. If it is for cachable but dynamic content install reverse-proxy cache it will fly.
This article being down/slow is a great response.
Not to discount the experiences that other have, but the site loads fine for me.
Because an average request would have to travel half the globe, so setting up a simple HTTPS connection would already take a second. That's completely unacceptable for static content.

Not only would transfer be slow, they would also be much more pressing on the network as the request would occupy huge stretches and many interconnects and switches.

Furthermore, it hardens the website against DDoS and adds robustness for regional failures.

Minority of sites have global traffic. This is especially true for non-English sites.

So, while average request may have to travel quarter (not half) of the Internet globe, median request from the set of requests that matter has much lower latency.

Barcelona to Stockholm is about 65ms, ~35ms to Amsterdam, ~43ms to Frankfurt.

HTTP/3 is ubiquitous, you don’t get TCP handshake penalty anymore in major browsers.

It depends on what you're trying to serve, but it's used to either save you money or as an insurance (or both). You don't need a CDN overall. But if you grow large enough, at some point you'll run into one of these three situations:

- Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead.

- Your customers on the other side of the world start complaining that the resources take ages to load.

- Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.

Reduces latency when the cached content is served from a local cdn pop, allows you to absorb some level of DDoS, can absorb traffic spikes more easily so infra can be more static, reduces load on server if assets are dynamically generated on the backend but can are cacheable, some senses can lead to simpler deployment as you serve assets from an object bucket, so no need to deal with keeping that data in your cluster, but that's minor. There are downsides too, cost, over caching, privacy/security perhaps too.
In most cases, it's not important and you can, but you are bandwagoning and/or being fearmongered to.
Europe sucks at tech?

Well I’ll be damned.

I would’ve never expected that.

How did you extrapolate that leap of logic? Maybe we suck at business.
Yeah because it's priced well and it works. It's a no-brainer. (Also if it does go down, well so has everyone else so no big deal)

Also in this list of GOATed companies: Tailscale, Ubiquiti.

(comment deleted)
The problem is that we have spent 40 years adopting US technology, across multiple generations of software developers and decision makers, while everyone was supposedly on the same side.

It will take similar amount of years to go back into the cold war heterogeneous computing landscape of the 60, early 90s.

This assuming there would be an willingness across all European countries to actually push for that, and not jump out when it gets too hard and search for compromises instead.

This is why most sovereignty initiatives focus mostly on SaaS products and hardly on actual computing devices.

Even if EU countries want to push for their own solutions, the biggest problem is the capital. The governments cannot fund this with tax payers money because they have other critical problems to solve and private companies only go far if they can make a profit.

Only time will tell how far this sovereign movement would go. Maybe when the US would have a president/government from the Democratic Party someday in the future. EU would cozy up again to US and go back to how things were. There’s no permanent enemies or allies when it comes to politics and at the end of the day it all revolves around money

> The governments cannot fund this with tax payers money because they have other critical problems to solve

The governments can's solve this problem because the entire economic model of the EU is that the core exploits the periphery, who don't have a currency that they can weaken as a response. If they had a strong democratic central government and a real central bank in the EU, they'd be forced to make transfer payments to the weaker members, and to bail them out (losing the leverage to make elite demands on them.)

The EU as a whole could easily solve the problem, they have the population, the talent, and the infrastructure. They're just really docile from the CIA and their own elite cliques working on them for the better part of a century.

> Only time will tell how far this sovereign movement would go.

There is none. Blah blah blah in the media isn't a "sovereign movement." It's a campaign to get you to vote for the same middle of the road radical centrist neocons served on a substrate of normie-relaxing anti-Trump rhetoric.

The current Europe strategy seems to be to pay software engineers less money and hope for a superior product. I'm not sure how you'd catch up when some of your engineers literally make less than our fast food workers.
I rather have 30 day vacations, a proper life with 40h work week, healthcare, union membership, than SV salaries, which are nontheless an exception, most of the developers, that aren't even properly accredited Software Engineers, get the same salary as most office workers.

In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?

I'm American and I take 30 days of PTO a year. I get paid the national median for pay, but that still puts me in the top 10% of _household_ incomes for my state. I have good healthcare and benefits. Hell, I got sick last year and took 2 months off from work paid because my company has the policies to cover that and then I came back and it was fine.

Like, I find SV culture and living to be a cancer, but I'm just saying as someone who doesn't live in a top 10 city in the US with a MCOL, I struggle to think of how working as a software engineer in the EU would be better.

It's been over 10 years since that 2 weeks PTO nonsense applied to tech. I don't even have a fancy job. I work for a bank.

Your bosses can only afford to give you that and high salary because they aren't giving it to everyone.
> I rather have 30 day vacations, a proper life with 40h work week, healthcare, union membership, than SV salaries

This is an appeal to mediocrity and it doesn't really hold when comparing EU to Silicon Valley tech jobs. Young engineers in the Silicon Valley (or NYC, or Seattle) have excellent health care, generous vacation and other benefits, and they also make substantially more money.

Why would a young, ambitious engineering graduate care about taking 30 days off when they have the opportunity to work on frontier tech that is only available in the US? And make an absurd salary doing it? Healthcare is also less of a concern because 20 somethings and 30 somethings barely use any social benefits anyway. And like I said earlier, they also have exceptional private health care through their employer.

This claim that the European lifestyle is somehow better despite the extreme salary difference really just doesn't hold when comparing to early/mid-career tech workers in the US.

That is what late capitalism expects, 20 something year olds willing to do whatever it takes to get that dream job, changing the world with code, as if.

The games industry and Hollywood have that lesson very well thought out.

> In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?

https://buc-ees.com/careers/

Tale as old as time (or at least as the 1970s): nobody ever got fired for buying ~~IBM~~ Cloudfare / AWS / Azure.
It's actually a great service though.
It's also a great protection racket. They host many DDoS provider sites and protect them from law enforcement.
Someone's eager to downvote this, but it's been known for a long time and still happens in obvious ways. First page of results for booter services contains https://zeusstress.com/ which is hosted by Cloudflare (yes yes, ceo will send lawyers to say they only proxy not host - doesn't matter in practice)
.. 9 out of 10 unhappy customers are currently unable to cause any blame, because they cannot even reach customer service because they are getting the "bot" treatment.
But isn't a CDN a commodity? I.e., you can switch to a different one with almost no effort.
How does that quip go again…there are only two difficulties in computer science, cache invalidation, naming things, and counting.

Going from one CDN to another can be infuriating even at a surprisingly small scale. Mostly (imo) from caching semantics and counting.

It's not really a commodity when Cloudflare is often cheaper, simpler and provides a better service compared to it's competitors.

For it to be a commodity there would be no good reason to pick Cloudflare over any alternative and this absolutely isn't the case.

Depends how deeply integrated it is. Cloudflare offers a web application firewall that can quickly become complex, alongside features like custom routing rules, input parsing, custom headers, etc. As soon as you start integrating any of those into your environment, migration becomes more difficult fast.
In the late 90s and early 2000s the NSA and other US intelligence agencies underwent massive efforts to basically privatize the gathering of intelligence. Its a lot easier to fund your "total information awarness" initiatives via public markets and private investors than to ask congress for money to do so. So they did just that.

"In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year."

--Matthew Prince's Wikipedia page.

Dont for a second think cloudflare's generous free tier offerings are out of the goodness of their heart. They're a giant fkin MiTM project for the US governemnt. And of course, cloudflare isn't the only one.

Cloudflare is the best security company In the world.
It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. And they have a few other things that aren't half bad to use with pretty generous freemium layers.

We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.

We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.

I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.

Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.

The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.

Or clouds in general, its all wishful thinking and pinky promises.

What about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence
Pick your poison
You have to be a registered Chinese business entity with a CCP director on your board to legally use that
"We've known it has an always-on microphone and speech-to-text for over a decade"

Literally? What is the reference here?

Is there any evidence of this
If the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying

For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost

The damage of being spied upon, if there is any, is already done

1. It's not clear why commenters are only concerned about intelligence agencies

> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.

  > The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.

I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.

Do you really need Cloudflare for something like this?
It's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site happens on Cloudflare.

And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.

He doesn't, but someone told him it was good so he uses it. This is Cloudflare's main audience, just like McAfee's.
Useless snark.
Who told you you need a k8s cluster to serve 5 HTML pages?
I believe this was a joke.
Poe's law applies. Many people actually think that.
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.

Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.

I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.

Not all traffic, but any.

I agree it doesn't matter for most smaller entities, but it's relevant for larger entities.

They also certainly have many heuristics running. Your corporate website is interesting because it reveals who your suppliers and customers are, and all of your passwords. They don't have the manpower to scrape this manually so they scrape it automatically
The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.

This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.

https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...

There's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting here.
Of course, but the comment I was replying to stated:

"the NSA learns everything there is to know about you and your customers"

Which implies that they are looking at it all and records it.

The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.

They are actively scanning all of it, looking for interesting stuff.
How do you do DPI on hundreds of PBs a day? Explain the process that would allow you to "look for interesting stuff".
I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.
If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.

That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.

Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.
According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.
if your threat model includes the NSA i don't think your choice of CDN is going to make a difference
>talks about how bad Cloudflare is with imaginary threats

>doesn't offer an alternative and leaves

Every. Single. Time.

The alternative is nothing. You don't actually need cloudflare.
And get hammered by bots, scrapers, and bad actors?
It's not like cloudflare actually blocks them. Have you tried?
Yeah and it works, that's why I keep using it
Also CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog. Also CF raise checks on pages that I opened few hours ago and reload.
> Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well.

You don't need to register your domain with them. Only make their DNS servers your domain name servers.

To be clear, we migrated our domains to them after moving our websites there, not before. Our old registrar charged more.
I also believed that, but at least for India, this doesn't work in practice. Unless you atleast do the 25$ pro plan, cloudflare routes even india-to-india, hell, even mumbai-to-mumbai and aws_mumbai-to-cloudflare_mumbai traffic via Marsaille!! Not even Singapore. The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.

I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved.

Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare).

Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan.

Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.

Transit in some countries, like India, genuinely is that expensive. Keep in mind it doesn’t cost Cloudflare any more to serve Indian traffic from Marsaille than to serve non-peered French traffic from that colo - they aren’t paying the cost of getting traffic between India and France.
The traffic still has to flow from an india provider to the international leg and back via the domestic provider.

In anycase, then they should document it clearly that they have unacceptable insertion latency in india and the free plan is entirely unusable for india. Instead of advertising '10 pops in india!!'

> The traffic still has to flow from an india provider to the international leg and back via the domestic provider.

Right, but Cloudflare doesn't have to pay for it in that case. If Cloudflare sends you to their Indian POP, then they have to pay their Indian service provider for traffic. If they send you to their France POP, then they have to pay their French ISP for traffic. The Indian provider cannot claim any of Cloudflare's traffic in that case, because the Indian service provider wouldn't have any relationship with Cloudflare

This is very standard for places with high ISP costs, like South Korea and India. You can see a lot of discussion about it online. I agree with you that Cloudflare should be more transparent if / when they make different routing decision for Free/Pro plans based on bandwidth costs, but I don't think their decision itself is unreasonable at all. Indian bandwidth is very expensive.

You would think Cloudflare would be in a position to do something about it, like they did with several cloud services in their Bandwidth Alliance. It would be a win-win-win for networks to interconnect better in India, it just can't happen stepwise because any individual step is a lose for somebody.
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.

IMHO, it's not that hard to believe.

a) Every hosting provider I've looked at prices for charges significantly more for bandwidth from their Indian locations.

b) In the US, transit providers basically never charged different rates for different destinations [1]. In Europe, it's typically rare, sometimes transit to the local incumbent telecom is more, sometimes there's a different rate for Europe or non-Europe, but there won't be a specific destination charge for India, it will be part of a blended rate. Otoh, east Asia often has separate rates for specific nearby countries and India is likely to be one of those...

Transit prices in Europe are pretty low compared to prices in India, so the blended price being less than the India direct price is not surprising to me at all.

[1] gcp premium does charge by destination, but the premium transit price is pretty close to their price for cross location traffic to something near the destination + non-premium traffic from that location... Which is more or less what their premium network egress is.

It's basically that payment flows towards the core of the network, which is Europe and America. If you're the first Indian ISP, you have to pay a European ISP for an upstream connection - they won't pay you. And that persists and becomes "just the way things are done". It can only reverse if there are significant websites in India that Europeans want to access, then the European ISPs will be getting more value than the Indian ones and the Indian ones will be able to demand payment.
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.

Your Indian ISP is paying a French ISP for both directions of that traffic, which makes it cheap at the French end. Were it India-to-India, Cloudflare would have to pay your ISP.

Re: complexity. I used to find AWS unusable, then I realized I can just tell Claude Code or Codex to manage it. This makes it into an entirely different product, where "Cloudflare is easier" doesn't really matter. Now price is the only barrier.
Before I went European sovereign for my own personal stack I used Cloudflare for hosting static and somewhat dynamic websites and it has become really nice the later years. There is almost no mention of "regions" in Cloudflare. Your content and code runs globally by default. With traditional clouds you need to think about how you distribute your application. At least that is my experience. Maybe they provide global CDN for global distribution of static content. But serverless containers and databases more or less run in a single region by default. And if you wish to distribute stuff it is on you to plan the architecture behind that.

Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well.

A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.

What do you use as a European CDN atm?
You know, the pricing page lays the features out pretty nicely, surprised that they're not way more popular: https://bunny.net/pricing/

Though I do remember some storage related complaints here on HN, other than that I haven't seen much about them on this site either!

Currently I don’t use any CDN. I just host everything on Scaleway on VMs and serverless. Works pretty well for my use, but I imagine latency is bad for South Americans. I’ve looked into Bunny and I think that is the closest you get to Cloudflare’s offerings.
yeah, I have been amazed at what I could do for free, and then amazed at how much more powerful it got for 5 bucks a months. Cloudflare is killing it in terms of value for small websites (and features and reliability).
Google Cloud and AWS are complex because they're meant for hosting complex apps and infrastructure, they're not really worth it for simple static websites.
I'd argue it's even more worth it for static sites, where CDNs and buckets will vastly out-perform hosting a static site on an instance yourself because of replication, caching, and geographic routing
But they don't, because your bucket is still in a location, and goes through more complexity layers.
I cannot visit most crimeflare sites because I just get endless captcha loops.
The trick is to use the most normal hardware, software and network connection you can think of. Which I assume you aren't doing for ideological reasons, which is fair.
My ISP seems to frequently rotate IPs with other people who can't behave, so my IPs always have garbage reputation... that probably has a lot to do with it as well.

How do I know this? I have received reports from various websites (and manually queried some public block lists/RBL/etc.) that my IP range was blocked due to all sorts of different things like open proxies, CSAM etc. even if I've never visited that site before, and I know just from being a neteng that that such traffic is not originating from my devices/router and I don't have any observably compromised devices or suspicious traffic when monitoring it.

This is common for third-world ISPs. Cloudflare would never block, say, Comcast, but they have no qualms about blocking the few largest ISPs in Brazil because who cares about Brazil? Those countries also have IP address shortages because we refused to move the whole internet to ipv6 yet, and may share just a few addresses per city.
AWS isn't aimed at regular people, it's infrastructure as a service. You use it because you need a thousand servers, or a redundant system that can survive a data centre exploding.

If you just need a single server that you don't care about then it's way cheaper to just own it yourself. You probably don't need 99.999999999999999% guarantees for your data, but if you're a bank then you do need those guarantees because losing all of your documents would be disastrous.

Normal people aren't worth anything to them. A company might spend a million a month with AWS, to get that with normal people you'd need at least a hundred thousand customers. And those people are going to spam you with tickets and do silly or illegal things. They're just not worth it. They obviously won't turn money down, but it's not a growth area for them.

I 99% agree, but have conflicted felings. There's a mix of services. S3 is and was an amazing resource for normal people. Extremely reliable cloud storage for backup, for distribution, for anything, well, it's a dream. I prefer Cloudflare's offering there in every way, but AWS defined the product category (with its correspondingly ugly API like every single AWS service), and met a core need for many many people. With S3, if you need a ton of storage, it's a terrible deal, and you shouldn't use it. But for a couple hundred gigabytes, go for it.

EC2 is similarly great for normal people as long as you only need a part-time server for a short amount of time. It's hard to beat with a VPS.

Once you get into load balances, event queues, and all the rest of AWS services, well, that's all there to drive lots of money to AWS and to contractors and busy work. MAYBE RDS is a good deal for somebody who really wants to pay somebody else for a managed database. Which turns out to be a ton of users of databases!

Cargo culting is probably the biggest reason people use AWS.
Registering domains on Cloudflare is great. They do it at cost as far as I can tell and more tlds have been added. I don't have to use a nasty local registrar with dark patterns anymore.
so instead of developing actual competent solution, European complaining about why US tech dominate ?????

what stopping europe from using their home ground solution ??? nothing

this is just a skill issue take

It is better for europeans to hide behind american companies. US has stronger laws, free speach, and can protects european citizens from censorship and draconian laws.

There was investigation in Germany against someone who called politician "fat". UK "hate speech" laws are very well known.

For any sort of europen sensitive content, I would use US infra.

And the same way, US companies should use german hosting...

Is it satire ? Laws apply to the publisher not to the TLS endpoint.
This has to be rage bait, right? Ever heard of GDPR? How about ICE?
The EU needs to stop giving money to the USA in general. They contribute to their own demise by doing so. Canadians understand this so much better than the EU, so the only logical conclusion to be made is that the EU is currently controlled by US lobbyists. This would explain about 80% of the issues; the remaining issues are inertia within the EU, but it also isn't made any easier when the US government constantly favours US mega-corporations ruthlessly infiltrating and abusing other markets.
Cloudflare interstitial pages are becoming the new cookie / GDPR pop-up for me. Remember when the internet used to be good?
Unfortunately that one's on the operators. I can complain for days about CF, but nobody is forcing the companies to default to giving everyone a managed challenge page. Some do, because either can don't care or don't realise the extra cost.
Same but they're so much worse than cookie banners...
My employer uses CDN77. Only for serving static resources.
But do they offer even 10% of the features Cloudflare offers to free customers? To imply that Cloudflare is merely a fancy CDN is to miss the whole point.
It's the same issue as being cloud agnostic.

If you use their unique features, you're locking yourself in. Is it worth it?

I get it. I’ve consciously avoided that exact trap with AWS. But Cloudflare aren’t giving me “features” so much as they’re allowing my site, which is routinely DDOSed, the ability to remain online at all.
You have to ask why they're so "generous" with giving away free services.
Looking back over the past 3-ish decades, becoming utterly dominant in some part of "essential" stuff on the internet has a way of paying off big.

Or, they discuss their free stuff at length here - https://www.sec.gov/Archives/edgar/data/1477333/000147733326....

(That is Cloudflare's 10-K for calendar 2025 - scrutinized by serious investors, and with heavy penalties for lying.)