10 ms·
Cloudflare took down our website
- iamleppert 2y agoShould have paid the protection money to CF. They need their cut of your gambling bag!
- h2odragon 2y agoRacketeering is easier and more profitable than actual services. Shocking how often "gatekeepers" fall to the temptation.
- jsheard 2y agoSpeaking of racketeering, it's an enlightening experience to search for "stresser" or "booter" providers (euphemisms for DDoS-as-a-Service) and look up their NS records to see who helping them ward off competitors DDoS attacks and keep their origin servers hidden. 9 times out of 10 it's Cloudflare, with the few exceptions being DDoS-Guard, who more or less specialize in facilitating crime.
- h2odragon 2y agoSee also early "anti" virus industry.
- willmadden 2y agoI wouldn't be the least bit surprised if DDOS protection providers were using DDOS on their prospective customers via proxy. Problem, reaction, solution. Did you pay your "protection" money this month, Luigi?
- CamelCaseName 2y ago> When we told them we were also in talks with Fastly, they suddenly "purged" all our domains Holy shit.
- JKCalhoun 2y agoWhat a way to more quickly show your customer the door.
- nolongerthere 2y agoWhat’s especially shocking is how closely coupled sales and engineering are. Like I get they talk, but for a sales call to end in engineering pulling the plug…
- scrollaway 2y agoTo me it's pretty clear: Trust & Safety (NOT engineering; they don't appear to be involved) likely raised an alarm saying "Customer X is breaking TOS - no immediate resolution available, but something might be possible given extensive legal & engineering review. Recommend switching to enterprise so we can study how to make it work." In that light you can see why Sales would be sent as the messenger. But I agree they shouldn't have been involved. Sending a T&S representative would have been better. But then again it looks like from screenshot #2 that they kind of did that? They just didn't have a direct call with T&S.
- theshackleford 2y agoNothing shocking here as someone who has been involved in hosting for close to twenty years.
- candiddevmike 2y agoSounds like OP is a casino and plays domain games to avoid regulatory interest. Recommend reading article carefully before reacting to the headline. Hopefully Cloudflare provides a perspective.
- Hikikomori 2y agoHow does paying $10k a month solve that?
- scrollaway 2y agoFor $10k / mo paid 1 year in advance, your cloud provider does a legal review of the situation and figures out how to make your problem work on both the technical and legal level. It's not a "special plan", it's consulting. Edit: "How do you know?" -- I don't know it's actually what happened, but when switching to enterprise, you don't go from 10% margin to 98% margin. The added costs actually represent added budget for the provider to deal with your "special case". ALL enterprise pricing tiers are disguised consulting contracts.
- Hikikomori 2y agoOr they had already decided to kick them out and tried to get some money out of them first.
- atmosx 2y agoGreat theory! The only questions that come to mind: how do you know? If that was the case why didn't they tell the customer?
- Tao3300 2y agoNice place you got here. It'd be a shame if something happened to it. Except the "place" isn't Mom and Pop's bodega, it's a casino dodging countries blocking its main domain.
- Hikikomori 2y ago
- cjk2 2y agoDoesn't matter if you're an asshole company or not: always have an exit plan and test it.
- softwaredoug 2y agoCloudflare was the company that went viral for the firing of an account rep not hitting her goals. I wonder if it’s overall indicative of not a great culture in terms of relationships with enterprise customers. https://m.youtube.com/watch?v=7LuwPdp-_4c https://m.youtube.com/watch?v=7LuwPdp-_4c
- CydeWeys 2y ago> Cloudflare was the company that went viral for the firing of an account rep not hitting her goals. How is that something worth going viral over? Salespeople get fired all the time for not meeting their sales goals. Engineers similarly get fired all the time for not meeting their productivity goals. If you don't do your job well, don't expect to keep it. And if I recall correctly, in this particular case, she was a green employee who hadn't even made a single sale yet! What more obvious of a layoff target is there than that? Would you keep a green unproven salesperson over a proven veteran salesperson who's landed 9 figures in sales?
- busterarm 2y agoWhile I agree with you, I think the call is for companies to be less psychopathic and stop onboarding people within 90 days of mass layoffs. Especially in a world where people pick up their whole lives and relocate for jobs. Recent joiners aren't getting any sustainable kind of severance either. The idea is if you're hiring them you have a minimum commitment to support their success. Yes she was an obvious fire, but it's also the organization's fault. Enterprise deals also take way longer to close than that... All that said, salespeople can and do move jobs a lot. I'm sure she'll be fine.
- gruez 2y ago>I think the call is for companies to be less psychopathic and stop onboarding people within 90 days of mass layoffs. Was there any indication that the "mass layoffs" were planned 90 days in advance?
- 2y ago
- brigadier132 2y agohas this happened to any businesses that were not questionably legal?
- CamelCaseName 2y agoThere are links in the article, for example: "Small SaaS banned by Cloudflare after 4 years of being paying customer" https://news.ycombinator.com/item?id=34639212 https://news.ycombinator.com/item?id=34639212 Also: https://news.ycombinator.com/item?id=31336515 https://news.ycombinator.com/item?id=31336515
- brigadier132 2y agoThanks, I was genuinely curious
- gruez 2y agoIn both examples you provided it was less "banned" and more "switch to a higher priced plan or we'll kick you off". In both cases they seem to be bandwidth related, and in the second case specifically they mentioned having hundreds of terabytes bandwidth but were upset for being told to upgrade to the $200 plan.
- ghoshbishakh 2y agoIs this why cloudflare manages to be cheap?
- brigadier132 2y agoThey manage to be cheap because it's massively multitenant infra
- chadsix 2y agoIt's unclear as it shouldn't be possible to be cheap. That said, in a world of data, Cloudflare being a massive man in the middle (MITM) probably means something [1]. [1] Cloudflare decrypts your traffic, reads it, and then forwards it. They see all encrypted data going to and from your website, in plaintext.
- rvnx 2y agoThis data collection project has a name: "Project Honey Pot" (and had excellent relations with FBI), look closely the story that led to Cloudflare. https://www.projecthoneypot.org/cloudflare_beta.html https://www.projecthoneypot.org/cloudflare_beta.html
- chadsix 2y agoWow. This is a travesty if I've ever known one. Hopefully, that can be posted and upvoted on HN.
- rvnx 2y agoI actually like Cloudflare very much from a technical perspective, so I wouldn't want to hurt them. In fact, the company vision and values (as the team grew) may have changed over the time, but originally it seems it was somewhat of a different spirit (and closer to a data collection network).
- pornel 2y agoTheir business model is described in their S1 filing: https://www.sec.gov/Archives/edgar/data/1477333/000119312519222176/d735023ds1.htm https://www.sec.gov/Archives/edgar/data/1477333/000119312519... * Cloudflare operates at a scale where its caching saves a lot of bandwidth, which saves ISPs money, which makes Cloudflare an attractive partner for peering and co-location. * CDN is a platform on top of which Cloudflare can offer a lot of additional services that used to be expensive dedicated middleboxes.
- tcsenpai 2y agoUsing this as a blatant example of why digital anarchism is needed nowadays
- hubraumhugo 2y agoThe Cloudflare CEO & co-founder is quite active on Twitter[0] and somewhat active on HN[1], would be interesting to get his perspective on this. [0] https://x.com/eastdakota/ https://x.com/eastdakota/ [1] https://news.ycombinator.com/user?id=eastdakota https://news.ycombinator.com/user?id=eastdakota
- remram 2y agoI don't know how those situations work though. The customer is obviously allowed to say whatever they want, but if a Cloudflare employee or CEO disagreed, would they be allowed to provide their own version of the facts? Wouldn't that go against privacy rules in some way, showing the details of someone's account? I would think they would only open themselves up to legal trouble. As far as I can see, the author was careful to redact their domain from all screenshots.
- archon810 2y agoI flagged it for him, we'll see if he replies. https://x.com/ArtemR/status/1795074047539068991 https://x.com/ArtemR/status/1795074047539068991
- EligibleDecoy 2y agoThe recommendations to, basically, not keep all your eggs in one basket and have backups of config are surely good ideas. But if you have to plan on dropping cloudflare in some arbitrary 24 hour window, perhaps it’s CF that’s the problem. This sort of stuff and other recent articles about CF are so worrying that it’s now being run by the finance team (hence why every email they got in this article was from sales teams rather than any technical folks). Also; if not registering domains on CF does anyone else do at-cost or otherwise super cheap pricing?
- silverquiet 2y agoI’d say be wary of any public company and actively make plans to get out of any company that gets acquired by private equity. Actually had a sales call with Cloudflare in the last month and I got some bad vibes from the whole experience. We did not end up going with them.
- RyeCombinator 2y agoMay I ask who you ended up going with? We had a similar experience recently and have some concerns with anything on CF.
- silverquiet 2y agoWe already have DDoS protection from our colo provider and it wasn't clearly advantageous to switch to Cloudflare. We were mainly interested in zero trust but I don't know what we're looking at as of now; we still use various VPNs which, while not exactly fashionable, do work for us.
- pteraspidomorph 2y agoWisdom of the ancients: Always make sure your domain services are completely independent from your other service provider(s), regardless of whether Cloudflare is involved. (Sorry, no recommendations at this time.)
- chadsix 2y agoThis is a really important lesson here. Don't put your eggs in one basket, and if network delivery/etc. is core to your revenues and livelihood, don't trust a random third party host to look out for you. 10TB/80TB at 120k/yr, either way, Cloudflare is taking you for a ride. If you aren't self hosting, you're really doing it wrong.
- icedchai 2y ago10TB/month is 30 megabits/sec on average. Not much for a CDN. They probably need Cloudflare more for DDOS protection than anything else, I'd think?
- latchkey 2y ago> Don't put your eggs in one basket Yet everyone in "ai ai ai ai" is buying up Nvidia/CUDA like there is no tomorrow and then pooping on AMD for even trying to do anything. History loves to repeat itself.
- remram 2y agoWhat is "don't put your eggs in one basket" here? Your DNS has to point to something... and changing it will go through propagation delays, during which it will be down if you are banned suddenly. It's not like you can have your domain/DNS somewhere else and point to Cloudflare IPs (to not put DNS and CDN in same basket). Cloudflare does not allow that setup. You can't protect your website from your DNS provider or hosting provider suddenly kicking you off. You are going to be offline for a couple of days.
- johnklos 2y ago> You can't protect your website from your DNS provider or hosting provider suddenly kicking you off. You are going to be offline for a couple of days. Sure you can. Colocate in two or three places. You're your own DNS provider and your own hosting provider. If one of your colocation companies doesn't like what you're doing for whatever reason, you use the other two until you replace that provider.
- 2y ago
- thinkingkong 2y agoIm reading between the lines here but it seems like the traffic amount, the saas subscription tier, and the actions required to remidiate some issue were all unaligned. 1. Its quite possible thar CF having this site on some multi-tenant infrastructure could be threatening. Not unreasonable at least to ask them to have their own IP block. 2. If thats the issue then a clear explanation should have been provided. Routing to sales is inexcusable. Someone isnt being transparent. 3. If it’s a pure cost / revenue issue then say that, set a deadline and negotiate. This is bad karma and even though CF is clearly the market leader, what they do isnt rocket surgery. Not worth it.
- posix86 2y agoWhat stands out as odd to me is that CF seems to be pushing away a $10k/month customer. No business can reasonably be expected to accept sudden price changes like that, even if they'd paid, they would've moved away within a year. Given that the article is an online casino that seems to be using potentially ToS violating domain rotation, and that they pay so little per month for apparently millions of users, I for one will not form an opinion on CF based on this article before CF has a chance to defend itself.
- sigseg1v 2y agoMy thoughts here are also all speculation, but when you mentioned multi-tenant issues my mind immediately went to a situation I've seen all too many times before: - a companies ops team identifies a tenant that is too heavy/burdensome for multi-tenant infra and is causing issues. These issues can cost a serious amount of money if you factor in dev/ops times to resolve, other customers impacted, etc. Certainly more than what a hypothetical single multi-tenant customer could be paying - they escalated internally and need the tenant moved to enterprise asap to resolve - the only reason the tenant was on multi was because sales sold them the wrong thing, so now it's on sales to explain how to fix this - improper handling internally results in this landing only on sales, with no backup, and with their task being to get them to take enterprise - when the customer refuses enterprise they go "we've tried nothing and we're all out of ideas" Again, this is totally speculation and I'd hope CF has more mature practices than this but this is a scenario I've seen before in much smaller orgs.
- curious_cat_163 2y agoA paragraph ends with: > This could arguably be seen as a violation of the Cloudflare TOS, as they wrote above. And the very next paragraph begins with: > In any case, we receive >95% of our traffic through the main domain that’s been unchanged since our founding, and were happy to resolve this issue in whatever way... And then they complain about paying up? The only issue I see here is around the aggressiveness on the CF side. But, I was not in those meetings and the way above reads tells me that I might have been slightly mad so perhaps the CF was just taking it out on them? Anyway. I don't think this is a CF foul.
- perihelions 2y ago- "This also means that if a country DNS-blocks our main domain, a secondary domain may still be available. This could arguably be seen as a violation of the Cloudflare TOS, as they wrote above." Attorneys love it when people put everything in writing like this.
- albert_e 2y agoDevil's advocate: If a country A decides to block twitter.com but forgets to ban x.com which remains available ... is Twitter engaging in illegality / violation of CDN terms of service?
- gruez 2y agoLike most things in the legal system, it depends on intent. It's pretty obvious that twitter's rebrand to x.com was an actual rebrand and not some way of evading domain bans.
- Dylan16807 2y agoThe author claims a reasonable intent and they give a traffic number that proves they're not doing "domain rotation".
- gruez 2y ago>The author claims a reasonable intent Right, I'm not arguing that they're guilty, just that the legal system doesn't operate off pure black and white rules like "if you have two seemingly unrelated domains then you're trying to evade bans". >and they give a traffic number that proves they're not doing "domain rotation". Are you talking about the part where they said "95% of our traffic through the main domain"? Without additional context behind that number it's a stretch to claim that "proves" they're not trying to evade bans. For instance if their country is banned in country A, but country A is a small country that only makes up 3% of their overall traffic, they can confidently claim "95% of our traffic through the main domain" while still theoretically using alternate domains for ban evasion purposes.
- viraptor 2y ago> Make backups of your configuration on Cloudflare. It's an unexpectedly large pain to recreate all those configurations Better yet, configure CloudFlare through terraform, so all your config exists in your own repo all the time. It also helps day to day since it's not that hard to accidentally flip some switch in the dashboard. But yeah, do research alternatives. CF has too much power already and will either ignore issues, destroy you, or pay lawyers to protect people trying to get you murdered, depending on their mood. There are better options.
- CydeWeys 2y ago$250/month sounds like nothing at all for a site with a claimed 4M MAU. The enterprise rate of $10k/month sounds a lot more reasonable. If everything presented here is accurate, I'm not understanding the sharp discrepancy in pricing tiers. If anything they should've already been paying more than $10k/month for massive traffic on the basic plan and then be able to save money by paying for massive scale when negotiating rates for the enterprise plan. Also this sounds like an online gambling site of questionable legality, knowingly serving customers in jurisdictions where it's illegal, so I can't say I have too much sympathy, and I feel like Cloudflare effectively fired them as a customer when they realized what they were up to.
- andersa 2y agoAccording to Cloudflare themselves, 80TB traffic should cost around $100/month. See: https://blog.cloudflare.com/aws-egregious-egress https://blog.cloudflare.com/aws-egregious-egress
- marziply 2y agoThe amount shouldn't matter, it's the unprofessional response from CF that's of concern. Also, the author doesn't necessarily say that they would be unwilling to pay more or even negotiate a higher price. The author has made it explicit that CF were more or less unwilling for any practical conversation. That, to me, is the problem. A lack of professional courtesy, communication, and transparency. Obviously there may be details from this exchange which have been omitted but if I were in this position, I would be equally upset.
- Etheryte 2y agoThis doesn't pass the sniff test. From the actions Cloudflare took and their communication, it's very clear that there was something about the way their services were used that they were unhappy about. The post doesn't include what that problem was, but I have a very hard time believing that the author was not in the know and just got their account nuked without any further commentary, especially after being in a number of calls with real human beings from Cloudflare. Surely they'd have plenty of room to both ask and tell to figure out what the issue is. More than anything, this sounds like they knowingly did something shady and are now trying to shift the blame.
- nso 2y agoSo CF is ok with shady for 10k but not for .25k?
- rvnx 2y agoMaybe... Same ratio: I might be ok to do shady stuff for 100k a month, but not 2.5k a month
- hardfriendship 2y ago[dead]
- kmbfjr 2y agoIsn’t that a tale as old as the internet? Hosting adult traffic is painful in all respects, and they get a premium for it. CF was more than happy to help, but .25k wasn’t a number that solved all the problems.
- kosolam 2y agoWell, this is disgusting behavior CF. I wonder if OPs company suing CF?
- xiwenc 2y agoIndeed. Based on what has been shared by OP, they could have a case. If OP’s business was in fact illegal, CF should have stated it. Now it seems CF is an evil sales driving monster. A monster that grew so big it thinks it can do whatever it likes. The sad part is that, assuming OP is not leaving out critical parts, multiple people play parts of this evil machine. I’ve seen how sales people think. But this is next level toxic culture. The second customer threats of leaving for the competition, they freak out and pull a bigger lever to destroy them. And the fact that a company allows this to happen… I would never do business with CF. Good thing i don’t right now. Cause i will definitely take it elsewhere.
- JoeyJooste 2y agoAfter reading this article carefully I have a few thoughts. Firstly you were knowingly in violation of TOS after they pointed it out to you. Violating their TOS is a fast way to have your account suspended. Secondly I'm a little confused why they would require you to pay a year upfront? I would like to hear from cloudflare as to why they required this? It's pretty fair for them to ask you to pay a year in advance because of the risk that you carry as a gambling company. Cloudflare needed you to have to enterprise plan to remove liability from them. It's not even a big request, they have specific pricing plans for a reason.
- dangoodmanUT 2y agoEvery customer is in violation of the tos if you read the html-only section They know this
- JoeyJooste 2y agoThere is a single mention of html in their terms, and it just restricts wrapping cloudflares software. Could you link me the section where they restrict anything to html-only?
- numair 2y ago> I'm a SysOps engineer at a fairly large online casino. We have around 4 million monthly active users. We had been happy Cloudflare customers since 2018 on the "Business" plan which has some neat features and costs $250/month for "unlimited" traffic. Sorry to be “that guy,” but, you’re serving 4 million people at a casino and paying $250 a month for shared multi tenant infra, and you’re SURPRISED you have problems? Really? To be honest, I’m glad these sorts of businesses get kicked off Cloudflare because it causes problems for others sharing the same IP space and infra. I’ll let someone else with experience discuss how many times a day the network would see a hacking or DDoS attempt against the online casino, which is by far the favorite target of hackers. But in general, I just don’t want any of my infra touching the same stuff as these guys. Like another person here, I am assuming that Cloudflare ops told someone “tell these guys to get their own IPs and upgrade,” and then the message went to Cloudflare’s (utterly lousy!!!) sales people to try to fix before shutdown, and then it all turned into the mess we see here. The true moral of the story, I think, is, if you’re running an online casino on a shoestring budget, expect bad things to happen to you. Of all kinds.
- endisneigh 2y agoWhat happened to net neutrality? Why bring in sales if the issue is a legal one.
- drivingmenuts 2y agoThis reads more like a shakedown than anything. Even if the casino was being dodgy, CF went in asking for more money, not demanding that they stop doing whatever it is they were doing.
- muglug 2y ago> causing… irreparable loss in customer trust > I'm a SysOps engineer at a fairly large online casino Oh no, a casino losing the trust of its customers? Those places are normally so scrupulous!
- lijok 2y agoIt has become apparent that doing business with Cloudflare is a liability.
- chadsix 2y agoThis is the nail on the coffin, but make no mistake, Cloudflare has been a liability. It's a massive Man In the Middle decrypting all traffic, including OkCupid and 4chan for example. Imagine all those 4channers learning they aren't actually anon.
- NicoJuicy 2y agoThat's literally their business and why people use Cloudflare. Caching, detecting+modifying headers, routing traffic, ...
- 587846 2y agoThis is my first post on Hacker News as I primarily just browse. This situation kept me intrigued, wanting to know how it would unfold. The Google Cloud situation and all these little happenings, including the proliferation of Gen AI into everything, make me long for the days when companies had their mainframes onsite, in closets or separate rooms, away from CDNs and cloud networks. It seems like a better idea to use these cloud networks as a separate off-site backup rather than for primary use. I’d love to learn more about what will happen next in this saga. I’ve seen a post where a Cloudflare exec has posted here on HN before. They probably won’t say anything for legal reasons, but what repercussions can Cloudflare expect for this? Will they be, or can they be, sued for this downtime and the related expenses?
- psd1 2y agoDid you ever notice the bit in EULAs that states that maximum liability to the vendor is capped at what you paid? When big cloud goes down, you get a few days of credit. That's it.
- msh 2y agoWhen you do custom enterprise agreements you can get a lot more than that.
- pteraspidomorph 2y agoUnfortunately it's difficult and expensive to scale those traditional solutions to the modern world of billions of internet users located all over the world. It's still quite slow to access a server on the other side of the globe. It's less noticeable for an american user accessing an american company's resources.
- seec 2y agoDoes it matter for 90% of business? I will say no, the vast majority of business is rather localized for very good reasons (as a starter, language/culture/legalese) so it is an unnecessary "feature" most of the time. The reality is that manager drank the Kool-Aid and wants to pretend that they are Google/Facebook or the likes but almost no one else has this kind of scale. Outside of tech behemoth nobody need that cloud bullshit.
- cromulent 2y agoThe OP does not give their company nor domain name. I wonder if this is related to recent efforts by the Dutch to collaborate with Cloudflare to prevent online gambling companies operating in the Netherlands. https://igamingbusiness.com/legal-compliance/legal/cloudflare-to-assist-dutch-gambling-regulator-in-tackling-illegal-providers/ https://igamingbusiness.com/legal-compliance/legal/cloudflar...
- nolverostae 2y agoWe do already fully block the Netherlands since a long time ago since their regulations don't allow us to operate there.
- Tao3300 2y agoThe KSA license doesn't sound too unreasonable on the surface. What was the hang-up?
- Hikikomori 2y agoOr CF had already decided to kick them off the platform and tried to get some money before they did so.
- _cenw 2y agoNotable, their Enterprise plan quote included BYOIP. I think that's the kicker. Cloudflare likely got a few of their anycast load balancing IPs blocked in one country, causing a huge disruption, because this customer that makes them no money wasn't in full compliance with local laws.
- jrochkind1 2y agoI have been hearing stories from developers/entrepeneurs about Cloudflare being very weird to deal with: "We'd like to talk to you about an enterprise plan." "No thanks, I'm fine with the free plan." "Based on your traffic, we'd like to talk to you about an enteprrise plan." "Is there a traffic limit on the free plan?" "No, there is no limit. But based on your traffic, we require you to get an enteprirse plan." [Gives up and gets an enterprise plan] [6 months later] "Based on your traffic, we'd like to talk to you about up'ing your enteprise plan to a new monthly pay." "Is there a cap to traffic in our current plan? I don't see that in our terms." "No, there is no cap to traffic in cloudflare plans, but based on your traffic, we're going to require you to pay more per month than you are currently paying." "OK, can you tell me the traffic limit in our current or new plan? So I know what I'm paying for and when I'm approaching it?" "No. But you need to pay more." [Wash, rinse, repeat, every 6-12 months] It seems like while cloudflare technically does not charge for egress, in fact for large egress it's just a game of chicken between the customer and a salesperson every 6-12 months, with the salesperson trying to figure out the most they can manage to get without losing the customer? I mean, I guess that is standard for enteprise sales, but I think usually you at least have some terms to know what you've got for how long without a renegotiation?
- iamflimflam1 2y agoSounds like auth0…
- gruez 2y agoBut they have explicit limits? https://auth0.com/pricing https://auth0.com/pricing
- iamflimflam1 2y agoNot on the enterprise plans… it’s a chat with the sales team. And they’ve generally got you over a barrel.
- endisneigh 2y agoI wonder why they don’t just have clear limits - seems like it would make it easier to grok.
- andersa 2y agoDo we know of any alternative services providing at least the basics of what Cloudflare does? Such as: - Unmetered DDoS protection (i.e. no absurd base fee for it existing) - Unmetered rate limiting (protection against cost attacks on the next) - Reasonably priced object storage (i.e. not more expensive than numbers listed here https://blog.cloudflare.com/aws-egregious-egress)
- dmw_ng 2y agoCloudFlare does not provide unmetered anything, at best they provide services on a discretionary basis while trying as hard as possible to make it appear this is not the case. It's better to think of their product line as a CRM system with some CDN features on the side
- intelVISA 2y agoEasy to build in a few weekends, grab a few geodistributed racks with Mellanox NICs and do HW offload. Obj storage is a similar NVME DMA approach.
- bluelightning2k 2y agoTo be fair to CloudFlare - let's replace "unmetered" with "fair use". Very typically free = actually "fair use". Where it gets murky is when this becomes a shotgun sales tactic.
- eknkc 2y agoWe had a site hosted on CF business plan with fairly large bandwidth usage (completely legal, had a lot of media). They approached us with an enterprise plan but we did not have the budget for it. Asked for a little time, they said fine and we moved much of the bandwidth usage to a couple of dedicated servers on OVH I think. Never heard from them after that.
- weird-eye-issue 2y agoCan I ask how much bandwidth we are talking? We are doing about 3TB
- andersa 2y agoHow do you deal with DDoS attacks against said OVH servers?
- wiether 2y ago> By default, every OVHcloud product is supported by the Anti-DDoS infrastructure to defend against malicious activity. https://us.ovhcloud.com/security/anti-ddos/ https://us.ovhcloud.com/security/anti-ddos/
- RomanAlexander 2y agoeveryone that has used OVH and received an attack is laughing at that.
- 2y ago
- jt2190 2y agoNaively, I imagine that Cloudflare’s math looks something like this: (Amount owed by customer at end of month times the probability of on time full payment) minus Cost of providing service to customer for one month = profit Since this is an online casino, could the risk of late/under/no payment be quite high?
- dailykoder 2y ago>I'm a SysOps engineer at a fairly large online casino. So they did a good thing taking it down, no?? Addiction as a businessmodel is not that cool
- zamadatix 2y agoSidestepping the whole ethical conversation and just taking it as a good action for the hosting provider to do it still fails the sniff test as Cloudflare (according to this story at least) didn't seek to take it down rather sought to make more off of it.
- zb3 2y agoSure, but if two bad entities fight I don't care about any of them, let them fight to death.
- Dylan16807 2y agoIf we need to start labeling cloudflare as a "bad entity", then that's a big deal.
- byyll 2y agoAfter they deplatformed KiwiFarms, I thought that's an isolated case but turns out they are just unprofessional. I can't have pity for a casino service anyways.
- suroot 2y agoDidn’t they also deplatform stormfront and a few others they didn’t like?
- byyll 2y agoYes but then people argued it's about these websites being bad. Turns out it's just about money, considering Cloudflare has no problem with CP or other website calling for violence and celebrating it.
- hawthornio 2y ago> a web forum that facilitates the discussion and harassment of online figures and communities. Their targets are often subject to organized group trolling and stalking, as well as doxxing and real-life harassment.These actions have tied Kiwi Farms to the suicides of three people targeted by members of the forum. Sounds like a pretty abhorrent website
- byyll 2y agoWho wrote that?
- kmeisthax 2y agoCloudFlare only dropped Kiwi Farms because Keffals made it inconvenient for them to do business with enterprise customers. Said customers were looking at Twitter and saying, "Wait, you host WHAT?!" Before that CF was high and mighty on the "free speech" horse. There's an old spat between CloudFlare and Malwarebytes where MB was threatening to block all of CloudFlare because they wouldn't remove literal malware. The argument being that running a reverse proxy "isn't hosting", and should be treated differently, even though to literally anyone else there's no difference between an origin server and a proxy. CloudFlare is just sketchy as all get out, IMO. Putting my biases on the table: I think CloudFlare shouldn't have hosted Kiwi Farms in it's current state, because I don't think hosting dox should be legal. A website that hosts dox is not engaging in speech, it is engaging in censorship. Hell, in the EU, it's already illegal to host dox, the US just needs to pass a privacy law comparable to that of the GDPR. Kiwi Farms is legal in the US purely for the same reason why the CIA/FBI/NSA can legally buy advertising data from Google and Facebook.
- emilfihlman 2y agoI guess it's the natural cycle of money always spreading its tentacles to everywhere, and specifically applying pressure after sufficient metastasis and entrenching.
- dangtimewaste 2y ago[dead]
- aeyes 2y agoFrom personal experience I know that 10TB per month is like 30k/year and SSL for SaaS is around 40k/year on the enterprise plan. No idea about pricing for having your own IP. I have no idea why Cloudflare would ask you to use these two features. SSL for SaaS is only useful if you want to add domains and certificates via API. I have had my fair share of negative experience with Cloudflare but this is next level bad. Unfortunately companies can chose who they want to do business with but it shouldn't be like this.
- weird-eye-issue 2y ago> From personal experience I know that 10TB per month is like 30k/year Is this true? We are at 3TB and growing so I'm slightly concerned
- tristan9 2y agoIt's not even 100Mbps sustained. That is nowhere near 30k/year or you're getting ripped off. For 3k/month you can get a good quality 10Gbps link. That's 3.2PB with a P.
- weird-eye-issue 2y agoYeah that's why I was asking
- bogwog 2y agoStart making a backup plan
- csomar 2y agoIf you are doing any serious business you should have a plan B always ready (ie: fastly) and a downgraded state where you can operate without a CDN.
- weird-eye-issue 2y agoAlmost all of our state is stored inside Durable Objects and R2 and we use Workers extensively
- jesprenj 2y ago> I'm a SysOps engineer at a fairly large online casino. And for some reason Cloudflare's the bad guy.
- Hikikomori 2y agoFor some reason both cannot be the bad guy?
- SXX 2y agoDDoS services are protected by CloudFlare because free speech and legal online casino are bad guys. Good.
- hardfriendship 2y ago[dead]
- luuurker 2y agoThe way Cloudflare approaches situations like this is not ideal for anyone. You start using the service and don't pay a lot, so you make plans around a certain level of expenses. Then out of the blue you receive an "urgent" email from a sales representative and suddenly you have to go from $20 or $250 to $thousands right away. Obviously it's not in CF's interest to keep a customer that doesn't pay enough, but dropping a "bomb" on the customer and make them feel like they're about to be kicked out from the service makes the customer lose trust on CF. CF can probably match Fastly's price. If they had acted differently in this and other similar situations, they could keep the customer, be paid more, trust wouldn't be affected, and there would be no bad PR here. Since the CF management that posts on HN usually say this is not supposed to happen, perhaps someone needs to sit down and look at the incentives sales reps have? Even if you don't care about the customers, this is affecting the CF brand a lot.
- HenryBemis 2y ago> but dropping a "bomb" on the customer Why on earth any company would jump from $250 to $10k per month unless they had a gun to their heads? Even if their revenue is to the millions/billions (which most likely is considering the nature of their business). They work for their own profit, not Cloudflare's.
- slyall 2y agoThe point is it doesn't have to be a "gun to their head". It just needs to be a serious of emails, calls and negotiation. I'll be they are now paying Fastly a lot closer to $10k/month than $250/month
- luuurker 2y agoNo one wants to pay more, but if they do it in a way that makes their customer run to a direct competitor and not want to come back, then maybe there's something wrong with their approach. We only have one side of the story here, but it's not the first time I've seen posts/comments about these emails from Cloudflare and the messy communication that follows. As a business customer, I really hope I don't have to deal with any of this.
- ecjhdnc2025 2y agoI will remind HNers: is Cloudflare not the company that leaked sensitive data through cache files that were indexed by at least Google, and when the tech community were up in arms about the massive leakage of sensitive data, the CEO’s strategy was to turn up here and criticise Google for not deindexing quickly enough? You get what you pay for.
- luuurker 2y agoI remember them criticising Google for not being faster at removing cached files. I don't remember them blaming Google for their screw up. And let's be honest, if a big provider wants to offer cached versions of pages, they probably should have a way to purge those files in case there's a problem (eg: malware).
- ecjhdnc2025 2y ago> I don't remember them blaming Google for their screw up. You're putting words into my mouth.
- Twirrim 2y agoI'm not sure what you were expecting people to take away from your message, with the way that it is worded. It may not have been the intent, but the particular way you expressed your point heavily implies it.
- ecjhdnc2025 2y agoI wrote what I wrote. He came here and in his only comment, criticised Google for not being quick enough. That is all I wrote and all I meant. https://news.ycombinator.com/item?id=13718752#13721644 https://news.ycombinator.com/item?id=13718752#13721644 I don't much care if words are being put in my mouth but I do point it out. But then again as Maya Angelou said: "When someone shows you who they are, believe them the first time."
- 2y ago
- tiffanyh 2y agoCan a sales rep de-platform you? I hope that’s not the case, because that would allow for bad behavior by reps trying to manufacture end-of-quarter sales. EDIT: why the down votes?
- tgtweak 2y agoOnce you upgrade to Enterprise it's a nonstop 6 month cycle of asking you to pay more. Couple this with the fact you have a new rep every 6 months and you get some pretty annoying nag service for the entire duration of your contract.
- intellix 2y agoevery 1-2 months
- deleted 2y ago[deleted]
- xyst 2y agoI’ll be honest, the high pressure to pay almost seemed like a well devised scam or phishing email. Scammer does recon on victim. Notices they use CF. Use high pressure sales tactic to get them to pay a hefty sum up front or else lose access. But as you read on, I see company did their own DD and followed up directly with CF executives and teams. Confirmed account is locked at CF. In this case, CF is acting scammy. I wonder if they are having liquidity issues thus the push for high pressure sales tactics and blackmail.
- Vvector 2y agoWhy is HN demoting this article? It was at the top of HN, then quickly buried to #20-#30. It is now at #27, being a hour old with 318 points.
- tgtweak 2y agoYep, from #1 to bottom of the first page in 5 minutes...
- yxhuvud 2y agoIt is actually more likely it is the opposite, that it got temporarily boosted to get exposure, and then fell back as interest vaned. If mods want it gone, then it will be gone.
- elaus 2y agoIt was significantly downranked after about an hour on #1: https://hnrankings.info/40481808/ https://hnrankings.info/40481808/
- youngtaff 2y agoLooks like a group of people decided to bury it
- KingOfCoders 2y agoSounds like the famous Oracle licensing team.
- bluelightning2k 2y agoAt the moment the account got banned, I would guess that the CloudFlare sales team had this down as a "60% likely to close, estimated close in 6 weeks". There is just no reason they would suspect that they were going to lose the deal to Fastly at this moment. They were very much the default winner. Extortion or not, I just can't fathom that they ragequit the deal at this moment, because they were about to win it. It therefore seems likely that after looking into it they disqualified it as a business category which is against their TOS or whatever. Or that the enforcement and sales teams have very similar, overlapping triggers for engagement, etc. Cloudflare's behaviour here was shitty and this is not the only report. By all means their reputation is very generous free tier and a horrible experience in paying. BUT seriously who ragequits a winning deal? Another comment summed this up - the attention caused them to take a look and realize they don't support shady-ish casinos, possibly (seeming to) evade US legislation, etc.
- wraptile 2y agoIt's quite a common pattern in saas. Someone gets through automated ToS checks with some niche use case and escalates some unrelated issue to support which triggers manual ToS review. That being said, a corporation as big as CF with 120k usd bills should do better and never let this happen. Very amateur.
- chatmasta 2y ago> It therefore seems likely that after looking into it they disqualified it as a business category which is against their TOS or whatever. The first sales email is from a Cloudflare with “Gaming Division” in their email signature, so they were clearly aware of the nature of the customer’s business. Moreover, it seems they have an entire department dedicated to serving the gaming market.
- Xeamek 2y agoCan any1 explain how HN algo works that this post, which at time of writing has 355p, 180comments while being posted 1 hour ago, isn't even on first page (ranked 31)???
- greyface- 2y agoFlags below the [flagged] threshold are invisible but still act to downweight the post.
- CamelCaseName 2y agoI've noticed that cloudflare complaint threads get flagged with surprising and unwarranted regularity.
- CtrlAltDelete51 2y agoAlmost, like … maybe one of the “protection” providers might have ways to suppress bad media? puts on tin foil hat and looks around nervously
- user_7832 2y agoA more charitable interpretation is that lots of techy HN'ers would rather defend CF against an unknown company, as some sort of tribal allegiance - the same way Apple has a huge cult following. Nonetheless the end result (flagging/downranking) is wrong - hell, I had to find this thread by going to my previous comments as I couldn't find it on the front 2 pages. If that isn't considered an abuse of systems (again, charitably speaking, unintentionally), I don't know what is.
- user_7832 2y agoIf someone disagrees with me or if I wrote something wrong I'll be happy to modify/edit my comment, but if you just downvote it really isn't clear
- 2y ago
- diimdeep 2y agoPlease stop using cloudflare, cloudflare captcha and google captcha is spyware and it needs to go away. > captc
- tekkk 2y agoHuh. Now that was some high-stakes poker right there. It seems the casino knew they were breaking the TOS and paying too little and Cloudflare caught up with that. Then knowing their situation they decided to ask for payment for all the expenses of the previous years (and some extra). In quite passive-aggressive manner. But the casino still decided to stretch the penny and alas, whoever at Cloudflare was in charge got quite upset their extortion-tactic failed. So they decided to resolve it the American way and kick them out with zero warning - ouch! How fascinating. I myself like using Cloudflare as it's quite affordable to setup and use. Makes me sad to know they have to resolve to tactics like this to finance their service. Well, at least I don't work in dubious businesses that violate TOS so perhaps I can at least wish for a graceful termination when my Enterprise bill is due.
- KingOfCoders 2y agoIf you depend on one vendor, as CTO always have a plan-b prepared that you can pull out and execute. Stall, stall, stall while you're executing your plan. $120k will never be enough, price hike is incoming for renewal.
- pclmulqdq 2y agoAs far as I can tell, the issue with this is: OP runs a casino/gambling site. Gambling is a regulatory mess (I have spent far too long dealing with this as an RNG supplier), and so it's very hard to comply with every jurisdiction, and each one needs you to prove compliance to operate in that jurisdiction.* Gaming companies spend a lot on compliance and tracking, but since the internet is the internet, it's pretty hard to enforce perfectly, so some countries and ISPs take this into their own hands. Due to that, IPs hosting gambling and gaming sites often get regionally blocked by internet providers or otherwise flagged as hosting illegal content. Those regional blocks consequently affect the reputation score of the IP, and if you are a traffic aggregator like Cloudflare, can cause other customers to have issues. One of the most aggressive and annoying regulatory environments for gambling companies is the US, so it's very possible Cloudflare has had some trouble due to gambling use of their IPs in states in the USA. Cloudflare wanted them to use the BYOIP features of the enterprise plan, and did not want them on Cloudflare's IPs. The solution was to aggressively sell the Enterprise plan, and in a stunning failure of corporate communication, not tell the customer what the problem was at all. The message from Cloudflare should have been "Enterprise plan + BYOIP or ban, and maybe we'll work with you on price" but it was instead "you would really like the Enterprise plan." *As an aside - we're lucky in that respect being a tech supplier with relatively uniform rules, but our customers (the gaming companies) get the short end of the stick here.
- zbentley 2y agoI also wonder if the company in the article didn’t know that (either by reading between the lines as you did or via other correspondence they didn’t mention) and weighed that in their decision to go with Fastly. BYOIP isn’t just expensive—if your content is bad for IP reputation the time-to-flagging of your IPs is going to be way shorter on BYOIP than on shared IPs due to there being less dilution. And that’s without getting into the challenges around rotating/renting IPs on a continual basis. I do agree that CF did not communicate that well or professionally—if the sales emails are the only comms that happened here.
- pclmulqdq 2y agoI think it is possible that the company posting this didn't realize that this might be the issue, but you are right that they may know. It may have been a small company, even doing that much bandwidth. Online gambling sites tend to push an entire video game when you are playing on their site. Many gambling companies are fine just doing BYOIP or running dedicated hosting infrastructure that is on providers who are explicitly running hosting for that industry (although they are moving to cloud). There is a good reason this separate infrastructure exists. In general, I would not assume they are rotating IPs: this is not a scam, it's a business, and they are largely fine with being blocked in places where they can't legally operate.
- CtrlAltDelete51 2y agoWhile the author could improve the narrative in his article, the historical issues with Cloudflare combined with, yet another one, paint a stark picture. Combine it with the stories I hear about Sales, the numerous other PR fumbles already mentioned in this thread, and the months I’ve personally waited (while on a paid plan!) for ticket responses only to get cookie cutter responses is, quite frankly, embarrassing. CloudFlare puts in a good front, and their products seem decent, but they really have questionable business practices that should make anyone think twice before using them.
- moltar 2y agoJust wow. We were in the midst of negotiations with Cloudflare and I’m Going to hard nope after reading this. I’m guessing they aren’t doing that well and are looking for revenue to cover the holes.
- markonen 2y agoI moved away from Cloudflare—to self hosting our network infrastructure—because, while this didn’t happen to us, I was very aware that it could. We had a great deal on Enterprise for a couple of years, but zero guarantees that it would last (and some indications that it wouldn’t). I wanted to stop praying that they wouldn’t alter the deal.
- OutOfHere 2y agoBeyond Fastly, what are viable non-extortionist alternatives to Cloudflare?
- Kronolord 2y ago[flagged]
- AlexErrant 2y agoMeta: 455 points, 3hrs old, but on the 2nd page of HN. What's up with the algo?
- nolverostae 2y agoI'm not sure. It was on spot one on the first page, then something happened and it got downranked: https://hnrankings.info/40481808/ https://hnrankings.info/40481808/ maybe due to being flagged by people (according to another comment). I guess it's due to general negative sentiment towards casinos, which may be understandable but doesn't (in my biased opinion) change anything about CF's behaviour in this post. I would have left it out but it's necessary in order to provide the full context.
- randunel 2y agoThis post was definitely demoted by HN. It stayed in the first position for less than 5 minutes and, as it quickly gathered upvotes, it jumped straight into 24th and quickly fell off the first page as it got 200 or so more points in less than an hour. I'm 80% confident HN tried to hide this link. It's the fastest downhill I've noticed on here, and I've been lurking and commenting for longer than 10 years.
- hengheng 2y agoPage 3 at #70 after four hours.
- dilawar 2y agoI had to search for it. I was under the impression that HN removed it for some reason. Does HN has stake in cloudflare?!
- AlotOfReading 2y agoRanking is strongly impacted by the flamewar-detector. Affected threads are automatically downranked to cool things down until a moderator steps in and manually reviews it.
- blibble 2y agoyep, it happens every single time a negative story about cloudflare appears more than a coincidence
- coolspot 2y agoThat’s why I use hckrnews-com as HN front-end.
- dangoodmanUT 2y agoHow is this not still #1? 488 upvotes in 3 hours. It was number one, the right to the third page? sus...
- o999 2y agoEvery business with this size should have another CDN as failover, relying on a single provider is proven to be dangerous.
- mediumsmart 2y agoSo when they asked to pay the 10k monthly, was that to gain time to move or was the price acceptable? Does it say anywhere?
- o999 2y ago[flagged]
- jononomo 2y agoIsn't there some kind of law against companies extorting the customers and being evasive about their terms of service and their prices?
- grishka 2y agoCustomer protection laws usually only work for individuals, not companies.
- sampli 2y agoThe casino in question is Gamdom btw
- ivraatiems 2y agoThis sort of situation is not time for an angry blog post. It's time for lawyers. OP needs to speak with counsel and find out whether they have a claim against Cloudflare for interfering with their business in this way. (If OP's business is so illegal they can't get a lawyer to help with that, that's another story, but it sure doesn't look that way.) Fundamentally, the OP might be involved in something scummy or at least against Cloudflare's TOS. But if that's the case, if you have a customer who is violating your TOS, you don't hit them up and say "pay me an extra $119k a year and I'll look the other way". You say "here are your violations, fix them and prove to me that you fixed them, or pay for plan X which has terms under which they are not violations." The way Cloudflare handled this is completely inappropriate and even if it wasn't their intention, makes it seem very strongly like extortion. Two wrongs don't make a right, and OP's business being possibly shady does not give Cloudflare license to extort them.
- Dylan16807 2y agoWhat are lawyers going to do about the clause that says they can drop anyone any time? Trying enforce "reasonable behavior" by suing is a massive money pit that might yield nothing at all.
- johnklos 2y agoCloudflare is evil, even though they do a decent job of pretending they care. They are smart to offer gateway services (gateway as in gateway drugs - stuff to get you hooked) for free to end users, since it grows their fanboi base, gets more people familiar with their services, and gets people hooked in ways that make it very difficult to use something else when their projects grow. However, any reasonably competent person can see that recentralization of the Internet is a Bad Thing™, and that this is precisely what Cloudflare wants. Likewise, we know that aggregating our data through a for-profit company that's based in the United States means that collected data is reasonably in the hands of the NSA, which makes their DNS-over-HTTPS scheming suspect. Just like what happened with the company in this post, we have plenty examples of them abusing their position to extract money from both legitimate companies, like this one which is aware of their legal obligations in various countries, and scammers and spammers alike, who Cloudflare are more than happy to host indefinitely in the name of "free speech". Their lack of clear communication, their broken abuse reporting, their continued claims that they don't "host" all show them to be antagonistic towards anyone negatively impacted by their facilitation of illegal activity. Cloudflare is an evil company that just happens to be better (but not great) at hiding it than other evil companies.
- mschuster91 2y ago> However, any reasonably competent person can see that recentralization of the Internet is a Bad Thing™, and that this is precisely what Cloudflare wants. It's an inevitable outcome, as long as there is nothing done against the big threat actors: government-run APTs from China, Russia, North Korea and Iran, government-tolerated scammers (India, Turkey), rogue actors in our governments' security services (e.g. Pegasus), ordinary criminals mass-hacking vulnerable devices and selling access to them to be abused for DDoS'ing for less than the cost of a coffee at Starbucks... it's a wild west, and people are hiding themselves behind the largest giants they can find: Cloudflare, Akamai, AWS, Azure and GCP. [1] https://en.wikipedia.org/wiki/Pegasus_(spyware) https://en.wikipedia.org/wiki/Pegasus_(spyware)
- johnklos 2y agoYou're throwing unrelated facts at the statement. Recentralization has absolutely nothing to do with being protected from DDoS or from other threats. Now, DDoS (and other kinds of) protection can be done by recentralization, but that's just one possible way. Saying it's inevitable makes you seem like a Cloudflare apologist, which unfortunately we see way too often here on ycombinator. Has anyone refuted my suggestion that Cloudflare is knowingly evil? No. Have they downvoted because my information is incorrect? Also, no, or if they think I'm incorrect, they haven't bothered pointing out how. People want to like the things they choose, and this, unfortunately, is where Cloudflare is cleverer than other large, evil companies.
- hnbad 2y agoWay to bury the lede of OP running a gambling site and doing a ton of shenanigans to make it legal in different jurisdictions. I understand why you might think you shouldn't lead with that but it puts the entire response from Cloudflare into perspective as dealing with gambling sites sounds like a headache and it's reasonable they might not want to run that kind of venture on a regular plan.
- nexoft 2y ago1-The gambling business is shady by design, whether you like it or not. This was probably more risk than benefit for them based on what they were getting from you. 2-Your business is probably very profitable, and $300 a month is very cheap compared to the potential hassles they could face working with such a business. 3-I find it very inappropriate to dox business representatives and show names when you have carefully hidden any information regarding yourself and haven't even disclosed your company name. After all they can choose with whom they want to do business. They gauged what price they could ask you, factoring in how profitable your business is and how noisy and painful it might be to work with you. It sucks but this is the downside of SaaS/PaaS.
- EmilStenstrom 2y agoGambling site or not: Cloudflare took their money for years, failed to communicate any problems, then deleted their data when they didn't accept their "enterprise deal". There's nothing saying that they won't do the same to ANY of their other thousands of customers, many of who reads this forum...
- deleted 2y ago[deleted]
- Aeolun 2y agoJup, that’s my takeaway. Even if they were in the “right” to stop serving the customer, the way they went about that is absolutely ridiculous.
- dangus 2y agoCloudflare certainly handled this poorly in their execution and abysmal level of transparency, but they’re almost certainly purging loss-leading risky customers like OP and they really don’t owe OP the time of day. OP is lucky CloudFlare even gave them 24 hours. I’m not going to dig through the their TOS or anything but I’m going to guess that you need to have an Enterprise contract to be a business of certain categories like banks/crypto, pornography, and gambling, which explains why they were being connected with a sales team. OP mentions lost customer trust…but Cloudflare doesn’t want or need OP to trust them. $250 a month isn’t enough to deal with a business like that.
- graycat 2y agoOkay, with this thread, I'm learning and need to: One Question: For the Web site for my startup, I have the ASP.NET code running so ASAP will be getting into to a business account with my ISP, IPs, domain names, DNS, etc., at least for the Alpha Test. So far, my intention is to host my own Web server. I've heard of CloudFlare, how they can help stop DDOS attacks, etc. but so far have hope not to use them. Question: How realistic is it for me just to host my own Web server and, e.g., avoid any chances of problems with CloudFlare, the Cloud, VPNs, etc.? Thanks!
- tamimio 2y agoRule #1 in any work, business, or even personal and social life: never put all your eggs in one basket. For CF first example, only use the cdn part, don’t use the registrar one, there are more registrars out there, don’t use their worker, use something else, and do on. It’s for obvious reasons, when shit happens, you can mitigate the impact quickly and easily compared to using all at once.
- udev4096 2y agoSo that's how you make the internet a safer place. Good job Cloudflare!
- ehathaway 2y agoI'm surprised by how many comments seem to assume Cloudflare is at fault. Shouldn't the default assumption be that no one did anything wrong? In defense of Cloudflare, the sys ops engineer should have understood the situation and knew they were misusing Cloudflares services. They decided to play hard ball by bringing up the fact they were thinking of leaving. And we have no history of the multiple phone calls they had with Cloudflare.
- sharpshadow 2y agoThey figured out that they are losing money with you and offered to negotiate a new plan which was declined so they made and offer which was ignored and you let them know that you maybe want to change the service so they magically found an violation and after still not accepting their offer they took you down. Pretty standard behavoir from both sides with room for improvement. They should have been more clear about what's going on and you should have been more insightful what they wanted. In my opinion they acted to fast and not really cooperative, but if you wouldn't have declined the initial offer and started to figure out why they offer it and what options there are, you would have came out with a better deal than 10k/month and likly without 1 year upfront payment which would have given you the time needed to transition to another service.
- deleted 2y ago[deleted]
- mikhailfranco 2y agoAnother issue with Cloudflare is that it seems to be blocking VPN access to sites that have any regional restrictions. Of course, it is easy to identify the IP addresses of the well-known VPNs, so it's not rocket science, but it does mean that popular VPNs will no-longer give you out-of-region access.
- tonetegeatinst 2y agoRegardless of who was in the right....it scares me how much cloudflare and the cloud have become ingrained in the internet. Imagine getting banned by cloudflare or some other cloud provider....
- geenat 2y agoSales teams can be asinine to deal with. I don't think cloudflare realises how damaging this is for them long term.
- uxx 2y agoBillion dollar unregulated casino that is burning through cloudflare ips.. i don't see where cloudflare can be blamed here, they stated you should BYOIP, you didn't approve and were banned, their is no blame here. Just FYI some countries ban casino domains/ips that are not licensed to operate even when its "just a landing page that says sorry not available"
- mrjin 2y agoWOW