Rendered at 21:37:32 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jillesvangurp 1 days ago [-]
It's seriously good value for small websites. Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well. And they have a few other things that aren't half bad to use with pretty generous freemium layers.
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.
snorremd 1 days ago [-]
Before I went European sovereign for my own personal stack I used Cloudflare for hosting static and somewhat dynamic websites and it has become really nice the later years. There is almost no mention of "regions" in Cloudflare. Your content and code runs globally by default. With traditional clouds you need to think about how you distribute your application. At least that is my experience. Maybe they provide global CDN for global distribution of static content. But serverless containers and databases more or less run in a single region by default. And if you wish to distribute stuff it is on you to plan the architecture behind that.
Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well.
A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.
exfalso 1 days ago [-]
What do you use as a European CDN atm?
snorremd 1 days ago [-]
Currently I don’t use any CDN. I just host everything on Scaleway on VMs and serverless. Works pretty well for my use, but I imagine latency is bad for South Americans. I’ve looked into Bunny and I think that is the closest you get to Cloudflare’s offerings.
The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
esperent 1 days ago [-]
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
icantevenhold 1 days ago [-]
Heck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level
TallGuyShort 1 days ago [-]
"The “threat model” section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them." -- James Mickens
giancarlostoro 1 days ago [-]
Man, can I get that as a telenovela? I want to hear my mother in law explain the plot.
I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.
mitxela 1 days ago [-]
Yeah but like, they still have to do that, we don't put our own uranium lumps in our cellphones like we do with cloudflare.
fr2029 1 days ago [-]
l2paragraph, aint nobody reading dat
strictnein 1 days ago [-]
> "it’s no big secret that the NSA is listening in on the node/isp level"
The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.
Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
axus 1 days ago [-]
You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.
DANmode 1 days ago [-]
You’re talking about two different things.
One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.
> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
ISP taps globally, undersea cable taps, the list goes on.
leonidasrup 1 days ago [-]
Most Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.
junofan 1 days ago [-]
Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.
If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.
That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.
If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
mitxela 1 days ago [-]
That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?
They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
mitxela 1 days ago [-]
You may as well make them work hard to get it. The NSA can only get metadata from your ISP.
ARandomerDude 1 days ago [-]
This is a joke. If it's electronic the NSA can hack it with impunity, including your ISP. And that's assuming your ISP won't just give them whatever they ask for (unlikely).
leonidasrup 1 days ago [-]
There is nothing magical about these NSA hacks:
NSA putting implants into Cisco equipment before delivery to the customer.
I did once theorise that Cloudflare would be a fantastic NSA front.
mitxela 1 days ago [-]
That's why it is one.
9864325789976 1 days ago [-]
[dead]
strictnein 1 days ago [-]
The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.
This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.
There's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting for the NSA there.
strictnein 1 days ago [-]
Of course, but the comment I was replying to stated:
"the NSA learns everything there is to know about you and your customers"
Which implies that they are looking at it all and records it.
The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.
pocksuppet 1 days ago [-]
They are actively scanning all of it, looking for interesting stuff.
ranger_danger 1 days ago [-]
I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.
jonathanstrange 1 days ago [-]
If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.
That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.
strictnein 1 days ago [-]
Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.
jonathanstrange 1 days ago [-]
According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.
icantevenhold 1 days ago [-]
Isnt that basically Palantirs business model?
ExoticPearTree 1 days ago [-]
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.
Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.
I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
petcat 1 days ago [-]
The NSA collects and archives all internet traffic it can access for future analysis. It's the purpose of the Utah Data center.
There’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic.
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
Public information shows that the NSA has been active intercepting as much data as possible.
It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
p-e-w 1 days ago [-]
That’s not what the GP comment said though. They claimed that they are storing everything they can intercept, which is weapons grade horseshit.
belorn 1 days ago [-]
People said/wrote in the past that what NSA and other intelligence agencies did was to gather data and store the meta data. The actually traffic got processed for the meta data, and small amount of the traffic got sorted out and also stored.
I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.
jgtrosh 1 days ago [-]
Regarding storage, a single data center using only slow but dense storage (magnetic tapes) can store far more data than a data center providing regular web services.
bblb 1 days ago [-]
It doesn't need to store the payloads itself. It stores the metadata of connections and probably the fingerprints of the content passing through the Internet. "The headers of the whole Internet" could be physically stored in a single datacenter.
Forgeties79 1 days ago [-]
“They’re not as good at violating your civil liberties as you think they are”
isn’t very comforting. They are still doing it at scale and i’m not too keen on opening the back door for them myself.
otabdeveloper4 1 days ago [-]
> The Internet runs on tens of thousands of massive datacenters.
"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)
p-e-w 1 days ago [-]
Sure. But a government agency has secretly rebuilt all the same infrastructure without Python, on a shoestring budget compared to what Big Tech is spending, yet it’s a lot more efficient than what they use, right?
otabdeveloper4 1 days ago [-]
Caveat: I have zero experience with USA government agencies. The spying tech from other countries I'm familiar with are beige box routers made by network engineering types with embedded firmware written in C inside.
I think spying on traffic is just a massively simpler task than generating content.
bulbar 1 days ago [-]
Not all traffic, but any.
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
mitxela 1 days ago [-]
They also certainly have many heuristics running. Your corporate website is interesting because it reveals who your suppliers and customers are, and all of your passwords. They don't have the manpower to scrape this manually so they scrape it automatically
1 days ago [-]
thorbutt 1 days ago [-]
That doesn't seem unique to Cloudflare though
cassianoleal 1 days ago [-]
No, but nothing comes close to their breadth and scale.
youngtaff 1 days ago [-]
Amazon and Akamai is their scale, maybe Fastly too
pocksuppet 1 days ago [-]
They are serving big commercial enterprises, ones the government already has direct access to. Cloudflare is serving the long tail.
aranelsurion 1 days ago [-]
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
Perepiska 11 hours ago [-]
Also CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog.
Also CF raise checks on pages that I opened few hours ago and reload.
lukan 1 days ago [-]
"We've known it has an always-on microphone and speech-to-text for over a decade"
Yeah, about those I know, but what about cloudflare?
a2ff6eeb0 1 days ago [-]
They hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache and forward appropriately.
lxgr 1 days ago [-]
Also to do DDoS mitigation. Being able to see the HTTP request, at least headers and path, greatly helps with distinguishing attackers from legitimate traffic.
It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.
Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
kakacik 1 days ago [-]
If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.
Or clouds in general, its all wishful thinking and pinky promises.
spacebanana7 1 days ago [-]
What about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence
mitxela 1 days ago [-]
You have to be a registered Chinese business entity with a CCP director on your board to legally use that
WarmWash 1 days ago [-]
One of them is just another arm of the government so all data is defacto government data, and the other releases transparency reports[1]
if your threat model includes the NSA i don't think your choice of CDN is going to make a difference
mopsi 1 days ago [-]
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.
I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
done_lurking 1 days ago [-]
Do you really need Cloudflare for something like this?
mitxela 1 days ago [-]
He doesn't, but someone told him it was good so he uses it. This is Cloudflare's main audience, just like McAfee's.
mopsi 22 hours ago [-]
Unfortunately my proposal to set up a K8s cluster to host 5 HTML pages and a dozen jpegs was not approved, so I had to make some compromises this time.
mitxela 20 hours ago [-]
Who told you you need a k8s cluster to serve 5 HTML pages?
yurish 14 hours ago [-]
I believe this was a joke.
mopsi 1 days ago [-]
It's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site is handled by Cloudflare.
And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
seki285 1 days ago [-]
>talks about how bad Cloudflare is with imaginary threats
>doesn't offer an alternative and leaves
Every. Single. Time.
mitxela 1 days ago [-]
The alternative is nothing. You don't actually need cloudflare.
seki285 1 days ago [-]
And get hammered by bots, scrapers, and bad actors?
mitxela 20 hours ago [-]
It's not like cloudflare blocks them either. Have you tried?
Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
samlinnfer 1 days ago [-]
They already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.
stef25 1 days ago [-]
Maybe that's why the keep hosting extremist content.
done_lurking 1 days ago [-]
I thought Cloudflare generally refuses to serve those kinds of sites. What content is Cloudflare serving that is extremist?
pocksuppet 1 days ago [-]
Many torrent sites, that's a kind of extremism.
1vuio0pswjnm7 17 hours ago [-]
I have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries
I don't think it's convincing
If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.
If the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying
For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost
The damage of being spied upon, if there is any, is already done
1. It's not clear why commenters are only concerned about intelligence agencies
Betelbuddy 1 days ago [-]
Or they will dump your secrets into all Internet caches...
AWS isn't aimed at regular people, it's infrastructure as a service. You use it because you need a thousand servers, or a redundant system that can survive a data centre exploding.
If you just need a single server that you don't care about then it's way cheaper to just own it yourself. You probably don't need 99.999999999999999% guarantees for your data, but if you're a bank then you do need those guarantees because losing all of your documents would be disastrous.
Normal people aren't worth anything to them. A company might spend a million a month with AWS, to get that with normal people you'd need at least a hundred thousand customers. And those people are going to spam you with tickets and do silly or illegal things. They're just not worth it. They obviously won't turn money down, but it's not a growth area for them.
epistasis 1 days ago [-]
I 99% agree, but have conflicted felings. There's a mix of services. S3 is and was an amazing resource for normal people. Extremely reliable cloud storage for backup, for distribution, for anything, well, it's a dream. I prefer Cloudflare's offering there in every way, but AWS defined the product category (with its correspondingly ugly API like every single AWS service), and met a core need for many many people. With S3, if you need a ton of storage, it's a terrible deal, and you shouldn't use it. But for a couple hundred gigabytes, go for it.
EC2 is similarly great for normal people as long as you only need a part-time server for a short amount of time. It's hard to beat with a VPS.
Once you get into load balances, event queues, and all the rest of AWS services, well, that's all there to drive lots of money to AWS and to contractors and busy work. MAYBE RDS is a good deal for somebody who really wants to pay somebody else for a managed database. Which turns out to be a ton of users of databases!
tjoff 1 days ago [-]
Cargo culting is probably the biggest reason people use AWS.
pampas 23 hours ago [-]
Registering domains on Cloudflare is great. They do it at cost as far as I can tell and more tlds have been added. I don't have to use a nasty local registrar with dark patterns anymore.
mitxela 19 hours ago [-]
They do it at cost with a caveat: you can only ever use Cloudflare for that domain. It's a loss leader.
theamk 18 hours ago [-]
what? their docs explicitly say nosy of them are not going tobe cloudflare-hosted
> Cloudflare does not offer web hosting for most websites
Re: complexity. I used to find AWS unusable, then I realized I can just tell Claude Code or Codex to manage it. This makes it into an entirely different product, where "Cloudflare is easier" doesn't really matter. Now price is the only barrier.
airstrike 1 days ago [-]
Cloudflare can also be managed by Claude Code or Codex, so for those instances in which you will personally have to go into the console to make edits, Cloudflare is still easier.
jerkstate 1 days ago [-]
yeah, I have been amazed at what I could do for free, and then amazed at how much more powerful it got for 5 bucks a months. Cloudflare is killing it in terms of value for small websites (and features and reliability).
el1s7 1 days ago [-]
Google Cloud and AWS are complex because they're meant for hosting complex apps and infrastructure, they're not really worth it for simple static websites.
sinsterizme 1 days ago [-]
I'd argue it's even more worth it for static sites, where CDNs and buckets will vastly out-perform hosting a static site on an instance yourself because of replication, caching, and geographic routing
mitxela 19 hours ago [-]
But they don't, because your bucket is still in a location, and goes through more complexity layers.
ghoul2 1 days ago [-]
I also believed that, but at least for India, this doesn't work in practice. Unless you atleast do the 25$ pro plan, cloudflare routes even india-to-india, hell, even mumbai-to-mumbai and aws_mumbai-to-cloudflare_mumbai traffic via Marsaille!! Not even Singapore. The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved.
Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare).
Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan.
Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.
toast0 1 days ago [-]
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
IMHO, it's not that hard to believe.
a) Every hosting provider I've looked at prices for charges significantly more for bandwidth from their Indian locations.
b) In the US, transit providers basically never charged different rates for different destinations [1]. In Europe, it's typically rare, sometimes transit to the local incumbent telecom is more, sometimes there's a different rate for Europe or non-Europe, but there won't be a specific destination charge for India, it will be part of a blended rate. Otoh, east Asia often has separate rates for specific nearby countries and India is likely to be one of those...
Transit prices in Europe are pretty low compared to prices in India, so the blended price being less than the India direct price is not surprising to me at all.
[1] gcp premium does charge by destination, but the premium transit price is pretty close to their price for cross location traffic to something near the destination + non-premium traffic from that location... Which is more or less what their premium network egress is.
mitxela 19 hours ago [-]
It's basically that payment flows towards the core of the network, which is Europe and America. If you're the first Indian ISP, you have to pay a European ISP for an upstream connection - they won't pay you. And that persists and becomes "just the way things are done". It can only reverse if there are significant websites in India that Europeans want to access, then the European ISPs will be getting more value than the Indian ones and the Indian ones will be able to demand payment.
piperswe 1 days ago [-]
Transit in some countries, like India, genuinely is that expensive. Keep in mind it doesn’t cost Cloudflare any more to serve Indian traffic from Marsaille than to serve non-peered French traffic from that colo - they aren’t paying the cost of getting traffic between India and France.
ghoul2 1 days ago [-]
The traffic still has to flow from an india provider to the international leg and back via the domestic provider.
In anycase, then they should document it clearly that they have unacceptable insertion latency in india and the free plan is entirely unusable for india. Instead of advertising '10 pops in india!!'
nightpool 1 days ago [-]
> The traffic still has to flow from an india provider to the international leg and back via the domestic provider.
Right, but Cloudflare doesn't have to pay for it in that case. If Cloudflare sends you to their Indian POP, then they have to pay their Indian service provider for traffic. If they send you to their France POP, then they have to pay their French ISP for traffic. The Indian provider cannot claim any of Cloudflare's traffic in that case, because the Indian service provider wouldn't have any relationship with Cloudflare
This is very standard for places with high ISP costs, like South Korea and India. You can see a lot of discussion about it online. I agree with you that Cloudflare should be more transparent if / when they make different routing decision for Free/Pro plans based on bandwidth costs, but I don't think their decision itself is unreasonable at all. Indian bandwidth is very expensive.
mitxela 19 hours ago [-]
You would think Cloudflare would be in a position to do something about it, like they did with several cloud services in their Bandwidth Alliance. It would be a win-win-win for networks to interconnect better in India, it just can't happen stepwise because any individual step is a lose for somebody.
mitxela 19 hours ago [-]
> The unstated reason is that indian transit is expensive, though I fail to believe its cheaper to go from mumbai to marsaille and back to mumbai.
Your Indian ISP is paying a French ISP for both directions of that traffic, which makes it cheap at the French end. Were it India-to-India, Cloudflare would have to pay your ISP.
dizhn 1 days ago [-]
> Basically, there is no cost aside from the domain. And for registering and managing domains, they are pretty much the most affordable option as well.
You don't need to register your domain with them. Only make their DNS servers your domain name servers.
jillesvangurp 1 days ago [-]
To be clear, we migrated our domains to them after moving our websites there, not before. Our old registrar charged more.
ranger_danger 1 days ago [-]
I cannot visit most crimeflare sites because I just get endless captcha loops.
mitxela 19 hours ago [-]
The trick is to use the most normal hardware, software and network connection you can think of. Which I assume you aren't doing for ideological reasons, which is fair.
ranger_danger 13 hours ago [-]
My ISP seems to frequently rotate IPs with other people who can't behave, so my IPs always have garbage reputation... that probably has a lot to do with it as well.
How do I know this? I have received reports from various websites (and manually queried some public block lists/RBL/etc.) that my IP range was blocked due to all sorts of different things like open proxies, CSAM etc. even if I've never visited that site before, and I know just from being a neteng that that such traffic is not originating from my devices/router and I don't have any observably compromised devices or suspicious traffic when monitoring it.
Not really unexpected, US domination of "tech" is near total, even if the sustained political will exists (and I'm not sure it will for long enough) unwinding that is the expensive work of years/decades not months.
Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
Personally I think we absolutely should, I just don't think we will.
Barring them doing something so egregiously awful we don't have the choice, Governments can move fast when they want to but efficient government scares the shit out of me because it rarely happens outside of a genuinely serious crisis.
zkmon 1 days ago [-]
>> US domination of "tech" is near total.
Not quite when considering China having the tech freedom they wanted. Also switching internet services is far easier than switching physical supply chains. The only thing that might be hard to switch is the part of the interent backbone infra that is controlled by USA.
shevy-java 1 days ago [-]
You are not living in Europe, right? Because while I agree that China is a problem, the USA is a much, much bigger problem for Europeans than China is right now. It's mostly the USA that wants to depict China as the main problem when in reality the USA behaves in a hugely aggressive colonial manner. Trump just makes this more obvious, but that has been the case way before Trump already.
aivisol 1 days ago [-]
Please speak for yourself. Not everyone in Europe thinks US is bigger problem than China. For many China is far bigger geopolitical threat since they openly support Russia in its current war.
pjc50 1 days ago [-]
It does actually matter that the US president is continually deriding Europe and making weird threats in English language social media where we can see it, while the Chinese leadership is politely selling us discounted cars.
(When is the first war going to be started purely downstream of social media beef? Was it arguably the Iran war?)
FuriouslyAdrift 1 days ago [-]
That's like complaining that the police are mean while your heroin dealer is so nice to you.
pjc50 1 days ago [-]
Well, yes, that's a huge structural problem in many American cities. When people perceive the police as more of a threat than crime, the situation deteriorates. Somehow "make the police trustworthy" isn't considered an option.
coldbrewed 1 days ago [-]
In this metaphor the police are corrupt, running a protection racket, and might get drunk and shoot you while your dealer is in the mafia. The mafia link might be a problem at some point but the person with the badge and the gun is a problem right now.
FuriouslyAdrift 1 days ago [-]
[flagged]
GMoromisato 1 days ago [-]
My hope as an American is that China's growing power will bring Europe and the US closer together.
It's true that MAGA craziness has pushed Europe aways from us. But, ironically, Europe increasing defense spending and standing up an independent military machine will actually make some MAGA people like Europe more.
But either way, the best thing for both the US and Europe is to figure out a way to reconcile. The alternative is a Europe-China alliance (which would be bad for Europe) or a US-China alliance (which would be horrific for Europe).
mitxela 19 hours ago [-]
The US also openly supports Russia in its current war, what's the difference?
aivisol 13 hours ago [-]
What do you mean by that? Are they selling any parts and components for military use? Are they buying oil and gas to support their war effort.
Roark66 1 days ago [-]
As a European that lives 200km from the Russian border it seems the USA has been supporting Russia in its current war a lot more than China.
Consider these points:
- US withdrawing it's "Intel support" just as Russia started a major offensive last year.
- US starting the war on Iran clearly to help their pal Putin on oil prices, now they try to use Ukraine as a scapegoat for "attacking Russian oil export infrastructure"
- Another "side effect" of war in Iran. No more patriots or modern weapons for any country that ordered them from the USA in recent years and was expecting deliveries just about now.
- US committing actual act of war (threatening force has been considered an act of war for centuries) against the EU by talking about invading Greenland (most certainly if Russia attacked Estonia US would try their luck with Greenland on same day, does it remind you anything from history?)
- US essentially waging an economic war on the rest of NATO.
- US companies with full support of the state trying to deny computing hardware to the rest of the world in hope they manage to monopolise compute capability using AI as cover (yes China is a real ally in this).
And much more.
Yes, the US is a much higher threat to the EU than China now.
phainopepla2 1 days ago [-]
> it seems the USA has been supporting Russia in its current war a lot more than China
Don't be ridiculous. The US literally provides targeting information to Ukraine, including for long-range missile strikes deep inside Russia earlier this year.
foldr 1 days ago [-]
US motives are currently inscrutable, but the US is sending military hardware to Ukraine, whereas China is sending dual-use hardware to Russia. You can see an itemised list of US contributions at the following link. It's not nothing.
Overall I agree with you, but I'd be wary of taking these numbers at face value. For instance, $20b of America's $65b aid contribution comes from a loan that's repaid by selling off sanctioned Russian assets. Many of the weapon systems sent over are decades old, but valued at the price the US paid for it in the 1980s/1990s.
Side-by-side with, for example, itemized Israeli aid, it's pretty clear which conflict the US is putting on the back-burner.
BenzeneDream 1 days ago [-]
This is incredibly inaccurate. China is why Russia is still even in the war and is still a functioning country. The EU itself supports Russia much more than the US does with its energy imports.
aivisol 13 hours ago [-]
As a European living 30km from Russian border let me disagree with you
0xDEAFBEAD 1 days ago [-]
Some of that alleged "support" for Russia would be more accurately described as a failure to support Ukraine. But most states outside of Europe are failing to support Ukraine.
BTW, Zelenskyy supports the Iranian opposition, possibly due to the fact that the current Iranian regime is sending Shaheds to Russia. The US has attacked Shahed factories during the current Iran war.
MentalM 1 days ago [-]
> it seems the USA has been supporting Russia in its current war a lot more than China.
No way that's true.
China is main ally of Russia. China have a huge economic exchange with Russia, China is the sole gateway to technology for Russia, and provide a great amount of political support for Russia.
Even if we are comparing USA and EU in those aspects, EU's support of Russia is way bigger. EU spends huge amounts of money for purchasing energy resources from Russia, EU spends far less money on help against Russian invasion than US (although EU's population is larger, and that issue is way more pressing for them).
I mean look at the numbers: EU spends on confrontation with Russia less money, than they have spent on economic crisis in Greece or something. That is how they perceive this problem and how "important" it is to them.
nonethewiser 1 days ago [-]
I have no idea how people can overlook this. I mean I have some idea. A sort of “enemy of my enemy is my friend” meets “leopards ate my face.”
atakan_gurkan 1 days ago [-]
Honestly, I had the impression that the current US regime also supports Russia in its current war. Did they not ask Ukraine to give the already occupied land and then some? As far as I remember, that was in a form almost like an ultimatum, too.
China might be a bigger threat, but I find it hard to believe that this would be the reason.
hdgvhicv 1 days ago [-]
European governments still importing Russian fuel. Not that it matters much as fuel is mostly fungible, if Europe imported from elsewhere for a higher price they’d be the middle man.
petcat 1 days ago [-]
> Did they not ask Ukraine to give the already occupied land and then some?
Ukraine is never going to retake the territory they've lost without European soldiers on the ground. Macron famously said that he would have to send troops to Odesa and yet 3 years later there are still no French troops in Ukraine. Meanwhile Putin has captured even more land and is now actively bombarding Kyiv.
It is painfully obvious that Europe lacks the political will to do any kind of substantial intervention. The war is at a complete standstill and it will last for another horrible decade if no concessions are made.
It's the unfortunate reality of the situation.
pjc50 1 days ago [-]
Not being able to take the territory, having a ceasefire over the territory, and actually conceding the territory are three different things. The world is full of unceded occupied areas. Korea. Taiwan. Northern Cyprus. Palestine. Nagorno-Karabakh. Transnistria.
Ukraine rightly has no interest in ceding land to achieve a temporary ceasefire to allow Russia to re-arm and then attack again.
Meanwhile it is also important that we don't have two nuclear armed states (France and Russsia) officially at war.
wat10000 1 days ago [-]
I'm not excited to have France and Russia in direct conflict, but having two nuclear states at war would not be anything new. There's been China/USSR, India/Pakistan, India/China, and if you want to consider wars that mostly exist on paper at this point, North Korea/USA.
foldr 1 days ago [-]
>The war is at a complete standstill and it will last for another horrible decade if no concessions are made.
There is a slight hope that the current Russian regime will collapse before then and be replaced by one that doesn't want to continue the war. (Though, that said, it could equally well be replaced by a regime that's even more ultranationalist than the current one.)
While Europe certainly does lack the political will to make a substantial intervention, it's not just a question of political will. There is the small matter of not starting the third world war to consider.
> Did they not ask Ukraine to give the already occupied land and then some?
I mean what are the alternatives? Ask Ukraine to give the already occupied land and then some, but later, when several more millions of Ukrainian men would be grabbed by Ukrainian gestapo from the streets like rabid animals and killed?
Because with current support from the EU (that is less then EU support for Greece during economic crisis), that is the only alternative.
soperj 1 days ago [-]
Trump supports Russia, and their policies (war in Iran, opening up oil purchases again) support it even more.
OptionX 1 days ago [-]
Between China and the US which have laid claim to Greenland and have in no uncertain terms said they would use military force to acquire it?
preisschild 1 days ago [-]
Which one provides weapons to Russia, a nation in an active war against Europe?
And AFAIK the US has not even claimed Greenland.
Vaslo 1 days ago [-]
This is all in your head. We just expect people in Europe to begin picking up more of the tab for things like NATO, and don't want our enemies (your enemies if in western/central Europe too, BTW) to get control of future energy/minerals. You call it "aggressive colonial control", Americans call it "time for Europe to accept more financial and personal responsibility.
pjc50 1 days ago [-]
This would be more convincing without the weird bullshit around Greenland and Canada.
rapind 1 days ago [-]
Also, JD Vance and the AfD...
1 days ago [-]
1 days ago [-]
zerozerotwo 1 days ago [-]
This is such a hilariously delusional comment. Who do you think is financially backing the Russians who bomb your cities?
expedition32 1 days ago [-]
Who do you think is financially backing the Chinese? The trillion euro of EU imports...
1 days ago [-]
thesmtsolver2 1 days ago [-]
What? Go ask almost anyone in Asia outside Mainland China.
They all consider China to be the aggressor because they are. E.g., Tibet or India.
hvb2 1 days ago [-]
For European governments that have their email and such running with Microsoft, it's quite the signal when individuals lose their email because the US doesn't like them. See international criminal court.
JumpCrisscross 1 days ago [-]
> Go ask almost anyone in Asia
I think it’s fair to say the U.S. and Russia are Europe’s principal geopolitical adversaries, today, while for anyone in Asia or Oceania it’s China. (Africa and South America are being weirdly carved up—it’s not particularly clear who is trying to colonize versus trade with them.)
iso1631 1 days ago [-]
> colonize versus trade
Very similar pressures in reality.
JumpCrisscross 1 days ago [-]
> similar pressures in reality
In the way slavery and employment are similar, sure. In practice they’re very different things, even if one—when taken to the extreme—can turn into the other.
iso1631 12 hours ago [-]
See what happened to countries over the last 80 years which didn't want to participate in the American economic system
See what happened to countries in the 18th and 19th centuries which didn't want to participate in the British economic system
kakacik 1 days ago [-]
Both claims can be correct. US became Europe's adversary, quite active and pushy. We don't know yet where the end of backstabbing and shitting on us lies, we can easily have a war ie over Greenland within 2 years.
China? It wants to sell its cars here, and thats about it. Incomparable.
broken-kebab 1 days ago [-]
China isn't a big bully for European nations cause it's counterbalanced by USA, not of inherent niceness. Also in two years there will be a different president in White house, but in Beijing things aren't that fluid.
kakacik 1 days ago [-]
US is also nice to others only because it benefits it long term ie in building and maintaining its hegemony, fighting for petrodollars and so on. Now that it shat on those decades of hard-won fights and alignment thats irrelevant thing of the past.
Ask/look around in places that dared to stood apart or directly up to whatever US wanted, the story is everything but nice and bloodless. Ask those that fought for them, and were completely abandoned to be then murdered one by one (vietnam, afghanistan).
Rest of your post is just wishful thinking, US is in semi-lawless state now with new oligarchy ruling the country based on emotions and whims and hardly any laws, so prior experiences do not guarantee any form of future. I personally would literally, objectively, trust Xi more than trump if I had to choose (which I don't, nobody does), any day any night.
broken-kebab 1 days ago [-]
USA fluctuates expanding, and diminishing its power mainly because it's typical for electoral democracies to change its course with higher frequency.
It's friendly to Europe most of the time, and hostile at times. It's culturally closer, and functionally democratic. You quite obviously don't like the latter statement, but it is, and it is verifiable claim.
1) Can an American sue the country's gov't and win?
2) Is said gov't changeable by the way of elections?
3) How easy it is to participate in political debates for electoral outcomes?
On all 3 USA gets pretty high score. In high contrast against the backdrop of China. Like, if you prefer a world hegemon who is actively imperialist, and contra democracy, cause you're so outraged by the orange man - that's your choice, of course. But let's not pretend the choice is well-thought. Were HN a Chinese place, and you dared to criticize Chinese imperialism your account would not remain unpunished for long, for instance.
DarmokTanagra 1 days ago [-]
[dead]
preisschild 1 days ago [-]
I'm from Europa and consider China a far bigger threat. Trump is probably going to get replaced by a Democrat in a few years. China has been ruled by dictators for decades and probably will be for decades and they are a lot more hostile to democratic nations.
carlosjobim 1 days ago [-]
When Trump talks about doing the anti colonial thing and withdrawing troops from European soil, the response is outrage.
But I've learnt that iPhones and social media is American imperialism, but thousands of troops in dozens of military bases on European soil is not, somehow.
zerreh50 1 days ago [-]
>the response is outrage
Mostly from the US serving politicians scared of losing power.
watwut 1 days ago [-]
> thousands of troops in dozens of military bases on European soil is not, somehow
Presence of allies is not colonialism. Threat to annex Greenland is. Threat to annex Canada is. Keeping pet dictator in Venezuela and taking their oil is.
On the other hand, when Germans, France and other European soldiers came to Greenland to defend against an American threat, it was not colonialism. It was being allies.
> and withdrawing troops from European soil, the response is outrage.
The response to withdrawing troops from European soil was mockery and frustration from army that is loosing valuable bases. Either way, it is not an anti-colonial thing.
> When Trump talks about doing the anti colonial thing
Trump is modern colonialist. He is not talking about doing "the anti colonial thing" ever, instead he is bragging about making America colonial.
------
Trying to frame Trump as somehow anti-colonial is really new level of post-fact dishonesty. It does not work, because his appeal is based on dominance, violence and willingness to steal.
carlosjobim 1 days ago [-]
Which way is it: Allies or a threat? How much double-think can you fit within a comment?
To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
js8 1 days ago [-]
Not to mention, the idea that Germany, 3rd or 4th largest economy on Earth, cannot defend itself on its own and needs American troops "to defend itself" is just ridiculous.
The Americans are there as a front of US empire (IIRC Rammstein is being used for Iran war).
watwut 1 days ago [-]
> Which way is it: Allies or a threat? How much double-think can you fit within a comment?
America was a trusted, respected and liked allied nation. It was not a threat. Then Trump supported by people like you turned into a threat to Canada (another former ally), Greenland, democracy and freedom. So, America is not respected or liked, except by neo-nazi it supports. There is no double think involved here.
> To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
It is irrelevant what you think about what other countries should or should not want. The question is what is colonialism.
carlosjobim 1 days ago [-]
[flagged]
Neil44 1 days ago [-]
Ironic that an article about a CDN was hugged to death. The free plan with a couple of caching rules could have sorted that.
bryanrasmussen 2 days ago [-]
lots of efficient government happens outside of a serious crisis, but then you don't notice it.
k__ 1 days ago [-]
Yeah, I think only in crypto the non-us providers have a leg up, because running a node just needs an instance.
embedding-shape 2 days ago [-]
> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
I'm thinking the opposite might be the way to go here.
We already know that "retaliation" comes from the US government regardless if you did something or not, so most of us (Europeans) have stopped pretending there is a way of preventing it.
Even more, if we piss off Trump enough, he might be dumb enough to try to block European access to CloudFlare, or something similar and maybe even dumber.
So with this, maybe the goal should actually be to try to piss off Trump and the US administration as much as possible, in order for them to start reacting and cutting off some stuff, so we (again, Europeans) basically gets forced off CloudFlare et al.
Lots of companies already finished moving away from storing their primary data in the US, lots of companies is in process of doing so (albeit some look like they'll take forever) but also lots of companies still aren't prepared for the future, would be nice if US government could make the decision a bit easier for them to make :)
microtonal 2 days ago [-]
While I theoretically agree, the issue is that Trump will connect economical issues to blowing up NATO Article 5, leaving NATO completely, or retracting intelligence or Starlink for Ukraine.
So for the most part, the EU has to work slowly and under the radar.
That said, my worry is that we'll be back to business as usual if the midterms look favorable. Even the urgency present during January's Greenland threats was gone after a few months. I fear that we don't have the long-term focus and planning to make sovereignty really happen. But I'd love to be surprised.
eckesicle 1 days ago [-]
I asked the Swedish Prime Minister this question almost verbatim on Reddit two days ago and he responded. The answer was ... understated.
Oh, I missed that. Interesting non-answer regarding AI, seems almost obvious by now they don't even consider it a concept in the real world. Back when I lived in Sweden the politicians were already pretty disconnected from the average person, but in regards AI they seem to be intentionally avoiding it and sleeping on it?
pocksuppet 1 days ago [-]
Machine translation and login-wall unblocker:
Question:
> Hello, Sweden (and Europe) is facing three almost existential risks over the coming term of office that we have never really had to take a position on to the same extent before. The climate. A new UN report from last week has shown that El Niño will probably contribute to between 3 and 4 degrees of warming in addition to last year's heat wave. I live abroad and we had 44 degrees warm for a couple of days this summer (2025). It was also over 30 degrees in Norrbotten for over 3 weeks. Unbearable. How do you prioritize this against the many other budget items? How should we now prepare for what will inevitably lead to an IPCC 3-4 degree scenario?
> AI. AI development is just going faster and faster. At my workplace, we have already replaced many employees with AI-driven processes. We buy all our computing capacity from the US and China. There are no European alternatives and it is not possible to buy Swedish. What do you want to do to, at the European level, prevent us from ending up in the AI lap of the US and China in 5 years? Where should we buy chips from when all manufacturing takes place in Taiwan, Korea, China and the US? We risk a situation where Swedish office workers are rarely replaced with US AI tokens. Surely this must be an initiative at EU level?
> American foreign policy. Trump's second term has been tumultuous, to say the least. We were probably as close to the brink of war in Europe (Greenland) as there is in living memory. Trade agreements are being torn up, sticks are being put in the works for Gripen agreements, etc. Even when he is gone, the illusion of America as a close ally has probably finally been broken in the eyes of many Swedes, myself included. What do you want to do to reduce Sweden's and the EU's dependence on foreign superpowers?
Answer:
> There is a lot in this. A completely unique geopolitical time - both militarily and economically - presents a small country like Sweden with important choices. NATO was one of them. We are now cooperating with all our neighbors around the Baltic Sea, for example our own defense build-up, another example, the largest since the 50s. And all the new free trade agreements when the United States messes up world trade.
> The climate is also one of these, and what the EU is now doing together is the single most important thing, in parallel with Swedish fossil-free energy. We can make ourselves completely national energy independent with the new Swedish nuclear power programme. German energy policy, I think, proves why this is needed, in addition to the wars in the Middle East.
> EU: no single EU issue is more important than our support for Ukraine and increasing European competitiveness in relation to both the US and China. And it starts with the internal market - where 70 percent of all Swedish goods exports end up. If it can be as good for services including digital services, it would be good for both the EU and Sweden. But I am genuinely concerned that Europe is lagging behind.
> last China: we will have an intense autumn regarding a common European response against China to get "level playing fields" when it comes to trade. Today's situation is not sustainable. even extremely free trade-friendly countries like Sweden see this. we should not have protectionism but the same opportunities for the EU in China as for China in the EU. We are not there now.
quadrifoliate 1 days ago [-]
> So for the most part, the EU has to work slowly and under the radar.
How convenient. If it wasn't for the US, the EU would work really fast and in the open! That is totally believable.
microtonal 1 days ago [-]
That's not what I said. Both can be true at the same time: the EU works slow; political repercussions requires the EU to work slow (regardless whether they are slow or not).
philipallstar 1 days ago [-]
I don't think the EU has the capability to work fast and just is opting not to.
embedding-shape 1 days ago [-]
> Even the urgency present during January's Greenland threats was gone after a few months.
There are troops deployed on Greenland right now ready to defend the island. The threat is not gone from the minds of the people there or in the rest of Europe just because you stopped reading about it on CNN or whatever.
Edit: I got curious if this part is even possible:
> leaving NATO completely
Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it. It also prohibits federal funds from being used to carry out an unauthorized withdrawal.
Seems some parts of the US has indeed managed to setup defenses against such idiocracy.
microtonal 1 days ago [-]
The threat is not gone from the minds of the people there or in the rest of Europe just because you stopped reading about it on CNN or whatever.
I don't watch CNN. I live in Europe, read European newspapers. It's just something that I noticed observing people. In January, a lot of people started thinking about moving away from US services, there were even newspaper articles about alternative smartphone OSes, etc. Now most people are back to business as usual. (Which doesn't mean that some countries aren't moving to alternatives, etc.)
Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it.
Agreed that complete withdrawal is hard currently. But it's a toothless tiger (as least with respect to the US) when the commander in chief says he will not defend a country because they have been unfair to the US.
My personal opinion is that the EU should just do what it needs to do, because NATO is effectively dead and reboot the alliance without the US in parallel.
wat10000 1 days ago [-]
Is a law going to stop it from happening? The destruction of USAID was against the law but it still happened. Let's say that the president announces we're leaving NATO, all troops stationed in Europe are leaving immediately, and we will no longer be bound to collective defense. What would actually prevent that from happening? Maybe we'd still be "in NATO" in some technical legal sense, but would it make any difference?
mitxela 19 hours ago [-]
Case in point: Trump just banned imports from Canada because they didn't cave to his extortion.
pocksuppet 1 days ago [-]
Trump doesn't need to block European access to Cloudflare when Europe already blocks European access to Cloudflare on weekends. In Spain and Italy. And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
embedding-shape 1 days ago [-]
Great, more misinformation. "Europe" doesn't block access to Cloudflare on weekends in either Spain nor Italy. Source: I live in Spain, and I'm affected by the blocks you're referring to, that happen because of shitty Spanish judges forcing Spanish ISPs to block access to specific Cloudflare properties.
Why not take even two seconds to check if what you're guessing about, might actually be correct or not? Or the goal is just FUD here?
> And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
Maybe because the impact of these blocks aren't as large as you allude to? Things change, these blocklists get updated. What was blocked 6 months ago no longer is, when these anti-piracy blocks happen.
Don't get me wrong, I don't agree with these blocks at all, and AFAIK, they break both national laws and wider "rights", but lets not pretend it's bigger than what it is in reality.
n6242 1 days ago [-]
If anything, you're the one misinforming. I have no interest in soccer and every time there is a match I find out immediately because they like to knock down everything they see in the same general direction. I've even been in the situation of needing to do work for overseas companies in the evening and had to get on a VPN because they were just blocking random stuff and I couldn't install some dependency because the repository was blocked. Last time it happened was last week. My non technical friend was also complaining about some of her uni stuff being blocked recently as well. Maybe you're lucky because only use YouTube and Twitter and don't notice too many sites blocked, but the moment you go outside of big tech your chances are 50/50 you will probably come accross one or two blocked sites if you're not on a VPN.
jonnybgood 1 days ago [-]
> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
You mean the US government working towards the interests of its people and economy? Which government wouldn't? It's kinda what we want it to do.
plufz 1 days ago [-]
I don’t want my government to be a corporate controlled army for the big corps in my country.
dofm 1 days ago [-]
I think if you think it's in the interest of the people of the USA for the country to be a cynical, overt, quixotic, childish bully on a global basis, including acting as goons on behalf of tech companies, that's an opinion you are certainly entitled to.
thesmtsolver2 1 days ago [-]
Didn’t you read the memo? Only European govts or China can act in the interests of their people and companies but if the US does that it is immoral.
lukan 1 days ago [-]
One difference is, EU or China don't act as global hegemon and claim to promote freedom, democracy and free markets for everyone.
ExoticPearTree 1 days ago [-]
> free markets for everyone
should read as "everyone the US likes", not everyone everyone.
JumpCrisscross 1 days ago [-]
> EU or China don't act as global hegemon
France has global geopolitical projects, as does China in South America, Central Asia and Africa. Both export arms into conflicts and conduct global intelligence operations.
lukan 1 days ago [-]
Sure, some also still dream secretly of a french global empire and french as the rightful lingua franca reinstalled. But de facto they ain't a global hegemon - the US is. And people were mostly fine with it, while they were not obviously abusing their position of power for themself.
JumpCrisscross 1 days ago [-]
> they ain't a global hegemon - the US is
This is currently a legitimately open question.
America acts like a global hegemon. My point is simply that France and China act similarly, too—they both project power across oceans and continents. (To what end is, as with America’s power projection, a good question.)
simondotau 1 days ago [-]
I agree with what you’re inferring. But that said, there’s a valid argument to be had that—for some things—your own government is a unique threat that other people’s governments are not, or less so.
I’m Australian, and if I was worried about the practical legal risk of being tracked online by a government, it’s mostly concern about my own. A foreign friendly government is mid tier: it’s unlikely that five eyes is an intel firehouse, so it’s unlikely for your petty domestic matter to be communicated. A foreign hostile government is probably safer if you’re committing domestic crimes.
quadrifoliate 1 days ago [-]
> Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
It's not the so-called retaliation of the US government that leads to European inefficiencies like paying notaries thousands of euros to read out a contract to you (several discussions going around about this in Germany recently).
This is ultimately just a boogeyman. European governments love to blame someone else for their inefficient and bureaucratic processes that stifle innovation and are slowly becoming the laughing stock of the tech world.
If they really want a thriving tech industry, EU should:
- Normalize laws and regulations relating to commerce and online activities throughout the EU. Get rid of the notary crap. While you are at it, get rid of the impressum (why the fuck should I need to post my home address on my website?).
- Ensure that these normalized regulations are available in the tens of languages across the EU
- Invest heavily in telecom and data center infrastructure and software on a European-wide basis. The current AI bubble will see a downturn but data centers and connectivity infrastructure can be reused for EU-based cloud services.
- Invite the UK back in once they are an actual economic powerhouse that can speak with one voice.
Of course none of this will ever get done because EU bureaucrats would rather be in a perpetual hand-wringing mode while blaming the Big Bad US Boogeyman for all their problems.
mitxela 19 hours ago [-]
That notary thing is very stupid but just one thing - let's not pretend the US doesn't have stupidity on that level too. DMV lines, anyone? One voting booth for an entire city because it's majority black?
quadrifoliate 16 hours ago [-]
Obviously, the US has lots and lots of stupid things.
The difference is that you typically don't hear "Oh we need to make slow progress on making voting easier, because the EU will retaliate". That would be absurd. We recognize that it's our own fault, i.e. the politicians that we are voting in.
bell-cot 1 days ago [-]
Upstream of all of those things is whether it's an actual priority for the ruling classes, or not. The politicians and bureaucrats are downstream of that, and physically incapable of wagging the dog.
shevy-java 1 days ago [-]
> Personally I think we absolutely should, I just don't think we will.
I think many millions in the EU want to. The problem is that the current EU "politicians" are just US lobbyists. You can see it when Leyen signed the
surrender treaty with her Overlord-buddy Trump. You can not fix the EU with
such lobbiysts in place - and it's not just Leyen alone. Look at Merz - the
guy basically is a tool used by US companies. He is not the brightest but
very loyal to the USA. More than to the people who voted for him (and now
curse themselves for having made such a big mistake).
expedition32 1 days ago [-]
Compared to the Spanish empire, Napoleon and Hitler the Americans are but whiny children. It would be one last hurrah for my country to break away.
throwaway613746 1 days ago [-]
[dead]
cbg0 2 days ago [-]
> The front door is not the whole stack
Hey Claude, can you move the ciphercue blog to Cloudflare so it can deal with traffic from HN?
On a more serious note, Cloudflare comes packed with features even on its free plan which makes it useful for any size website. For a real business it's one of the cheapest options for DDoS protection on the market. Some years ago you would have paid a fortune for Akamai or Level3 to help keep you online and now you can get by on a $200 a month plan for a small business.
embedding-shape 2 days ago [-]
> now you can get by on a $200 a month plan for a small business
You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.
stronglikedan 1 days ago [-]
If it's one thing I learned from my old web hosting business, it's that any website can be in immediate need of a CDN or DDOS protection at any given time. It's the only business where my customers were randomly attacked for seemingly no good reason. It's also why I got the hell out of that business.
cbg0 2 days ago [-]
What you're paying for is business continuity, not for them to host your site. I know you can host the site itself on much cheaper infrastructure.
cyphar 1 days ago [-]
If your site is static you can host it on CF pages for free with unlimited* egress.
* of course it's not unlimited unlimited but I've not heard of anyone being cut off.
veeti 1 days ago [-]
The internet is a dangerous place and some people will be dicks even if you aren't making any money. Most hosts will show you the door the someone puts their crosshairs on you. Some small businesses like gaming are disproportionately effected.
viraptor 1 days ago [-]
> you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you
This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.
embedding-shape 1 days ago [-]
> Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.
Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.
But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.
viraptor 1 days ago [-]
It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service.
> and I don't think people should default to trying to prevent them.
It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.
Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)
cbg0 1 days ago [-]
I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada:
That graph is useful for the people who think DDoS is the biggest issue or even a big issue typically: https://www.bdc.ca/globalassets/digizuite/55250-canadian-sma... "Percentage of Canadian small businesses that have experienced a cybersecurity incident"
The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.
cbg0 1 days ago [-]
What exactly are you arguing? I already said 5%. Your personal experience of DDoS being super rare doesn't seem to match the real world.
embedding-shape 1 days ago [-]
Literally the graph you posted agrees with me. Most "cyber attacks" are phishing according to that graph, which I'd argue is less of an technological attack and more social engineering.
Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.
> Your personal experience of DDoS being super rare doesn't seem to match the real world.
What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.
pocksuppet 1 days ago [-]
For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days.
Hikikomori 1 days ago [-]
Wouldn't most udp reflection attacks be bigger than your pipe?
mitxela 18 hours ago [-]
Is that still a thing? What are they reflecting from? Where are they getting unfiltered uplinks?
Hikikomori 11 hours ago [-]
Not as common anymore, but the guy I responded to mentioned 30 year history.
theideaofcoffee 1 days ago [-]
Dozens and dozens of times. And having the bigger pipe has always saved it, along with the supporting infrastructure to churn through that traffic.
> But again, those sort of attacks seem to happen seldom
[citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.
xboxnolifes 1 days ago [-]
Nobody needs DDoS protection... until they do. It only takes 1 disgruntled person with a few dollars to take down a cheap server for days.
bryanrasmussen 1 days ago [-]
I think their delusion is probably in what they consider a small business. A lot of people on here, given their work experience, think of small as something with a few hundred employees.
cbg0 1 days ago [-]
Given that we're on HN I probably should've said startup, though depending on the business itself it's not unrealistic for some of those 200-400 employee companies to sit on a free Cloudflare plan if their entire website is static + a back-office CRUD app.
If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.
bell-cot 1 days ago [-]
> ... think of small as something with a few hundred ...
Yes, plus a strong bias toward IT-heavy businesses. Vs. if my company is doing commercial landscaping, or machining gears for automobile transmissions? Several hundred employees still gives me no reason to pay much for web hosting.
mschuster91 1 days ago [-]
> Most websites don't need a CDN nor DDOS protection
A CDN not, and certainly not a global one.
But unfortunately, you absolutely need DDoS protection, especially as a business. Too many shady actors and skiddies pulling off extortion/protection racket scams - a complete and utter lack of telco regulations, AI, tons of unsecured IoT devices and shitcoins truly have made for a terrible mixture.
Sure, a 50€ a month server at Hetzner, OVH or whatever is more than enough to host a website. If you're not running some NodeJS garbage, a 5€ VPS can be enough. But at the first sign of you being targeted by a troublemaker, your hoster will cut you off just to protect their other customers.
dwroberts 2 days ago [-]
[flagged]
microtonal 1 days ago [-]
I think they articulated the underlying issue well. Cloudflare is too attractive for individuals and small businesses. For instance, my personal website has a healthy amount of traffic, but means nothing at CDN scale. I considered moving to a EU CDN company, but they all have per GB/TB pricing. It would cost me nothing now, but what if my site comes under attack or someone starts hotlinking a large file? So, I stay with Cloudflare because with their free plan I don't have to worry about such contingincies.
I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.
cbg0 2 days ago [-]
I was explaining why I believe it's a super popular service. I have no affiliation or stock, just a regular user.
I've been using bunny.net for a while and it's not bad. It has some rough edges, but it does what it's supposed to and I haven't experienced any downtime.
The main "gotcha" is that there's no free plan, it's a minimum of $1 per month, you pay for usage. In practice it's very hard to spend more than a dollar in a month.
spiderfarmer 1 days ago [-]
I spend 40 euros per month, with 75% because of AI scrapers.
draxen 1 days ago [-]
None of them have the unmetered anti-DDoS and global CDN/caching combination like Cloudflare.
Which is weird. CDN requires massive distributed footprint, which inherently provides the enormous network capacity needed to absorb DDoS attacks. So why aren't they offering the same thing as Cloudflare?
European CDNs should form partnerships with both European IXPs and Tier-1/Tier-2 ISPs (like Orange, Deutsche Telekom, etc.) to see what exactly is missing to do both unmetered anti-DDoS and global CDN/caching.
mitxela 18 hours ago [-]
LOL Deutsche Telekom... Their peering policy is "don't".
Havoc 2 days ago [-]
Bunny.net is a good alternative - they don’t have CF depth of offerings but are getting there
jarco 1 days ago [-]
I tried them with our small company.
They seem ... young. Support on discord is not something I can sell to our owners.
We sent a ticket that activating some of their services instantly caused bad bots to scan our site, and never got a decent reply on that.
Their attitude does not inspire confidence and for that reason we scrapped them as an option.
Never actually found a good European option besides them, which is sad.
viraptor 1 days ago [-]
> We sent a ticket that activating some of their services instantly caused bad bots to scan our site
You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.
bcye 1 days ago [-]
There is a normal support ticket system not on Discord, which they loudly advertise for having a very good response time. The Discord server is not the primary support method
AndroTux 1 days ago [-]
In my case, the claim was justified. Got a technical response answering my question in detail after half an hour or so.
boesboes 1 days ago [-]
That's also my experience. I did have a few instances of 'random requests failing' they couldn't really diagnose back when they were new; but that was just amazon dropping request in the end
Service has been great, prices like 10% of cloudflare too once you get the real pricing :P
kosinus 1 days ago [-]
Like, the bad bots you see when they get an https cert issued and it becomes visible in the public logs, or something else?
Agree discord sucks.
frevib 1 days ago [-]
We use them en they have improved a lot in the last year. For edge services they have all the important thing like ddos protection and edge scripting. There is no replacement for Cloudflare Tunnel, but frp [1] is a good alternative.
They're fine for a CDN but overall their offering surprisingly immature IME. The devx for their hosted scripts/database just isn't there, and e.g. they only allow one global API key with full permissions, etc.
Havoc 10 hours ago [-]
Yeah noticed the key thing too - that seems quite dangerous for things like DNS challenge
Bunny is the MVP among these European alternatives. It's not just a CDN, it offers Cloudflare-style Edge scripting, Edge workers, databases (Sqlite compatible) etc.
s_dev 1 days ago [-]
MVP would be widely understood on this forum to mean "Minimum Viable Product", I don't think that's what you meant. Options are always good to have.
boesboes 1 days ago [-]
true, but MVP -> most valuable player might be even more common on the internet, interesting conundrum tbh haha
jarym 1 days ago [-]
Like bunny.net - its still tiny compared to CF but hopefully they will grow and won't adopt the crappier bits of CF.
CommanderData 2 days ago [-]
They don't have Cloudflare Tunnels which is almost too good to pass up.
I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.
ramon156 2 days ago [-]
big corps = big money. they dont make money from your $5/mth static site, its practically free when you're at CF scale
10+ BT trackers using CF likely free tier. Low-end EACH 300-500 MILLION HTTP requests/24hr uncached, some exceed a billion reqs/day (using statistics from other open trackers) 20TB-40TB daily, ~1-3 Gbps sustained.
That's a crap load of transfer and compute to process those tiny network connections. As someone that's run a Tunnel on a normal site in the millions, the daemon uses a sizeable amount of CPU and I can't see any reason why it's not the same on the other end.
Whatever source CF has going on, kudos to them and their engineering team.
viraptor 1 days ago [-]
Lots of people will run http over the tunnel rather than https, so that actually comes out cheaper for CF overall because they don't have to start new TLS sessions.
tmtvl 1 days ago [-]
If you're not paying, you're not the customer; you're the product.
I wonder of the CEO ever got back with an update. It seems awfully quiet in that thread.
8by3 1 days ago [-]
When someone says cloudflare is too good / cheap to be true... maybe think about it.
They have shareholders, who wouldn't allow them to provide value for free, its just not obvious to you how they are extracting that value. Maybe its by capturing a huge % of unencrypted https traffic because if you let them do your certs it means they can read all your real traffic.
smw 1 days ago [-]
There are lots of companies that provide low end services for free to attract people who may now or in the future be decision makers at large companies.
stroebs 1 days ago [-]
For better or worse, the free plan that Cloudflare has provided me for 10 years for my 20-30 hobby/personal domains has gotten them several hundred thousand dollars in business.
8by3 1 days ago [-]
indeed, typically by using their huge cash piles to build a moat around them, so no small new player has a dream of competing.
This is why I refuse to give any money to AWS/GCP/Azure or anyone who runs on them.
mitxela 18 hours ago [-]
You should avoid giving them money because they're 50 times more expensive than the competition, not because of that.
DarkUranium 1 days ago [-]
I'm pretty sure that's impossible nowadays, at least avoiding everything that runs on AWS.
boesboes 1 days ago [-]
I'm pretty sure it's not really any different from a protection scheme that turns into vendor lock in.
huzefashaikh 23 hours ago [-]
[dead]
lII1lIlI11ll 1 days ago [-]
> They have shareholders, who wouldn't allow them to provide value for free, its just not obvious to you how they are extracting that value. Maybe its by capturing a huge % of unencrypted https traffic because if you let them do your certs it means they can read all your real traffic.
If it is "not obvious to you how they extract the value", you can just look for NET (their ticker) earning reports and SEC fillings since they are a publicly traded company instead of spreading conspiracy theories...
pjmlp 2 days ago [-]
The problem is that we have spent 40 years adopting US technology, across multiple generations of software developers and decision makers, while everyone was supposedly on the same side.
It will take similar amount of years to go back into the cold war heterogeneous computing landscape of the 60, early 90s.
This assuming there would be an willingness across all European countries to actually push for that, and not jump out when it gets too hard and search for compromises instead.
This is why most sovereignty initiatives focus mostly on SaaS products and hardly on actual computing devices.
sajithdilshan 1 days ago [-]
Even if EU countries want to push for their own solutions, the biggest problem is the capital. The governments cannot fund this with tax payers money because they have other critical problems to solve and private companies only go far if they can make a profit.
Only time will tell how far this sovereign movement would go. Maybe when the US would have a president/government from the Democratic Party someday in the future. EU would cozy up again to US and go back to how things were. There’s no permanent enemies or allies when it comes to politics and at the end of the day it all revolves around money
pessimizer 1 days ago [-]
> The governments cannot fund this with tax payers money because they have other critical problems to solve
The governments can's solve this problem because the entire economic model of the EU is that the core exploits the periphery, who don't have a currency that they can weaken as a response. If they had a strong democratic central government and a real central bank in the EU, they'd be forced to make transfer payments to the weaker members, and to bail them out (losing the leverage to make elite demands on them.)
The EU as a whole could easily solve the problem, they have the population, the talent, and the infrastructure. They're just really docile from the CIA and their own elite cliques working on them for the better part of a century.
> Only time will tell how far this sovereign movement would go.
There is none. Blah blah blah in the media isn't a "sovereign movement." It's a campaign to get you to vote for the same middle of the road radical centrist neocons served on a substrate of normie-relaxing anti-Trump rhetoric.
mrits 1 days ago [-]
The current Europe strategy seems to be to pay software engineers less money and hope for a superior product. I'm not sure how you'd catch up when some of your engineers literally make less than our fast food workers.
pjmlp 1 days ago [-]
I rather have 30 day vacations, a proper life with 40h work week, healthcare, union membership, than SV salaries, which are nontheless an exception, most of the developers, that aren't even properly accredited Software Engineers, get the same salary as most office workers.
In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?
doublepg23 1 days ago [-]
> In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?
I'm American and I take 30 days of PTO a year. I get paid the national median for pay, but that still puts me in the top 10% of _household_ incomes for my state. I have good healthcare and benefits. Hell, I got sick last year and took 2 months off from work paid because my company has the policies to cover that and then I came back and it was fine.
Like, I find SV culture and living to be a cancer, but I'm just saying as someone who doesn't live in a top 10 city in the US with a MCOL, I struggle to think of how working as a software engineer in the EU would be better.
It's been over 10 years since that 2 weeks PTO nonsense applied to tech. I don't even have a fancy job. I work for a bank.
mitxela 18 hours ago [-]
Your bosses can only afford to give you that and high salary because they aren't giving it to everyone.
petcat 1 days ago [-]
> I rather have 30 day vacations, a proper life with 40h work week, healthcare, union membership, than SV salaries
This is an appeal to mediocrity and it doesn't really hold when comparing EU to Silicon Valley tech jobs. Young engineers in the Silicon Valley (or NYC, or Seattle) have excellent health care, generous vacation and other benefits, and they also make substantially more money.
Why would a young, ambitious engineering graduate care about taking 30 days off when they have the opportunity to work on frontier tech that is only available in the US? And make an absurd salary doing it? Healthcare is also less of a concern because 20 somethings and 30 somethings barely use any social benefits anyway. And like I said earlier, they also have exceptional private health care through their employer.
This claim that the European lifestyle is somehow better despite the extreme salary difference really just doesn't hold when comparing to early/mid-career tech workers in the US.
pjmlp 1 days ago [-]
That is what late capitalism expects, 20 something year olds willing to do whatever it takes to get that dream job, changing the world with code, as if.
The games industry and Hollywood have that lesson very well thought out.
maxcoding 2 days ago [-]
I feel like your site needs a CDN, it takes over 40 seconds to load your front page from the EU.
dotcoma 2 days ago [-]
Maybe a European CDN, like Bunny (Slovenia)
unglaublich 2 days ago [-]
Do they also have their own infra or are they just an entity between the customer and AWS?
ramon156 2 days ago [-]
They have their own infra but its not the size of CF. Chicken and Egg
roshanabdullah1 1 days ago [-]
I have been personally using Cloudflare, and I must say, It is a great choice for small sites, even if you are willing to scale, Cloudflare works great!
It provides you with all the tools necessary to scale your app.
piskov 1 days ago [-]
Why not use cheap vps?
It will not get down with half of the internet the next time cloudflare has issues.
reincoder 1 days ago [-]
I was looking into the IPv6 adoption of US government websites (https://community.ipinfo.io/t/the-state-of-ipv6-across-us-go...) when we discovered that Cloudflare had essentially dethroned Akamai for government content hosting over a number of years. The post primarily focuses on IPv6, but according to our data, Cloudflare hosts 70% of US government websites.
1 days ago [-]
arjie 1 days ago [-]
Cloudflare is a great service and nearly free on low traffic sites. This describes a surprising amount of competence among European webmasters of small sites.
nonethewiser 1 days ago [-]
Yeah this is basically my reaction. 9/10 use it because it's obviously the best solution.
The real point is what's between the lines: A growing number of European techies are not optimizing for the best technical solution.
At least on hackernews. The observed stat says otherwise, up to this point in time at least.
Personally I love using cloudflare. I am always surprised to see the hate from devs here. I would expect it to be beloved.
nottorp 1 days ago [-]
Cloudflare is the only CDN with a free tier that's basically enough for personal use and even a small organization, right?
tlogan 1 days ago [-]
The biggest problem with Europe is the lack of innovation. But that was not an issue before.
Before the 2000s, Europe was very very strong in telecom (Ericsson, Nokia, Siemens, Alcatel), industrial technology, the auto industry, mobile phones, semiconductors, and enterprise software (SAP, Baan, Business Objects, Dassault Systèmes, sage). Europe was definitely much less dependent on U.S. technology back then. In some area I would say it was the other way around.
But Europe's dependence on U.S. technology has accelerated dramatically over the last 10-15 years.
I'm really not sure why. Regulation and bureaucracy did not get worse. And Europe even created the EU, which provided a better "single market" (better than before the 2000s).
I would love to hear some opinions on what changed.
mitxela 18 hours ago [-]
Before the 2000s, Berlin was still ruled by squatters and illegal techno clubs.
hnisjafx40 1 days ago [-]
the actual asymmetry isn't nsa, it's that cloudflare terminates tls for ~20% of the web in one place — one config push and everyone's plaintext moves.
mitxela 1 days ago [-]
People rarely reach for a CDN. They only ever reach for Cloudflare. Nobody's reaching for Akamai without a good sales pitch, nobody's tossing up between Akamai and Cloudflare, everyone's using CF because it's free. And they don't need the thing CF offers, they don't go out looking for it, it comes to them and they say "that sounds neat" and set it up.
seki285 1 days ago [-]
Nobody can also afford Akamai unless you're a fortune 500 company, CDN alternative like bunny.net exist but it lacks so much compared to cloudflare.
mitxela 1 days ago [-]
What are your requirements
everfrustrated 1 days ago [-]
Last I looked you can't even use Akamai without signing a sales agreement ahead of using them.
mitxela 1 days ago [-]
That's how most businesses work, yes.
em500 2 days ago [-]
Tale as old as time (or at least as the 1970s): nobody ever got fired for buying ~~IBM~~ Cloudfare / AWS / Azure.
9 out of 10 corporate decisions are for blame avoidance / ass covering.
chpatrick 1 days ago [-]
It's actually a great service though.
viraptor 1 days ago [-]
It's also a great protection racket. They host many DDoS provider sites and protect them from law enforcement.
viraptor 1 days ago [-]
Someone's eager to downvote this, but it's been known for a long time and still happens in obvious ways. First page of results for booter services contains https://zeusstress.com/ which is hosted by Cloudflare (yes yes, ceo will send lawyers to say they only proxy not host - doesn't matter in practice)
edelbitter 1 days ago [-]
.. 9 out of 10 unhappy customers are currently unable to cause any blame, because they cannot even reach customer service because they are getting the "bot" treatment.
Danoch 1 days ago [-]
[dead]
bildung 2 days ago [-]
I'd also be interested in share of companies using a CDN in the first place. UK has 17k sites, while France and Germany, so countries with about equal and higher population than the UK, have only 4k and 6k sites behind a CDN.
I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?
embedding-shape 2 days ago [-]
> I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?
Maybe our countries are just small enough to not be overwhelmed by traffic? Most websites I've built and launched for Spanish national companies, that only have other Spaniards as users and customers, haven't needed any CDN at all, because you don't suddenly get 1K req/s. Meanwhile, launch a global website in English, that even get the slightest amount of popular, and all of a sudden you reach 1K req/s very quickly. Add on top that people usually don't even give two cents about performance, and adding CDN on top as a saving grace seems like an easy tradeoff.
So, why add a CDN when you don't need it? :) Probably 80% of everything I've ever deployed never needed a CDN in the first place, but I also save it as a thing in my toolbox to be used sparingly, rather than a default thing I slap on top of everything.
ivlad 1 days ago [-]
nginx can do about 20krps per CPU for static files. You only need CDN if you want to improve time to DOM loaded in locations where time to first byte is over ~100ms and can be improved with local caching.
If all your users are in Spain and you don’t care how fast your site loads for a techbro in California, you indeed don’t need CDN.
JimBlackwood 1 days ago [-]
It’s a limitation of their dataset. If you take all domains, it definitely creates a different picture.
For both France and the UK, less than 15% of sites are behind a CDN. For both, around 95% use Cloudflare.
So in terms of percentages, there’s not much of a difference.
wiether 2 days ago [-]
Their index being paywalled, it's not possible to answer about its content.
I wanted to check if the 5 customers for which I already did a change on their Cloudflare settings today where on the list, but can't do.
pajamasam 2 days ago [-]
I'd be interested in what data they're using in the first place. It looks like their data is behind a paywall.
Also, funny that their page with for "Companies running Cloudflare" says there are only "887 European organisations using Cloudflare."
helsinkiandrew 1 days ago [-]
> I only counted companies that actually run a CDN. If a company serves its site straight from its own origin, it is not in these numbers at all
Doesn't this miss websites that serve their own site html but serve (static) assets from a CDN.
This seems to be a common pattern with Wordpress sites, presumably because it makes cache configuration simpler
inemesitaffia 1 days ago [-]
It's always surprising to find a website that's not behind CloudFlare, Akamai, DDOS guard or Fastly.
BTW CDN is a terrible business.
The only thing worse that's adjacent is rural Fiber and seemingly Wholesale IP transit.
mitxela 18 hours ago [-]
I'd tolerate DDOS-guard - they let you host illegal stuff
inemesitaffia 16 hours ago [-]
I noticed a lot of illegal video sites now host their video itself via CloudFlare.
Before they'd use some European host or file locker.
I wonder about the economics and how it's hidden.
jamesnorden 1 days ago [-]
You have to ask why they're so "generous" with giving away free services.
bell-cot 1 days ago [-]
Looking back over the past 3-ish decades, becoming utterly dominant in some part of "essential" stuff on the internet has a way of paying off big.
(That is Cloudflare's 10-K for calendar 2025 - scrutinized by serious investors, and with heavy penalties for lying.)
victorbjorklund 1 days ago [-]
Bunny CDN for the win. They are awesome, European and affordable.
stef25 1 days ago [-]
While digging deep to speed up a website loading time, Cloudflare's offerings made the biggest difference. Rocketloader and a few others. Immediately noticeable.
talhaanwar 1 days ago [-]
I think everyone use cloudflare in the world. Setting up DNS is not easy without cloduflare. I also use cloudflare tunnels for DNS
mitxela 18 hours ago [-]
what else did you try?
Zaheer 1 days ago [-]
Has anyone used Cloudflare's enterprise bot packages and have first hand experience with AWS's equivalent offering? Would love to chat.
password4321 1 days ago [-]
Surprised to see no mention of Cloudbleed yet, something like that is when this centralization hurts the most.
vaylian 2 days ago [-]
Naive question: How important is it to use a CDN in the first place? Why can't you just serve the content yourself?
viraptor 2 days ago [-]
It depends on what you're trying to serve, but it's used to either save you money or as an insurance (or both). You don't need a CDN overall. But if you grow large enough, at some point you'll run into one of these three situations:
- Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead. (Where the cache size is larger than anything you'd want to support yourself. For example, if it's <1G and survives your service restarts, you may want to do it yourself)
- Your customers on the other side of the world start complaining that the resources take ages to load.
- Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.
pluc 2 days ago [-]
This article being down/slow is a great response.
vaylian 1 days ago [-]
Not to discount the experiences that other have, but the site loads fine for me.
_joel 2 days ago [-]
Reduces latency when the cached content is served from a local cdn pop, allows you to absorb some level of DDoS, can absorb traffic spikes more easily so infra can be more static, reduces load on server if assets are dynamically generated on the backend but can are cacheable, some senses can lead to simpler deployment as you serve assets from an object bucket, so no need to deal with keeping that data in your cluster, but that's minor.
There are downsides too, cost, over caching, privacy/security perhaps too.
unglaublich 2 days ago [-]
Because an average request would have to travel half the globe, so setting up a simple HTTPS connection would already take a second. That's completely unacceptable for static content.
Not only would transfer be slow, they would also be much more pressing on the network as the request would occupy huge stretches and many interconnects and switches.
Furthermore, it hardens the website against DDoS and adds robustness for regional failures.
ivlad 1 days ago [-]
Minority of sites have global traffic. This is especially true for non-English sites.
So, while average request may have to travel quarter (not half) of the Internet globe, median request from the set of requests that matter has much lower latency.
Barcelona to Stockholm is about 65ms, ~35ms to Amsterdam, ~43ms to Frankfurt.
HTTP/3 is ubiquitous, you don’t get TCP handshake penalty anymore in major browsers.
pocksuppet 1 days ago [-]
In most cases, it's not important and you can, but you are bandwagoning and/or being fearmongered to.
esseph 2 days ago [-]
The site this is about is current down due to HN traffic.
Lol
embedding-shape 2 days ago [-]
Depends on your use case.
If you have a very inefficient backend (maybe legacy project?), you have massive amount of traffic (say 100K req/s or above) or you really must have sub-500ms latency absolutely everywhere in the world, then it might make sense to slap a CDN (or similar) on top of that.
In pretty much any case outside of that, it makes no sense to waste the time, money or effort on CDNs. But, all the CDN companies seemingly have convinced half the internet that you absolutely must use a CDN, otherwise you'll get hacked/broke/killed/sent to the moon, and they've been successful with this campaign too seemingly.
bdauvergne 1 days ago [-]
How does a cdn makes you backend faster or your latency better ? I thought it was only for distributing static assets and managing DDOS. If it is for cachable but dynamic content install reverse-proxy cache it will fly.
embedding-shape 1 days ago [-]
Because it lets you use it as a geographically distributed cache basically. Most GET requests should be able to be cachable on the typical website, besides the ones that are unique per logged in user or similar.
If your server is in Europe, and you have Australian users, there is a physical limit how low the response times can go, serving bits over that distance, so only way you can make it go below that limit, is by moving where you serve the data from closer to the user.
Lots of websites have horrible performance for whatever reasons, and lots of freelancers/consultants basically default to throwing a CDN on top of those when they get approached by businesses to fix the slow website browsing, as they're not the ones who have to pay the monthly subscription, and the less work they have to do, the better $ per hour spent for them.
I agree that it's a shit solution and there is much better sustainable ways of solving these things.
esseph 2 days ago [-]
Data scraping.
If anything else, the AI machine wants near constant streams of new data, even if it already checked with you 30ms ago.
A CDN helps immensely.
Also keeps you from getting DDoS'd if you did something like run it off your home connection.
embedding-shape 1 days ago [-]
Your webserver most likely have "rate limiting" built in already, which you can configure to act based on lots of variables typically. Set a limit of 1 req/s or whatever, and you've stopped 99% of all DDoS you'll encounter on the public web. If your visitors get cranky, up it to 10 req/s and you still are preventing most of the "abusive traffic", granted your backend/website isn't completely upside down when it comes to performance and resource usage.
CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.
viraptor 1 days ago [-]
This is not how things work and no company providing online services for money would rate limit like that. This would do nothing for real world DDoS. You're in "not even wrong" territory.
And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.
embedding-shape 1 days ago [-]
Yeah, of course if you're a large service, stuff that works for SMEs isn't gonna work for you...
If your problem is AI crawlers, then simple rate limits help, I've helped countless of businesses with this already. For the ones that it isn't enough, you continue adding more roadblocks. There is no "one size fits all here" and that you seemingly is under that belief, leads less credence to what you're saying, not more.
esseph 1 days ago [-]
Brother if you have the solution, start a company.
There are people willing to throw money at you.
But Free is hard to beat with a global presence.
And please listen to what others are saying here, there's a lot of experienced people here. It is no longer 1998, 2008, or even 2018. The traffic a basic website experiences now is a massive increase, especially for those well SEO'd and using TLS.
Also you said this:
> CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.
Origin obfuscation.
Also greatly helps to protect it directly from various attacks and scans, especially in our new LLM driven security world where new 0days are being found constantly. How much at risk are you willing to put the SMB?
j16sdiz 1 days ago [-]
Rate limit never work like that in large volume.
Keeping connection alive take memory.
Rate limit by bytes/sec would hold the connection longer, taking more resources.
Rate limit by ip don't work with sudden surge demand, ddos, etc
Rate limit by user basically means you need to process the request and CPU bound
In very large scale DDoS, incoming SYN alone can cog your down pipe. You need to upgrade the connection just for that
(Or something on your upstream to block by ip)
You can do lots of these without using cdn, yes. But it is easier with cdn and it is cheaper than paying for extra capacity "just in case"
1 days ago [-]
bborud 1 days ago [-]
If, for a moment, we set aside the fact that Europe is strongly incentivised to depend less on the US, and US companies, it should worry us that so many sectors are dominated by 1-3 or so players. One of the selling points for market capitalism, which we at least pretend to believe in, is efficient allocation of resources through competition. But when the market is dominated by de facto monopolies there exists no real competition and there is no real market.
Even in the previous political climate this should, objectively, be deemed a problem. Having 90% of all eggs in one basket is neither good, nor does it constitute functioning market.
I'm not sure what the Cloudflare market share is in the US, but if it is the same as in Europe, this is a problem for US companies as well.
elai-intelligen 1 days ago [-]
If we're speaking strictly on Cost and your ROI, Cloudflare is pretty much unmatched.
amelius 1 days ago [-]
But isn't a CDN a commodity? I.e., you can switch to a different one with almost no effort.
AndroTux 1 days ago [-]
Depends how deeply integrated it is. Cloudflare offers a web application firewall that can quickly become complex, alongside features like custom routing rules, input parsing, custom headers, etc. As soon as you start integrating any of those into your environment, migration becomes more difficult fast.
pyvpx 1 days ago [-]
How does that quip go again…there are only two difficulties in computer science, cache invalidation, naming things, and counting.
Going from one CDN to another can be infuriating even at a surprisingly small scale. Mostly (imo) from caching semantics and counting.
amelius 1 days ago [-]
Can you give a practical example?
kypro 1 days ago [-]
It's not really a commodity when Cloudflare is often cheaper, simpler and provides a better service compared to it's competitors.
For it to be a commodity there would be no good reason to pick Cloudflare over any alternative and this absolutely isn't the case.
drchaim 1 days ago [-]
How I miss those NET stocks picked up at about 15$ after Covid…what a fail…
pdimitar 1 days ago [-]
And? Why should they not use Cloudflare?
What do the EU investors do outside of demanding guaranteed profit with zero risk for them? How many are ready to absorb 10-30 years of new infrastructure investments and play the long game?
If the EU wants to compete, well, here's the global market, right that way. ==>
Get to it. Nobody is actually stopping you.
But if you have no appetite for risk, don't complain when one day you realize you don't have EU alternatives.
VBprogrammer 1 days ago [-]
Cloudflare interstitial pages are becoming the new cookie / GDPR pop-up for me. Remember when the internet used to be good?
viraptor 1 days ago [-]
Unfortunately that one's on the operators. I can complain for days about CF, but nobody is forcing the companies to default to giving everyone a managed challenge page. Some do, because either they don't care or don't realise the extra cost.
cassianoleal 1 days ago [-]
Same but they're so much worse than cookie banners...
ObscureScience 1 days ago [-]
My employer uses CDN77. Only for serving static resources.
simondotau 1 days ago [-]
But do they offer even 10% of the features Cloudflare offers to free customers? To imply that Cloudflare is merely a fancy CDN is to miss the whole point.
Tepix 1 days ago [-]
It's the same issue as being cloud agnostic.
If you use their unique features, you're locking yourself in. Is it worth it?
simondotau 1 days ago [-]
I get it. I’ve consciously avoided that exact trap with AWS. But Cloudflare aren’t giving me “features” so much as they’re allowing my site, which is routinely DDOSed, the ability to remain online at all.
ghoshbishakh 1 days ago [-]
Because they are free. Almost for everyone.
schnebbau 2 days ago [-]
Yeah because it's priced well and it works. It's a no-brainer. (Also if it does go down, well so has everyone else so no big deal)
Also in this list of GOATed companies: Tailscale, Ubiquiti.
parasxos 1 days ago [-]
In control systems, one vendor behind nine out of ten front doors has a name: common-mode failure. We get audited for it. The web apparently calls it best practice.
0trip 1 days ago [-]
i just found out about cloudflare recently. And it is amazingly smooth compared with GCP and AWS
ericpauley 1 days ago [-]
AI;dr
postepowanieadm 1 days ago [-]
Company samples are tiny.
christkv 1 days ago [-]
I don't have to talk to any sales person thats the reason I use it.
raverbashing 1 days ago [-]
It's hard to beat the "free DDoS" protection of CF. Could even be considered dumping in a way
shevy-java 1 days ago [-]
The EU needs to stop giving money to the USA in general. They contribute to their own demise by doing so. Canadians understand this so much better than the EU, so the only logical conclusion to be made is that the EU is currently controlled by US lobbyists. This would explain about 80% of the issues; the remaining issues are inertia within the EU, but it also isn't made any easier when the US government constantly favours US mega-corporations ruthlessly infiltrating and abusing other markets.
trilogic 1 days ago [-]
ignorance at the pick
dakolli 1 days ago [-]
In the late 90s and early 2000s the NSA and other US intelligence agencies underwent massive efforts to basically privatize the gathering of intelligence. Its a lot easier to fund your "total information awarness" initiatives via public markets and private investors than to ask congress for money to do so. So they did just that.
"In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year."
--Matthew Prince's Wikipedia page.
Dont for a second think cloudflare's generous free tier offerings are out of the goodness of their heart. They're a giant fkin MiTM project for the US governemnt. And of course, cloudflare isn't the only one.
2 days ago [-]
bethekidyouwant 1 days ago [-]
90% of the CDN market is Cloudflare. I’m not reading this stupid article.
pessimizer 1 days ago [-]
Pretty sure that Cloudflare has absolutely no moat in Europe, and could be replaced by any adequately funded European version. Never believe that European talk about separating from the US is anything but slop for the plebs.
mitxela 18 hours ago [-]
Their moat is mindshare.
Aditya_0315 1 days ago [-]
[flagged]
tunahanfaruksav 1 days ago [-]
[flagged]
iamislida 1 days ago [-]
[dead]
miu33 1 days ago [-]
[dead]
hn45e7pbij 1 days ago [-]
[flagged]
herbertyang 1 days ago [-]
[dead]
dansmet 1 days ago [-]
[dead]
Yash16 1 days ago [-]
[dead]
CrimsonRain 1 days ago [-]
[flagged]
bean469 1 days ago [-]
> This article is as useful as writing sky is blue.
Subtle
DuncanCoffee 1 days ago [-]
4edgy5me
tolusky 1 days ago [-]
[flagged]
cassianoleal 1 days ago [-]
Do you mean US national security?
chrocni380 2 days ago [-]
[flagged]
Steve16384 2 days ago [-]
How did you extrapolate that leap of logic? Maybe we suck at business.
ilikerashers 1 days ago [-]
We have stagnant economies with slow adopters and shallow capital markets. EU tech companies are working with hands tied behind their backs.
The US deserves it's success.
throw93947309 1 days ago [-]
[flagged]
AndroTux 1 days ago [-]
This has to be rage bait, right? Ever heard of GDPR? How about ICE?
throw93947309 1 days ago [-]
ICE does not have a jurisdiction in europe.
AndroTux 1 days ago [-]
Exactly.
bdauvergne 1 days ago [-]
Is it satire ? Laws apply to the publisher not to the TLS endpoint.
tonyhart7 1 days ago [-]
so instead of developing actual competent solution, European complaining about why US tech dominate ?????
what stopping europe from using their home ground solution ??? nothing
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.
Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well.
A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.
Though I do remember some storage related complaints here on HN, other than that I haven't seen much about them on this site either!
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.
The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.
Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.
> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
ISP taps globally, undersea cable taps, the list goes on.
[1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...
That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.
If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
NSA putting implants into Cisco equipment before delivery to the customer.
https://www.certificationkits.com/nsa-upgrade-process-cisco-...
ANT catalogue from 2008 with hacking equipment:
https://dcssproject.net/ant-catalogue/index.html
This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.
https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...
"the NSA learns everything there is to know about you and your customers"
Which implies that they are looking at it all and records it.
The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.
That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.
I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.
Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.
I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
https://en.wikipedia.org/wiki/Utah_Data_Center
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
https://en.wikipedia.org/wiki/Room_641A
Public information shows that the NSA has been active intercepting as much data as possible.
It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.
"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)
I think spying on traffic is just a massively simpler task than generating content.
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
Literally? What is the reference here?
It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.
Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
Or clouds in general, its all wishful thinking and pinky promises.
[1]https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_C...
I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
>doesn't offer an alternative and leaves
Every. Single. Time.
Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
I don't think it's convincing
If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.
The fact is businesses do "tolerate it"
For example,
https://en.wikipedia.org/wiki/Cloudbleed
The MITM design of CF is what it is
It creates risks, but these risks are tolerated
For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost
The damage of being spied upon, if there is any, is already done
1. It's not clear why commenters are only concerned about intelligence agencies
"Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752
If you just need a single server that you don't care about then it's way cheaper to just own it yourself. You probably don't need 99.999999999999999% guarantees for your data, but if you're a bank then you do need those guarantees because losing all of your documents would be disastrous.
Normal people aren't worth anything to them. A company might spend a million a month with AWS, to get that with normal people you'd need at least a hundred thousand customers. And those people are going to spam you with tickets and do silly or illegal things. They're just not worth it. They obviously won't turn money down, but it's not a growth area for them.
EC2 is similarly great for normal people as long as you only need a part-time server for a short amount of time. It's hard to beat with a VPS.
Once you get into load balances, event queues, and all the rest of AWS services, well, that's all there to drive lots of money to AWS and to contractors and busy work. MAYBE RDS is a good deal for somebody who really wants to pay somebody else for a managed database. Which turns out to be a ton of users of databases!
> Cloudflare does not offer web hosting for most websites
https://developers.cloudflare.com/fundamentals/manage-domain...
I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved.
Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare).
Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan.
Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.
IMHO, it's not that hard to believe.
a) Every hosting provider I've looked at prices for charges significantly more for bandwidth from their Indian locations.
b) In the US, transit providers basically never charged different rates for different destinations [1]. In Europe, it's typically rare, sometimes transit to the local incumbent telecom is more, sometimes there's a different rate for Europe or non-Europe, but there won't be a specific destination charge for India, it will be part of a blended rate. Otoh, east Asia often has separate rates for specific nearby countries and India is likely to be one of those...
Transit prices in Europe are pretty low compared to prices in India, so the blended price being less than the India direct price is not surprising to me at all.
[1] gcp premium does charge by destination, but the premium transit price is pretty close to their price for cross location traffic to something near the destination + non-premium traffic from that location... Which is more or less what their premium network egress is.
In anycase, then they should document it clearly that they have unacceptable insertion latency in india and the free plan is entirely unusable for india. Instead of advertising '10 pops in india!!'
Right, but Cloudflare doesn't have to pay for it in that case. If Cloudflare sends you to their Indian POP, then they have to pay their Indian service provider for traffic. If they send you to their France POP, then they have to pay their French ISP for traffic. The Indian provider cannot claim any of Cloudflare's traffic in that case, because the Indian service provider wouldn't have any relationship with Cloudflare
This is very standard for places with high ISP costs, like South Korea and India. You can see a lot of discussion about it online. I agree with you that Cloudflare should be more transparent if / when they make different routing decision for Free/Pro plans based on bandwidth costs, but I don't think their decision itself is unreasonable at all. Indian bandwidth is very expensive.
Your Indian ISP is paying a French ISP for both directions of that traffic, which makes it cheap at the French end. Were it India-to-India, Cloudflare would have to pay your ISP.
You don't need to register your domain with them. Only make their DNS servers your domain name servers.
How do I know this? I have received reports from various websites (and manually queried some public block lists/RBL/etc.) that my IP range was blocked due to all sorts of different things like open proxies, CSAM etc. even if I've never visited that site before, and I know just from being a neteng that that such traffic is not originating from my devices/router and I don't have any observably compromised devices or suspicious traffic when monitoring it.
Not really unexpected, US domination of "tech" is near total, even if the sustained political will exists (and I'm not sure it will for long enough) unwinding that is the expensive work of years/decades not months.
Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
Personally I think we absolutely should, I just don't think we will.
Barring them doing something so egregiously awful we don't have the choice, Governments can move fast when they want to but efficient government scares the shit out of me because it rarely happens outside of a genuinely serious crisis.
Not quite when considering China having the tech freedom they wanted. Also switching internet services is far easier than switching physical supply chains. The only thing that might be hard to switch is the part of the interent backbone infra that is controlled by USA.
(When is the first war going to be started purely downstream of social media beef? Was it arguably the Iran war?)
It's true that MAGA craziness has pushed Europe aways from us. But, ironically, Europe increasing defense spending and standing up an independent military machine will actually make some MAGA people like Europe more.
But either way, the best thing for both the US and Europe is to figure out a way to reconcile. The alternative is a Europe-China alliance (which would be bad for Europe) or a US-China alliance (which would be horrific for Europe).
Consider these points: - US withdrawing it's "Intel support" just as Russia started a major offensive last year. - US starting the war on Iran clearly to help their pal Putin on oil prices, now they try to use Ukraine as a scapegoat for "attacking Russian oil export infrastructure" - Another "side effect" of war in Iran. No more patriots or modern weapons for any country that ordered them from the USA in recent years and was expecting deliveries just about now. - US committing actual act of war (threatening force has been considered an act of war for centuries) against the EU by talking about invading Greenland (most certainly if Russia attacked Estonia US would try their luck with Greenland on same day, does it remind you anything from history?) - US essentially waging an economic war on the rest of NATO. - US companies with full support of the state trying to deny computing hardware to the rest of the world in hope they manage to monopolise compute capability using AI as cover (yes China is a real ally in this).
And much more.
Yes, the US is a much higher threat to the EU than China now.
Don't be ridiculous. The US literally provides targeting information to Ukraine, including for long-range missile strikes deep inside Russia earlier this year.
https://en.wikipedia.org/wiki/List_of_military_aid_to_Ukrain...
Side-by-side with, for example, itemized Israeli aid, it's pretty clear which conflict the US is putting on the back-burner.
BTW, Zelenskyy supports the Iranian opposition, possibly due to the fact that the current Iranian regime is sending Shaheds to Russia. The US has attacked Shahed factories during the current Iran war.
No way that's true.
China is main ally of Russia. China have a huge economic exchange with Russia, China is the sole gateway to technology for Russia, and provide a great amount of political support for Russia.
Even if we are comparing USA and EU in those aspects, EU's support of Russia is way bigger. EU spends huge amounts of money for purchasing energy resources from Russia, EU spends far less money on help against Russian invasion than US (although EU's population is larger, and that issue is way more pressing for them).
I mean look at the numbers: EU spends on confrontation with Russia less money, than they have spent on economic crisis in Greece or something. That is how they perceive this problem and how "important" it is to them.
Ukraine is never going to retake the territory they've lost without European soldiers on the ground. Macron famously said that he would have to send troops to Odesa and yet 3 years later there are still no French troops in Ukraine. Meanwhile Putin has captured even more land and is now actively bombarding Kyiv.
It is painfully obvious that Europe lacks the political will to do any kind of substantial intervention. The war is at a complete standstill and it will last for another horrible decade if no concessions are made.
It's the unfortunate reality of the situation.
Ukraine rightly has no interest in ceding land to achieve a temporary ceasefire to allow Russia to re-arm and then attack again.
Meanwhile it is also important that we don't have two nuclear armed states (France and Russsia) officially at war.
There is a slight hope that the current Russian regime will collapse before then and be replaced by one that doesn't want to continue the war. (Though, that said, it could equally well be replaced by a regime that's even more ultranationalist than the current one.)
While Europe certainly does lack the political will to make a substantial intervention, it's not just a question of political will. There is the small matter of not starting the third world war to consider.
I mean what are the alternatives? Ask Ukraine to give the already occupied land and then some, but later, when several more millions of Ukrainian men would be grabbed by Ukrainian gestapo from the streets like rabid animals and killed?
Because with current support from the EU (that is less then EU support for Greece during economic crisis), that is the only alternative.
And AFAIK the US has not even claimed Greenland.
They all consider China to be the aggressor because they are. E.g., Tibet or India.
I think it’s fair to say the U.S. and Russia are Europe’s principal geopolitical adversaries, today, while for anyone in Asia or Oceania it’s China. (Africa and South America are being weirdly carved up—it’s not particularly clear who is trying to colonize versus trade with them.)
Very similar pressures in reality.
In the way slavery and employment are similar, sure. In practice they’re very different things, even if one—when taken to the extreme—can turn into the other.
See what happened to countries in the 18th and 19th centuries which didn't want to participate in the British economic system
China? It wants to sell its cars here, and thats about it. Incomparable.
Ask/look around in places that dared to stood apart or directly up to whatever US wanted, the story is everything but nice and bloodless. Ask those that fought for them, and were completely abandoned to be then murdered one by one (vietnam, afghanistan).
Rest of your post is just wishful thinking, US is in semi-lawless state now with new oligarchy ruling the country based on emotions and whims and hardly any laws, so prior experiences do not guarantee any form of future. I personally would literally, objectively, trust Xi more than trump if I had to choose (which I don't, nobody does), any day any night.
It's friendly to Europe most of the time, and hostile at times. It's culturally closer, and functionally democratic. You quite obviously don't like the latter statement, but it is, and it is verifiable claim.
1) Can an American sue the country's gov't and win?
2) Is said gov't changeable by the way of elections?
3) How easy it is to participate in political debates for electoral outcomes?
On all 3 USA gets pretty high score. In high contrast against the backdrop of China. Like, if you prefer a world hegemon who is actively imperialist, and contra democracy, cause you're so outraged by the orange man - that's your choice, of course. But let's not pretend the choice is well-thought. Were HN a Chinese place, and you dared to criticize Chinese imperialism your account would not remain unpunished for long, for instance.
But I've learnt that iPhones and social media is American imperialism, but thousands of troops in dozens of military bases on European soil is not, somehow.
Mostly from the US serving politicians scared of losing power.
Presence of allies is not colonialism. Threat to annex Greenland is. Threat to annex Canada is. Keeping pet dictator in Venezuela and taking their oil is.
On the other hand, when Germans, France and other European soldiers came to Greenland to defend against an American threat, it was not colonialism. It was being allies.
> and withdrawing troops from European soil, the response is outrage.
The response to withdrawing troops from European soil was mockery and frustration from army that is loosing valuable bases. Either way, it is not an anti-colonial thing.
> When Trump talks about doing the anti colonial thing
Trump is modern colonialist. He is not talking about doing "the anti colonial thing" ever, instead he is bragging about making America colonial.
------
Trying to frame Trump as somehow anti-colonial is really new level of post-fact dishonesty. It does not work, because his appeal is based on dominance, violence and willingness to steal.
To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
The Americans are there as a front of US empire (IIRC Rammstein is being used for Iran war).
America was a trusted, respected and liked allied nation. It was not a threat. Then Trump supported by people like you turned into a threat to Canada (another former ally), Greenland, democracy and freedom. So, America is not respected or liked, except by neo-nazi it supports. There is no double think involved here.
> To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
It is irrelevant what you think about what other countries should or should not want. The question is what is colonialism.
I'm thinking the opposite might be the way to go here.
We already know that "retaliation" comes from the US government regardless if you did something or not, so most of us (Europeans) have stopped pretending there is a way of preventing it.
Even more, if we piss off Trump enough, he might be dumb enough to try to block European access to CloudFlare, or something similar and maybe even dumber.
So with this, maybe the goal should actually be to try to piss off Trump and the US administration as much as possible, in order for them to start reacting and cutting off some stuff, so we (again, Europeans) basically gets forced off CloudFlare et al.
Lots of companies already finished moving away from storing their primary data in the US, lots of companies is in process of doing so (albeit some look like they'll take forever) but also lots of companies still aren't prepared for the future, would be nice if US government could make the decision a bit easier for them to make :)
So for the most part, the EU has to work slowly and under the radar.
That said, my worry is that we'll be back to business as usual if the midterms look favorable. Even the urgency present during January's Greenland threats was gone after a few months. I fear that we don't have the long-term focus and planning to make sovereignty really happen. But I'd love to be surprised.
https://www.reddit.com/r/sweden/comments/1w8p0z4/comment/p84...
Question:
> Hello, Sweden (and Europe) is facing three almost existential risks over the coming term of office that we have never really had to take a position on to the same extent before. The climate. A new UN report from last week has shown that El Niño will probably contribute to between 3 and 4 degrees of warming in addition to last year's heat wave. I live abroad and we had 44 degrees warm for a couple of days this summer (2025). It was also over 30 degrees in Norrbotten for over 3 weeks. Unbearable. How do you prioritize this against the many other budget items? How should we now prepare for what will inevitably lead to an IPCC 3-4 degree scenario?
> AI. AI development is just going faster and faster. At my workplace, we have already replaced many employees with AI-driven processes. We buy all our computing capacity from the US and China. There are no European alternatives and it is not possible to buy Swedish. What do you want to do to, at the European level, prevent us from ending up in the AI lap of the US and China in 5 years? Where should we buy chips from when all manufacturing takes place in Taiwan, Korea, China and the US? We risk a situation where Swedish office workers are rarely replaced with US AI tokens. Surely this must be an initiative at EU level?
> American foreign policy. Trump's second term has been tumultuous, to say the least. We were probably as close to the brink of war in Europe (Greenland) as there is in living memory. Trade agreements are being torn up, sticks are being put in the works for Gripen agreements, etc. Even when he is gone, the illusion of America as a close ally has probably finally been broken in the eyes of many Swedes, myself included. What do you want to do to reduce Sweden's and the EU's dependence on foreign superpowers?
Answer:
> There is a lot in this. A completely unique geopolitical time - both militarily and economically - presents a small country like Sweden with important choices. NATO was one of them. We are now cooperating with all our neighbors around the Baltic Sea, for example our own defense build-up, another example, the largest since the 50s. And all the new free trade agreements when the United States messes up world trade.
> The climate is also one of these, and what the EU is now doing together is the single most important thing, in parallel with Swedish fossil-free energy. We can make ourselves completely national energy independent with the new Swedish nuclear power programme. German energy policy, I think, proves why this is needed, in addition to the wars in the Middle East.
> EU: no single EU issue is more important than our support for Ukraine and increasing European competitiveness in relation to both the US and China. And it starts with the internal market - where 70 percent of all Swedish goods exports end up. If it can be as good for services including digital services, it would be good for both the EU and Sweden. But I am genuinely concerned that Europe is lagging behind.
> last China: we will have an intense autumn regarding a common European response against China to get "level playing fields" when it comes to trade. Today's situation is not sustainable. even extremely free trade-friendly countries like Sweden see this. we should not have protectionism but the same opportunities for the EU in China as for China in the EU. We are not there now.
How convenient. If it wasn't for the US, the EU would work really fast and in the open! That is totally believable.
There are troops deployed on Greenland right now ready to defend the island. The threat is not gone from the minds of the people there or in the rest of Europe just because you stopped reading about it on CNN or whatever.
Edit: I got curious if this part is even possible:
> leaving NATO completely
Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it. It also prohibits federal funds from being used to carry out an unauthorized withdrawal.
Seems some parts of the US has indeed managed to setup defenses against such idiocracy.
I don't watch CNN. I live in Europe, read European newspapers. It's just something that I noticed observing people. In January, a lot of people started thinking about moving away from US services, there were even newspaper articles about alternative smartphone OSes, etc. Now most people are back to business as usual. (Which doesn't mean that some countries aren't moving to alternatives, etc.)
Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it.
Agreed that complete withdrawal is hard currently. But it's a toothless tiger (as least with respect to the US) when the commander in chief says he will not defend a country because they have been unfair to the US.
My personal opinion is that the EU should just do what it needs to do, because NATO is effectively dead and reboot the alliance without the US in parallel.
Why not take even two seconds to check if what you're guessing about, might actually be correct or not? Or the goal is just FUD here?
> And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
Maybe because the impact of these blocks aren't as large as you allude to? Things change, these blocklists get updated. What was blocked 6 months ago no longer is, when these anti-piracy blocks happen.
Don't get me wrong, I don't agree with these blocks at all, and AFAIK, they break both national laws and wider "rights", but lets not pretend it's bigger than what it is in reality.
You mean the US government working towards the interests of its people and economy? Which government wouldn't? It's kinda what we want it to do.
should read as "everyone the US likes", not everyone everyone.
France has global geopolitical projects, as does China in South America, Central Asia and Africa. Both export arms into conflicts and conduct global intelligence operations.
This is currently a legitimately open question.
America acts like a global hegemon. My point is simply that France and China act similarly, too—they both project power across oceans and continents. (To what end is, as with America’s power projection, a good question.)
I’m Australian, and if I was worried about the practical legal risk of being tracked online by a government, it’s mostly concern about my own. A foreign friendly government is mid tier: it’s unlikely that five eyes is an intel firehouse, so it’s unlikely for your petty domestic matter to be communicated. A foreign hostile government is probably safer if you’re committing domestic crimes.
It's not the so-called retaliation of the US government that leads to European inefficiencies like paying notaries thousands of euros to read out a contract to you (several discussions going around about this in Germany recently).
This is ultimately just a boogeyman. European governments love to blame someone else for their inefficient and bureaucratic processes that stifle innovation and are slowly becoming the laughing stock of the tech world.
If they really want a thriving tech industry, EU should:
- Normalize laws and regulations relating to commerce and online activities throughout the EU. Get rid of the notary crap. While you are at it, get rid of the impressum (why the fuck should I need to post my home address on my website?).
- Ensure that these normalized regulations are available in the tens of languages across the EU
- Invest heavily in telecom and data center infrastructure and software on a European-wide basis. The current AI bubble will see a downturn but data centers and connectivity infrastructure can be reused for EU-based cloud services.
- Invite the UK back in once they are an actual economic powerhouse that can speak with one voice.
Of course none of this will ever get done because EU bureaucrats would rather be in a perpetual hand-wringing mode while blaming the Big Bad US Boogeyman for all their problems.
The difference is that you typically don't hear "Oh we need to make slow progress on making voting easier, because the EU will retaliate". That would be absurd. We recognize that it's our own fault, i.e. the politicians that we are voting in.
I think many millions in the EU want to. The problem is that the current EU "politicians" are just US lobbyists. You can see it when Leyen signed the surrender treaty with her Overlord-buddy Trump. You can not fix the EU with such lobbiysts in place - and it's not just Leyen alone. Look at Merz - the guy basically is a tool used by US companies. He is not the brightest but very loyal to the USA. More than to the people who voted for him (and now curse themselves for having made such a big mistake).
Hey Claude, can you move the ciphercue blog to Cloudflare so it can deal with traffic from HN?
On a more serious note, Cloudflare comes packed with features even on its free plan which makes it useful for any size website. For a real business it's one of the cheapest options for DDoS protection on the market. Some years ago you would have paid a fortune for Akamai or Level3 to help keep you online and now you can get by on a $200 a month plan for a small business.
You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.
* of course it's not unlimited unlimited but I've not heard of anyone being cut off.
This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.
Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.
But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.
> and I don't think people should default to trying to prevent them.
It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.
Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)
https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...
The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.
Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.
> Your personal experience of DDoS being super rare doesn't seem to match the real world.
What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.
> But again, those sort of attacks seem to happen seldom
[citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.
If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.
Yes, plus a strong bias toward IT-heavy businesses. Vs. if my company is doing commercial landscaping, or machining gears for automobile transmissions? Several hundred employees still gives me no reason to pay much for web hosting.
A CDN not, and certainly not a global one.
But unfortunately, you absolutely need DDoS protection, especially as a business. Too many shady actors and skiddies pulling off extortion/protection racket scams - a complete and utter lack of telco regulations, AI, tons of unsecured IoT devices and shitcoins truly have made for a terrible mixture.
Sure, a 50€ a month server at Hetzner, OVH or whatever is more than enough to host a website. If you're not running some NodeJS garbage, a 5€ VPS can be enough. But at the first sign of you being targeted by a troublemaker, your hoster will cut you off just to protect their other customers.
I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.
Edit: I found https://european-alternatives.eu/alternative-to/cloudflare , which lists among others: https://bunny.net/ , https://www.keycdn.com/ , https://blazingcdn.com/ , https://www.myrasecurity.com/en/product-content-delivery-net..., https://www.leaseweb.com/cdn . If anyone has any personal experiences with any of these please share.
The main "gotcha" is that there's no free plan, it's a minimum of $1 per month, you pay for usage. In practice it's very hard to spend more than a dollar in a month.
Which is weird. CDN requires massive distributed footprint, which inherently provides the enormous network capacity needed to absorb DDoS attacks. So why aren't they offering the same thing as Cloudflare?
European CDNs should form partnerships with both European IXPs and Tier-1/Tier-2 ISPs (like Orange, Deutsche Telekom, etc.) to see what exactly is missing to do both unmetered anti-DDoS and global CDN/caching.
You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.
Service has been great, prices like 10% of cloudflare too once you get the real pricing :P
Agree discord sucks.
We don’t miss Cloudflare one bit.
[1] https://github.com/fatedier/frp
I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.
10+ BT trackers using CF likely free tier. Low-end EACH 300-500 MILLION HTTP requests/24hr uncached, some exceed a billion reqs/day (using statistics from other open trackers) 20TB-40TB daily, ~1-3 Gbps sustained.
That's a crap load of transfer and compute to process those tiny network connections. As someone that's run a Tunnel on a normal site in the millions, the daemon uses a sizeable amount of CPU and I can't see any reason why it's not the same on the other end.
Whatever source CF has going on, kudos to them and their engineering team.
They have shareholders, who wouldn't allow them to provide value for free, its just not obvious to you how they are extracting that value. Maybe its by capturing a huge % of unencrypted https traffic because if you let them do your certs it means they can read all your real traffic.
This is why I refuse to give any money to AWS/GCP/Azure or anyone who runs on them.
If it is "not obvious to you how they extract the value", you can just look for NET (their ticker) earning reports and SEC fillings since they are a publicly traded company instead of spreading conspiracy theories...
It will take similar amount of years to go back into the cold war heterogeneous computing landscape of the 60, early 90s.
This assuming there would be an willingness across all European countries to actually push for that, and not jump out when it gets too hard and search for compromises instead.
This is why most sovereignty initiatives focus mostly on SaaS products and hardly on actual computing devices.
Only time will tell how far this sovereign movement would go. Maybe when the US would have a president/government from the Democratic Party someday in the future. EU would cozy up again to US and go back to how things were. There’s no permanent enemies or allies when it comes to politics and at the end of the day it all revolves around money
The governments can's solve this problem because the entire economic model of the EU is that the core exploits the periphery, who don't have a currency that they can weaken as a response. If they had a strong democratic central government and a real central bank in the EU, they'd be forced to make transfer payments to the weaker members, and to bail them out (losing the leverage to make elite demands on them.)
The EU as a whole could easily solve the problem, they have the population, the talent, and the infrastructure. They're just really docile from the CIA and their own elite cliques working on them for the better part of a century.
> Only time will tell how far this sovereign movement would go.
There is none. Blah blah blah in the media isn't a "sovereign movement." It's a campaign to get you to vote for the same middle of the road radical centrist neocons served on a substrate of normie-relaxing anti-Trump rhetoric.
In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?
https://buc-ees.com/careers/
Like, I find SV culture and living to be a cancer, but I'm just saying as someone who doesn't live in a top 10 city in the US with a MCOL, I struggle to think of how working as a software engineer in the EU would be better.
It's been over 10 years since that 2 weeks PTO nonsense applied to tech. I don't even have a fancy job. I work for a bank.
This is an appeal to mediocrity and it doesn't really hold when comparing EU to Silicon Valley tech jobs. Young engineers in the Silicon Valley (or NYC, or Seattle) have excellent health care, generous vacation and other benefits, and they also make substantially more money.
Why would a young, ambitious engineering graduate care about taking 30 days off when they have the opportunity to work on frontier tech that is only available in the US? And make an absurd salary doing it? Healthcare is also less of a concern because 20 somethings and 30 somethings barely use any social benefits anyway. And like I said earlier, they also have exceptional private health care through their employer.
This claim that the European lifestyle is somehow better despite the extreme salary difference really just doesn't hold when comparing to early/mid-career tech workers in the US.
The games industry and Hollywood have that lesson very well thought out.
It provides you with all the tools necessary to scale your app.
It will not get down with half of the internet the next time cloudflare has issues.
The real point is what's between the lines: A growing number of European techies are not optimizing for the best technical solution.
At least on hackernews. The observed stat says otherwise, up to this point in time at least.
Personally I love using cloudflare. I am always surprised to see the hate from devs here. I would expect it to be beloved.
Before the 2000s, Europe was very very strong in telecom (Ericsson, Nokia, Siemens, Alcatel), industrial technology, the auto industry, mobile phones, semiconductors, and enterprise software (SAP, Baan, Business Objects, Dassault Systèmes, sage). Europe was definitely much less dependent on U.S. technology back then. In some area I would say it was the other way around.
But Europe's dependence on U.S. technology has accelerated dramatically over the last 10-15 years.
I'm really not sure why. Regulation and bureaucracy did not get worse. And Europe even created the EU, which provided a better "single market" (better than before the 2000s).
I would love to hear some opinions on what changed.
9 out of 10 corporate decisions are for blame avoidance / ass covering.
I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?
Maybe our countries are just small enough to not be overwhelmed by traffic? Most websites I've built and launched for Spanish national companies, that only have other Spaniards as users and customers, haven't needed any CDN at all, because you don't suddenly get 1K req/s. Meanwhile, launch a global website in English, that even get the slightest amount of popular, and all of a sudden you reach 1K req/s very quickly. Add on top that people usually don't even give two cents about performance, and adding CDN on top as a saving grace seems like an easy tradeoff.
So, why add a CDN when you don't need it? :) Probably 80% of everything I've ever deployed never needed a CDN in the first place, but I also save it as a thing in my toolbox to be used sparingly, rather than a default thing I slap on top of everything.
If all your users are in Spain and you don’t care how fast your site loads for a techbro in California, you indeed don’t need CDN.
For both France and the UK, less than 15% of sites are behind a CDN. For both, around 95% use Cloudflare.
So in terms of percentages, there’s not much of a difference.
I wanted to check if the 5 customers for which I already did a change on their Cloudflare settings today where on the list, but can't do.
Also, funny that their page with for "Companies running Cloudflare" says there are only "887 European organisations using Cloudflare."
Doesn't this miss websites that serve their own site html but serve (static) assets from a CDN.
This seems to be a common pattern with Wordpress sites, presumably because it makes cache configuration simpler
BTW CDN is a terrible business.
The only thing worse that's adjacent is rural Fiber and seemingly Wholesale IP transit.
Before they'd use some European host or file locker.
I wonder about the economics and how it's hidden.
Or, they discuss their free stuff at length here - https://www.sec.gov/Archives/edgar/data/1477333/000147733326....
(That is Cloudflare's 10-K for calendar 2025 - scrutinized by serious investors, and with heavy penalties for lying.)
- Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead. (Where the cache size is larger than anything you'd want to support yourself. For example, if it's <1G and survives your service restarts, you may want to do it yourself)
- Your customers on the other side of the world start complaining that the resources take ages to load.
- Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.
Not only would transfer be slow, they would also be much more pressing on the network as the request would occupy huge stretches and many interconnects and switches.
Furthermore, it hardens the website against DDoS and adds robustness for regional failures.
So, while average request may have to travel quarter (not half) of the Internet globe, median request from the set of requests that matter has much lower latency.
Barcelona to Stockholm is about 65ms, ~35ms to Amsterdam, ~43ms to Frankfurt.
HTTP/3 is ubiquitous, you don’t get TCP handshake penalty anymore in major browsers.
Lol
If you have a very inefficient backend (maybe legacy project?), you have massive amount of traffic (say 100K req/s or above) or you really must have sub-500ms latency absolutely everywhere in the world, then it might make sense to slap a CDN (or similar) on top of that.
In pretty much any case outside of that, it makes no sense to waste the time, money or effort on CDNs. But, all the CDN companies seemingly have convinced half the internet that you absolutely must use a CDN, otherwise you'll get hacked/broke/killed/sent to the moon, and they've been successful with this campaign too seemingly.
If your server is in Europe, and you have Australian users, there is a physical limit how low the response times can go, serving bits over that distance, so only way you can make it go below that limit, is by moving where you serve the data from closer to the user.
Lots of websites have horrible performance for whatever reasons, and lots of freelancers/consultants basically default to throwing a CDN on top of those when they get approached by businesses to fix the slow website browsing, as they're not the ones who have to pay the monthly subscription, and the less work they have to do, the better $ per hour spent for them.
I agree that it's a shit solution and there is much better sustainable ways of solving these things.
If anything else, the AI machine wants near constant streams of new data, even if it already checked with you 30ms ago.
A CDN helps immensely.
Also keeps you from getting DDoS'd if you did something like run it off your home connection.
CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.
And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.
If your problem is AI crawlers, then simple rate limits help, I've helped countless of businesses with this already. For the ones that it isn't enough, you continue adding more roadblocks. There is no "one size fits all here" and that you seemingly is under that belief, leads less credence to what you're saying, not more.
There are people willing to throw money at you.
But Free is hard to beat with a global presence.
And please listen to what others are saying here, there's a lot of experienced people here. It is no longer 1998, 2008, or even 2018. The traffic a basic website experiences now is a massive increase, especially for those well SEO'd and using TLS.
Also you said this:
> CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.
Origin obfuscation.
Also greatly helps to protect it directly from various attacks and scans, especially in our new LLM driven security world where new 0days are being found constantly. How much at risk are you willing to put the SMB?
Keeping connection alive take memory.
Rate limit by bytes/sec would hold the connection longer, taking more resources.
Rate limit by ip don't work with sudden surge demand, ddos, etc
Rate limit by user basically means you need to process the request and CPU bound
In very large scale DDoS, incoming SYN alone can cog your down pipe. You need to upgrade the connection just for that (Or something on your upstream to block by ip)
You can do lots of these without using cdn, yes. But it is easier with cdn and it is cheaper than paying for extra capacity "just in case"
Even in the previous political climate this should, objectively, be deemed a problem. Having 90% of all eggs in one basket is neither good, nor does it constitute functioning market.
I'm not sure what the Cloudflare market share is in the US, but if it is the same as in Europe, this is a problem for US companies as well.
Going from one CDN to another can be infuriating even at a surprisingly small scale. Mostly (imo) from caching semantics and counting.
For it to be a commodity there would be no good reason to pick Cloudflare over any alternative and this absolutely isn't the case.
What do the EU investors do outside of demanding guaranteed profit with zero risk for them? How many are ready to absorb 10-30 years of new infrastructure investments and play the long game?
If the EU wants to compete, well, here's the global market, right that way. ==>
Get to it. Nobody is actually stopping you.
But if you have no appetite for risk, don't complain when one day you realize you don't have EU alternatives.
If you use their unique features, you're locking yourself in. Is it worth it?
Also in this list of GOATed companies: Tailscale, Ubiquiti.
"In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year."
--Matthew Prince's Wikipedia page.
Dont for a second think cloudflare's generous free tier offerings are out of the goodness of their heart. They're a giant fkin MiTM project for the US governemnt. And of course, cloudflare isn't the only one.
Subtle
The US deserves it's success.
what stopping europe from using their home ground solution ??? nothing
this is just a skill issue take