27 comments

  • jillesvangurp 1 hour ago
    It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. And they have a few other things that aren't half bad to use with pretty generous freemium layers.

    We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.

    We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.

    I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.

    Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.

    • pocksuppet 1 hour ago
      The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
      • esperent 1 hour ago
        > The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers

        You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?

        If so, what's your source for that claim?

      • thorbutt 1 hour ago
        That doesn't seem unique to Cloudflare though
        • cassianoleal 58 minutes ago
          No, but nothing comes close to their breadth and scale.
      • aranelsurion 45 minutes ago
        > The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

        I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.

      • kakacik 1 hour ago
        If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.

        Or clouds in general, its all wishful thinking and pinky promises.

      • CommanderData 1 hour ago
        Is there any evidence of this
        • bcye 59 minutes ago
          Well it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
          • CommanderData 55 minutes ago
            The reputational damage for CF would be intense.

            Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.

            • samlinnfer 48 minutes ago
              They already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.
      • lukan 1 hour ago
        "We've known it has an always-on microphone and speech-to-text for over a decade"

        Literally? What is the reference here?

    • dizhn 1 hour ago
      > Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well.

      You don't need to register your domain with them. Only make their DNS servers your domain name servers.

  • noir_lord 2 hours ago
    Since it appears to have gotten hugged to death - https://web.archive.org/web/20260908084626/https://ciphercue...

    Not really unexpected, US domination of "tech" is near total, even if the sustained political will exists (and I'm not sure it will for long enough) unwinding that is the expensive work of years/decades not months.

    Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

    Personally I think we absolutely should, I just don't think we will.

    Barring them doing something so egregiously awful we don't have the choice, Governments can move fast when they want to but efficient government scares the shit out of me because it rarely happens outside of a genuinely serious crisis.

    • zkmon 1 hour ago
      >> US domination of "tech" is near total.

      Not quite when considering China having the tech freedom they wanted. Also switching internet services is far easier than switching physical supply chains. The only thing that might be hard to switch is the part of the interent backbone infra that is controlled by USA.

      • shevy-java 1 hour ago
        You are not living in Europe, right? Because while I agree that China is a problem, the USA is a much, much bigger problem for Europeans than China is right now. It's mostly the USA that wants to depict China as the main problem when in reality the USA behaves in a hugely aggressive colonial manner. Trump just makes this more obvious, but that has been the case way before Trump already.
        • aivisol 10 minutes ago
          Please speak for yourself. Not everyone in Europe thinks US is bigger problem than China. For many China is far bigger geopolitical threat since they openly support Russia in its current war.
          • atakan_gurkan 0 minutes ago
            Honestly, I had the impression that the current US regime also supports Russia in its current war. Did they not ask Ukraine to give the already occupied land and then some? As far as I remember, that was in a form almost like an ultimatum, too. China might be a bigger threat, but I find it hard to believe that this would be the reason.
          • nonethewiser 5 minutes ago
            I have no idea how people can overlook this. I mean I have some idea. A sort of “enemy of my enemy is my friend” meets “leopards ate my face.”
        • thesmtsolver2 1 hour ago
          What? Go ask almost anyone in Asia outside Mainland China.

          They all consider China to be the aggressor because they are. E.g., Tibet or India.

          • JumpCrisscross 42 minutes ago
            I think it’s fair to say the U.S. and Russia are Europe’s principal geopolitical adversaries, today, while for anyone in Asia or Oceania it’s China. (Africa and South America are being weirdly carved up—it’s not particularly clear who is trying to colonize versus trade with them.)
          • hvb2 45 minutes ago
            For European governments that have their email and such running with Microsoft, it's quite the signal when individuals lose their email because the US doesn't like them. See international criminal court.
          • kakacik 1 hour ago
            Both claims can be correct. US became Europe's adversary, quite active and pushy. We don't know yet where the end of backstabbing and shitting on us lies, we can easily have a war ie over Greenland within 2 years.

            China? It wants to sell its cars here, and thats about it. Incomparable.

          • DarmokTanagra 42 minutes ago
            [dead]
        • carlosjobim 17 minutes ago
          When Trump talks about doing the anti colonial thing and withdrawing troops from European soil, the response is outrage.

          But I've learnt that iPhones and social media is American imperialism, but thousands of troops in dozens of military bases on European soil is not, somehow.

          • watwut 7 minutes ago
            Trump is modern colonialist. He is not talking about doing "the anti colonial thing" ever, instead he is bragging about making America colonial.

            > and withdrawing troops from European soil, the response is outrage.

            The response to withdrawing troops from European soil was mockery and frustration from army that is loosing valuable bases. Either way, it is not an anti-colonial thing.

            > thousands of troops in dozens of military bases on European soil is not, somehow

            Presence of allies is not colonialism. Threat to annex greenland is. Threat to annex Canada is. Keeping pet dictator in Venezuela and taking their oil is.

            When Germans, France and other European soldiers came to Greenland to defend against an American threat, it was not colonialism either.

    • jonnybgood 1 hour ago
      > Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

      You mean the US government working towards the interests of its people and economy? Which government wouldn't? It's kinda what we want it to do.

      • plufz 1 hour ago
        I don’t want my government to be a corporate controlled army for the big corps in my country.
      • thesmtsolver2 1 hour ago
        Didn’t you read the memo? Only European govts or China can act in the interests of their people and companies but if the US does that it is immoral.
        • simondotau 38 minutes ago
          I agree with what you’re inferring. But that said, there’s a valid argument to be had that—for some things—your own government is a unique threat that other people’s governments are not, or less so.

          I’m Australian, and if I was worried about the practical legal risk of being tracked online by a government, it’s mostly concern about my own. A foreign friendly government is mid tier: it’s unlikely that five eyes is an intel firehouse, so it’s unlikely for your petty domestic matter to be communicated. A foreign hostile government is probably safer if you’re committing domestic crimes.

        • lukan 1 hour ago
          One difference is, EU or China don't act as global hegemon and claim to promote freedom, democracy and free markets for everyone.
          • JumpCrisscross 40 minutes ago
            > EU or China don't act as global hegemon

            France has global geopolitical projects, as does China in South America, Central Asia and Africa. Both export arms into conflicts and conduct global intelligence operations.

            • lukan 3 minutes ago
              Sure, some also still dream secretly of a french global empire and french as the rightful lingua franca reinstalled. But de facto they ain't a global hegemon - the US is. And people were mostly fine with it, while they were not obviously abusing their position of power for themself.
          • ExoticPearTree 43 minutes ago
            > free markets for everyone

            should read as "everyone the US likes", not everyone everyone.

    • k__ 1 hour ago
      Yeah, I think only in crypto the non-us providers have a leg up, because running a node just needs an instance.
    • bryanrasmussen 1 hour ago
      lots of efficient government happens outside of a serious crisis, but then you don't notice it.
    • embedding-shape 2 hours ago
      > Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.

      I'm thinking the opposite might be the way to go here.

      We already know that "retaliation" comes from the US government regardless if you did something or not, so most of us (Europeans) have stopped pretending there is a way of preventing it.

      Even more, if we piss off Trump enough, he might be dumb enough to try to block European access to CloudFlare, or something similar and maybe even dumber.

      So with this, maybe the goal should actually be to try to piss off Trump and the US administration as much as possible, in order for them to start reacting and cutting off some stuff, so we (again, Europeans) basically gets forced off CloudFlare et al.

      Lots of companies already finished moving away from storing their primary data in the US, lots of companies is in process of doing so (albeit some look like they'll take forever) but also lots of companies still aren't prepared for the future, would be nice if US government could make the decision a bit easier for them to make :)

      • microtonal 1 hour ago
        While I theoretically agree, the issue is that Trump will connect economical issues to blowing up NATO Article 5, leaving NATO completely, or retracting intelligence or Starlink for Ukraine.

        So for the most part, the EU has to work slowly and under the radar.

        That said, my worry is that we'll be back to business as usual if the midterms look favorable. Even the urgency present during January's Greenland threats was gone after a few months. I fear that we don't have the long-term focus and planning to make sovereignty really happen. But I'd love to be surprised.

        • eckesicle 1 hour ago
          I asked the Swedish Prime Minister this question almost verbatim on Reddit two days ago and he responded. The answer was ... understated.

          https://www.reddit.com/r/sweden/comments/1w8p0z4/comment/p84...

          • embedding-shape 1 hour ago
            Oh, I missed that. Interesting non-answer regarding AI, seems almost obvious by now they don't even consider it a concept in the real world. Back when I lived in Sweden the politicians were already pretty disconnected from the average person, but in regards AI they seem to be intentionally avoiding it and sleeping on it?
          • pocksuppet 1 hour ago
            Machine translation and login-wall unblocker:

            Question:

            > Hello, Sweden (and Europe) is facing three almost existential risks over the coming term of office that we have never really had to take a position on to the same extent before. The climate. A new UN report from last week has shown that El Niño will probably contribute to between 3 and 4 degrees of warming in addition to last year's heat wave. I live abroad and we had 44 degrees warm for a couple of days this summer (2025). It was also over 30 degrees in Norrbotten for over 3 weeks. Unbearable. How do you prioritize this against the many other budget items? How should we now prepare for what will inevitably lead to an IPCC 3-4 degree scenario?

            > AI. AI development is just going faster and faster. At my workplace, we have already replaced many employees with AI-driven processes. We buy all our computing capacity from the US and China. There are no European alternatives and it is not possible to buy Swedish. What do you want to do to, at the European level, prevent us from ending up in the AI lap of the US and China in 5 years? Where should we buy chips from when all manufacturing takes place in Taiwan, Korea, China and the US? We risk a situation where Swedish office workers are rarely replaced with US AI tokens. Surely this must be an initiative at EU level?

            > American foreign policy. Trump's second term has been tumultuous, to say the least. We were probably as close to the brink of war in Europe (Greenland) as there is in living memory. Trade agreements are being torn up, sticks are being put in the works for Gripen agreements, etc. Even when he is gone, the illusion of America as a close ally has probably finally been broken in the eyes of many Swedes, myself included. What do you want to do to reduce Sweden's and the EU's dependence on foreign superpowers?

            Answer:

            > There is a lot in this. A completely unique geopolitical time - both militarily and economically - presents a small country like Sweden with important choices. NATO was one of them. We are now cooperating with all our neighbors around the Baltic Sea, for example our own defense build-up, another example, the largest since the 50s. And all the new free trade agreements when the United States messes up world trade.

            > The climate is also one of these, and what the EU is now doing together is the single most important thing, in parallel with Swedish fossil-free energy. We can make ourselves completely national energy independent with the new Swedish nuclear power programme. German energy policy, I think, proves why this is needed, in addition to the wars in the Middle East.

            > EU: no single EU issue is more important than our support for Ukraine and increasing European competitiveness in relation to both the US and China. And it starts with the internal market - where 70 percent of all Swedish goods exports end up. If it can be as good for services including digital services, it would be good for both the EU and Sweden. But I am genuinely concerned that Europe is lagging behind.

            > last China: we will have an intense autumn regarding a common European response against China to get "level playing fields" when it comes to trade. Today's situation is not sustainable. even extremely free trade-friendly countries like Sweden see this. we should not have protectionism but the same opportunities for the EU in China as for China in the EU. We are not there now.

        • philipallstar 1 hour ago
          I don't think the EU has the capability to work fast and just is opting not to.
        • embedding-shape 1 hour ago
          > Even the urgency present during January's Greenland threats was gone after a few months.

          There are troops deployed on Greenland right now ready to defend the island. The threat is not gone from the minds of the people there or in the rest of Europe just because you stopped reading about it on CNN or whatever.

          Edit: I got curious if this part is even possible:

          > leaving NATO completely

          Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it. It also prohibits federal funds from being used to carry out an unauthorized withdrawal.

          Seems some parts of the US has indeed managed to setup defenses against such idiocracy.

      • pocksuppet 1 hour ago
        Trump doesn't need to block European access to Cloudflare when Europe already blocks European access to Cloudflare on weekends. In Spain and Italy. And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
        • embedding-shape 1 hour ago
          Great, more misinformation. "Europe" doesn't block access to Cloudflare on weekends in either Spain nor Italy. Source: I live in Spain, and I'm affected by the blocks you're referring to, that happen because of shitty Spanish judges forcing Spanish ISPs to block access to specific Cloudflare properties.

          Why not take even two seconds to check if what you're guessing about, might actually be correct or not? Or the goal is just FUD here?

          > And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.

          Maybe because the impact of these blocks aren't as large as you allude to? Things change, these blocklists get updated. What was blocked 6 months ago no longer is, when these anti-piracy blocks happen.

          Don't get me wrong, I don't agree with these blocks at all, and AFAIK, they break both national laws and wider "rights", but lets not pretend it's bigger than what it is in reality.

    • shevy-java 1 hour ago
      > Personally I think we absolutely should, I just don't think we will.

      I think many millions in the EU want to. The problem is that the current EU "politicians" are just US lobbyists. You can see it when Leyen signed the surrender treaty with her Overlord-buddy Trump. You can not fix the EU with such lobbiysts in place - and it's not just Leyen alone. Look at Merz - the guy basically is a tool used by US companies. He is not the brightest but very loyal to the USA. More than to the people who voted for him (and now curse themselves for having made such a big mistake).

    • expedition32 1 hour ago
      Compared to the Spanish empire, Napoleon and Hitler the Americans are but whiny children. It would be one last hurrah for my country to break away.
  • cbg0 2 hours ago
    > The front door is not the whole stack

    Hey Claude, can you move the ciphercue blog to Cloudflare so it can deal with traffic from HN?

    On a more serious note, Cloudflare comes packed with features even on its free plan which makes it useful for any size website. For a real business it's one of the cheapest options for DDoS protection on the market. Some years ago you would have paid a fortune for Akamai or Level3 to help keep you online and now you can get by on a $200 a month plan for a small business.

    • embedding-shape 2 hours ago
      > now you can get by on a $200 a month plan for a small business

      You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.

      • cbg0 2 hours ago
        What you're paying for is business continuity, not for them to host your site. I know you can host the site itself on much cheaper infrastructure.
        • cyphar 1 hour ago
          If your site is static you can host it on CF pages for free with unlimited* egress.

          * of course it's not unlimited unlimited but I've not heard of anyone being cut off.

      • viraptor 1 hour ago
        > you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you

        This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

        • embedding-shape 1 hour ago
          > Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

          Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.

          But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.

          • viraptor 1 hour ago
            It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service.

            > and I don't think people should default to trying to prevent them.

            It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.

            Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)

          • cbg0 1 hour ago
            I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada:

            https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...

            • embedding-shape 1 hour ago
              That graph is useful for the people who think DDoS is the biggest issue or even a big issue typically: https://www.bdc.ca/globalassets/digizuite/55250-canadian-sma... "Percentage of Canadian small businesses that have experienced a cybersecurity incident"

              The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.

              • cbg0 54 minutes ago
                What exactly are you arguing? I already said 5%. Your personal experience of DDoS being super rare doesn't seem to match the real world.
                • embedding-shape 48 minutes ago
                  Literally the graph you posted agrees with me. Most "cyber attacks" are phishing according to that graph, which I'd argue is less of an technological attack and more social engineering.

                  Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.

                  > Your personal experience of DDoS being super rare doesn't seem to match the real world.

                  What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.

          • pocksuppet 1 hour ago
            For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days.
          • Hikikomori 30 minutes ago
            Wouldn't most udp reflection attacks be bigger than your pipe?
          • theideaofcoffee 38 minutes ago
            Dozens and dozens of times. And having the bigger pipe has always saved it, along with the supporting infrastructure to churn through that traffic.

            > But again, those sort of attacks seem to happen seldom

            [citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.

      • bryanrasmussen 1 hour ago
        I think their delusion is probably in what they consider a small business. A lot of people on here, given their work experience, think of small as something with a few hundred employees.
        • cbg0 1 hour ago
          Given that we're on HN I probably should've said startup, though depending on the business itself it's not unrealistic for some of those 200-400 employee companies to sit on a free Cloudflare plan if their entire website is static + a back-office CRUD app.

          If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.

    • dwroberts 2 hours ago
      [flagged]
      • microtonal 1 hour ago
        I think they articulated the underlying issue well. Cloudflare is too attractive for individuals and small businesses. For instance, my personal website has a healthy amount of traffic, but means nothing at CDN scale. I considered moving to a EU CDN company, but they all have per GB/TB pricing. It would cost me nothing now, but what if my site comes under attack or someone starts hotlinking a large file? So, I stay with Cloudflare because with their free plan I don't have to worry about such contingincies.

        I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.

      • cbg0 1 hour ago
        I was explaining why I believe it's a super popular service. I have no affiliation or stock, just a regular user.
      • glimshe 1 hour ago
        My PM buddies speak like this about any subject.
  • Havoc 2 hours ago
    Bunny.net is a good alternative - they don’t have CF depth of offerings but are getting there
    • jarco 1 hour ago
      I tried them with our small company. They seem ... young. Support on discord is not something I can sell to our owners. We sent a ticket that activating some of their services instantly caused bad bots to scan our site, and never got a decent reply on that. Their attitude does not inspire confidence and for that reason we scrapped them as an option. Never actually found a good European option besides them, which is sad.
      • viraptor 59 minutes ago
        > We sent a ticket that activating some of their services instantly caused bad bots to scan our site

        You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.

      • bcye 54 minutes ago
        There is a normal support ticket system not on Discord, which they loudly advertise for having a very good response time. The Discord server is not the primary support method
        • AndroTux 48 minutes ago
          In my case, the claim was justified. Got a technical response answering my question in detail after half an hour or so.
      • kosinus 1 hour ago
        Like, the bad bots you see when they get an https cert issued and it becomes visible in the public logs, or something else?

        Agree discord sucks.

    • tao_oat 2 hours ago
      They're fine for a CDN but overall their offering surprisingly immature IME. The devx for their hosted scripts/database just isn't there, and e.g. they only allow one global API key with full permissions, etc.
    • frevib 1 hour ago
      We use them en they have improved a lot in the last year. For edge services they have all the important thing like ddos protection and edge scripting. There is no replacement for Cloudflare Tunnel, but frp [1] is a good alternative.

      We don’t miss Cloudflare one bit.

      [1] https://github.com/fatedier/frp

    • s_dev 1 hour ago
      • sparkling 59 minutes ago
        Bunny is the MVP among these European alternatives. It's not just a CDN, it offers Cloudflare-style Edge scripting, Edge workers, databases (Sqlite compatible) etc.
    • jarym 1 hour ago
      Like bunny.net - its still tiny compared to CF but hopefully they will grow and won't adopt the crappier bits of CF.
    • bakugo 39 minutes ago
      Something to consider if you're looking at Bunny.net: https://news.ycombinator.com/item?id=47710845
    • CommanderData 2 hours ago
      They don't have Cloudflare Tunnels which is almost too good to pass up.

      I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.

      • ramon156 2 hours ago
        big corps = big money. they dont make money from your $5/mth static site, its practically free when you're at CF scale
        • CommanderData 1 hour ago
          What I was talking about: https://newtrackon.com/

          10+ BT trackers using CF likely free tier. Low-end EACH 300-500 MILLION HTTP requests/24hr uncached, some exceed a billion reqs/day (using statistics from other open trackers) 20TB-40TB daily, ~1-3 Gbps sustained.

          That's a crap load of transfer and compute to process those tiny network connections. As someone that's run a Tunnel on a normal site in the millions, the daemon uses a sizeable amount of CPU and I can't see any reason why it's not the same on the other end.

          Whatever source CF has going on, kudos to them and their engineering team.

          • viraptor 33 minutes ago
            Lots of people will run http over the tunnel rather than https, so that actually comes out cheaper for CF overall because they don't have to start new TLS sessions.
  • maxcoding 2 hours ago
    I feel like your site needs a CDN, it takes over 40 seconds to load your front page from the EU.
    • dotcoma 2 hours ago
      Maybe a European CDN, like Bunny (Slovenia)
      • unglaublich 2 hours ago
        Do they also have their own infra or are they just an entity between the customer and AWS?
        • ramon156 2 hours ago
          They have their own infra but its not the size of CF. Chicken and Egg
  • jamesnorden 34 minutes ago
    You have to ask why they're so "generous" with giving away free services.
  • pjmlp 2 hours ago
    The problem is that we have spent 40 years adopting US technology, across multiple generations of software developers and decision makers, while everyone was supposedly on the same side.

    It will take similar amount of years to go back into the cold war heterogeneous computing landscape of the 60, early 90s.

    This assuming there would be an willingness across all European countries to actually push for that, and not jump out when it gets too hard and search for compromises instead.

    This is why most sovereignty initiatives focus mostly on SaaS products and hardly on actual computing devices.

    • mrits 9 minutes ago
      The current Europe strategy seems to be to pay software engineers less money and hope for a superior product. I'm not sure how you'd catch up when some of your engineers literally make less than our fast food workers.
    • sajithdilshan 1 hour ago
      Even if EU countries want to push for their own solutions, the biggest problem is the capital. The governments cannot fund this with tax payers money because they have other critical problems to solve and private companies only go far if they can make a profit.

      Only time will tell how far this sovereign movement would go. Maybe when the US would have a president/government from the Democratic Party someday in the future. EU would cozy up again to US and go back to how things were. There’s no permanent enemies or allies when it comes to politics and at the end of the day it all revolves around money

  • CrimsonRain 4 minutes ago
    Europoors can't compete but can complain about not using european tech while drowning own people/tech/startups in bureaucracy. Peak europoor things.

    This article is as useful as writing sky is blue. Nothing stopped an european cdn to become cliudflare but euro bureaucracy and europoor risk averse mentally.

  • bildung 2 hours ago
    I'd also be interested in share of companies using a CDN in the first place. UK has 17k sites, while France and Germany, so countries with about equal and higher population than the UK, have only 4k and 6k sites behind a CDN.

    I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?

    • embedding-shape 2 hours ago
      > I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?

      Maybe our countries are just small enough to not be overwhelmed by traffic? Most websites I've built and launched for Spanish national companies, that only have other Spaniards as users and customers, haven't needed any CDN at all, because you don't suddenly get 1K req/s. Meanwhile, launch a global website in English, that even get the slightest amount of popular, and all of a sudden you reach 1K req/s very quickly. Add on top that people usually don't even give two cents about performance, and adding CDN on top as a saving grace seems like an easy tradeoff.

      So, why add a CDN when you don't need it? :) Probably 80% of everything I've ever deployed never needed a CDN in the first place, but I also save it as a thing in my toolbox to be used sparingly, rather than a default thing I slap on top of everything.

      • ivlad 1 hour ago
        nginx can do about 20krps per CPU for static files. You only need CDN if you want to improve time to DOM loaded in locations where time to first byte is over ~100ms and can be improved with local caching.

        If all your users are in Spain and you don’t care how fast your site loads for a techbro in California, you indeed don’t need CDN.

    • JimBlackwood 40 minutes ago
      It’s a limitation of their dataset. If you take all domains, it definitely creates a different picture.

      For both France and the UK, less than 15% of sites are behind a CDN. For both, around 95% use Cloudflare.

      So in terms of percentages, there’s not much of a difference.

    • wiether 2 hours ago
      Their index being paywalled, it's not possible to answer about its content.

      I wanted to check if the 5 customers for which I already did a change on their Cloudflare settings today where on the list, but can't do.

    • pajamasam 2 hours ago
      I'd be interested in what data they're using in the first place. It looks like their data is behind a paywall.

      Also, funny that their page with for "Companies running Cloudflare" says there are only "887 European organisations using Cloudflare."

  • ObscureScience 53 minutes ago
    My employer uses CDN77. Only for serving static resources.
    • simondotau 31 minutes ago
      But do they offer even 10% of the features Cloudflare offers to free customers? To imply that Cloudflare is merely a fancy CDN is to miss the whole point.
      • Tepix 5 minutes ago
        It's the same issue as being cloud agnostic.

        If you use their unique features, you're locking yourself in. Is it worth it?

  • em500 2 hours ago
    Tale as old as time (or at least as the 1970s): nobody ever got fired for buying ~~IBM~~ Cloudfare / AWS / Azure.

    9 out of 10 corporate decisions are for blame avoidance / ass covering.

    • chpatrick 1 hour ago
      It's actually a great service though.
      • viraptor 49 minutes ago
        It's also a great protection racket. They host many DDoS provider sites and protect them from law enforcement.
    • edelbitter 1 hour ago
      .. 9 out of 10 unhappy customers are currently unable to cause any blame, because they cannot even reach customer service because they are getting the "bot" treatment.
    • Danoch 1 hour ago
      [dead]
  • raverbashing 32 minutes ago
    It's hard to beat the "free DDoS" protection of CF. Could even be considered dumping in a way
  • dakolli 1 hour ago
    In the late 90s and early 2000s the NSA and other US intelligence agencies underwent massive efforts to basically privatize the gathering of intelligence. Its a lot easier to fund your "total information awarness" initiatives via public markets and private investors than to ask congress for money to do so. So they did just that.

    "In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year."

    --Matthew Prince's Wikipedia page.

    Dont for a second think cloudflare's generous free tier offerings are out of the goodness of their heart. They're a giant fkin MiTM project for the US governemnt. And of course, cloudflare isn't the only one.

  • shevy-java 1 hour ago
    The EU needs to stop giving money to the USA in general. They contribute to their own demise by doing so. Canadians understand this so much better than the EU, so the only logical conclusion to be made is that the EU is currently controlled by US lobbyists. This would explain about 80% of the issues; the remaining issues are inertia within the EU, but it also isn't made any easier when the US government constantly favours US mega-corporations ruthlessly infiltrating and abusing other markets.
  • amelius 1 hour ago
    But isn't a CDN a commodity? I.e., you can switch to a different one with almost no effort.
    • AndroTux 44 minutes ago
      Depends how deeply integrated it is. Cloudflare offers a web application firewall that can quickly become complex, alongside features like custom routing rules, input parsing, custom headers, etc. As soon as you start integrating any of those into your environment, migration becomes more difficult fast.
    • pyvpx 1 hour ago
      How does that quip go again…there are only two difficulties in computer science, cache invalidation, naming things, and counting.

      Going from one CDN to another can be infuriating even at a surprisingly small scale. Mostly (imo) from caching semantics and counting.

      • amelius 1 hour ago
        Can you give a practical example?
    • kypro 1 hour ago
      It's not really a commodity when Cloudflare is often cheaper, simpler and provides a better service compared to it's competitors.

      For it to be a commodity there would be no good reason to pick Cloudflare over any alternative and this absolutely isn't the case.

  • vaylian 2 hours ago
    Naive question: How important is it to use a CDN in the first place? Why can't you just serve the content yourself?
    • viraptor 2 hours ago
      It depends on what you're trying to serve, but it's used to either save you money or as an insurance (or both). You don't need a CDN overall. But if you grow large enough, at some point you'll run into one of these three situations:

      - Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead. (Where the cache size is larger than anything you'd want to support yourself. For example, if it's <1G and survives your service restarts, you may want to do it yourself)

      - Your customers on the other side of the world start complaining that the resources take ages to load.

      - Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.

    • _joel 1 hour ago
      Reduces latency when the cached content is served from a local cdn pop, allows you to absorb some level of DDoS, can absorb traffic spikes more easily so infra can be more static, reduces load on server if assets are dynamically generated on the backend but can are cacheable, some senses can lead to simpler deployment as you serve assets from an object bucket, so no need to deal with keeping that data in your cluster, but that's minor. There are downsides too, cost, over caching, privacy/security perhaps too.
    • pluc 2 hours ago
      This article being down/slow is a great response.
      • vaylian 1 hour ago
        Not to discount the experiences that other have, but the site loads fine for me.
    • unglaublich 2 hours ago
      Because an average request would have to travel half the globe, so setting up a simple HTTPS connection would already take a second. That's completely unacceptable for static content.

      Not only would transfer be slow, they would also be much more pressing on the network as the request would occupy huge stretches and many interconnects and switches.

      Furthermore, it hardens the website against DDoS and adds robustness for regional failures.

      • ivlad 1 hour ago
        Minority of sites have global traffic. This is especially true for non-English sites.

        So, while average request may have to travel quarter (not half) of the Internet globe, median request from the set of requests that matter has much lower latency.

        Barcelona to Stockholm is about 65ms, ~35ms to Amsterdam, ~43ms to Frankfurt.

        HTTP/3 is ubiquitous, you don’t get TCP handshake penalty anymore in major browsers.

    • esseph 2 hours ago
      The site this is about is current down due to HN traffic.

      Lol

    • embedding-shape 2 hours ago
      Depends on your use case.

      If you have a very inefficient backend (maybe legacy project?), you have massive amount of traffic (say 100K req/s or above) or you really must have sub-500ms latency absolutely everywhere in the world, then it might make sense to slap a CDN (or similar) on top of that.

      In pretty much any case outside of that, it makes no sense to waste the time, money or effort on CDNs. But, all the CDN companies seemingly have convinced half the internet that you absolutely must use a CDN, otherwise you'll get hacked/broke/killed/sent to the moon, and they've been successful with this campaign too seemingly.

      • bdauvergne 56 minutes ago
        How does a cdn makes you backend faster or your latency better ? I thought it was only for distributing static assets and managing DDOS. If it is for cachable but dynamic content install reverse-proxy cache it will fly.
        • embedding-shape 50 minutes ago
          Because it lets you use it as a geographically distributed cache basically. Most GET requests should be able to be cachable on the typical website, besides the ones that are unique per logged in user or similar.

          If your server is in Europe, and you have Australian users, there is a physical limit how low the response times can go, serving bits over that distance, so only way you can make it go below that limit, is by moving where you serve the data from closer to the user.

          Lots of websites have horrible performance for whatever reasons, and lots of freelancers/consultants basically default to throwing a CDN on top of those when they get approached by businesses to fix the slow website browsing, as they're not the ones who have to pay the monthly subscription, and the less work they have to do, the better $ per hour spent for them.

          I agree that it's a shit solution and there is much better sustainable ways of solving these things.

      • esseph 2 hours ago
        Data scraping.

        If anything else, the AI machine wants near constant streams of new data, even if it already checked with you 30ms ago.

        A CDN helps immensely.

        Also keeps you from getting DDoS'd if you did something like run it off your home connection.

        • embedding-shape 1 hour ago
          Your webserver most likely have "rate limiting" built in already, which you can configure to act based on lots of variables typically. Set a limit of 1 req/s or whatever, and you've stopped 99% of all DDoS you'll encounter on the public web. If your visitors get cranky, up it to 10 req/s and you still are preventing most of the "abusive traffic", granted your backend/website isn't completely upside down when it comes to performance and resource usage.

          CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.

          • viraptor 44 minutes ago
            This is not how things work and no company providing online services for money would rate limit like that. This would do nothing for real world DDoS. You're in "not even wrong" territory.

            And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.

            • embedding-shape 38 minutes ago
              Yeah, of course if you're a large service, stuff that works for SMEs isn't gonna work for you...

              If your problem is AI crawlers, then simple rate limits help, I've helped countless of businesses with this already. For the ones that it isn't enough, you continue adding more roadblocks. There is no "one size fits all here" and that you seemingly is under that belief, leads less credence to what you're saying, not more.

  • VBprogrammer 1 hour ago
    Cloudflare interstitial pages are becoming the new cookie / GDPR pop-up for me. Remember when the internet used to be good?
    • viraptor 54 minutes ago
      Unfortunately that one's on the operators. I can complain for days about CF, but nobody is forcing the companies to default to giving everyone a managed challenge page. Some do, because either they don't care or don't realise the extra cost.
    • cassianoleal 40 minutes ago
      Same but they're so much worse than cookie banners...
  • tunahanfaruksav 1 hour ago
    [flagged]
  • iamislida 1 hour ago
    [dead]
  • dansmet 53 minutes ago
    [dead]
  • chrocni380 2 hours ago
    [flagged]
    • Steve16384 1 hour ago
      How did you extrapolate that leap of logic? Maybe we suck at business.
      • ilikerashers 1 hour ago
        We have stagnant economies with slow adopters and shallow capital markets. EU tech companies are working with hands tied behind their backs.

        The US deserves it's success.

  • Yash16 1 hour ago
    [dead]
  • tolusky 1 hour ago
    [flagged]
    • cassianoleal 38 minutes ago
      Do you mean US national security?
  • throw93947309 1 hour ago
    [flagged]
    • AndroTux 42 minutes ago
      This has to be rage bait, right? Ever heard of GDPR? How about ICE?
    • bdauvergne 54 minutes ago
      Is it satire ? Laws apply to the publisher not to the TLS endpoint.
  • tonyhart7 1 hour ago
    so instead of developing actual competent solution, European complaining about why US tech dominate ?????

    what stopping europe from using their home ground solution ??? nothing

    this is just a skill issue take

  • schnebbau 2 hours ago
    Yeah because it's priced well and it works. It's a no-brainer. (Also if it does go down, well so has everyone else so no big deal)

    Also in this list of GOATed companies: Tailscale, Ubiquiti.