upvote
Do you get paid commission for comments like this? Genuinely feels like an ad-read
reply
I think they articulated the underlying issue well. Cloudflare is too attractive for individuals and small businesses. For instance, my personal website has a healthy amount of traffic, but means nothing at CDN scale. I considered moving to a EU CDN company, but they all have per GB/TB pricing. It would cost me nothing now, but what if my site comes under attack or someone starts hotlinking a large file? So, I stay with Cloudflare because with their free plan I don't have to worry about such contingincies.

I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.

reply
I was explaining why I believe it's a super popular service. I have no affiliation or stock, just a regular user.
reply
My PM buddies speak like this about any subject.
reply
> now you can get by on a $200 a month plan for a small business

You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.

reply
What you're paying for is business continuity, not for them to host your site. I know you can host the site itself on much cheaper infrastructure.
reply
If your site is static you can host it on CF pages for free with unlimited* egress.

* of course it's not unlimited unlimited but I've not heard of anyone being cut off.

reply
> you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you

This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

reply
> Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.

Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.

But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.

reply
It's quite standard these days. If you're already with Akamai then you're not an attractive target though, so maybe that's why you haven't seen many of those? The DDoS services are really cheap today and it's pretty normal to get attacked regularly if you're large enough. For $100 you can easily get 5gbps for a few days, or larger volume / shorter time for <$50 subscription. But there's no reason to attack anyone already on a quality CDN service.

> and I don't think people should default to trying to prevent them.

It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.

Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)

reply
I was curious and it seems like smaller businesses do get DDoSed, ~5% of them in Canada:

https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...

reply
That graph is useful for the people who think DDoS is the biggest issue or even a big issue typically: https://www.bdc.ca/globalassets/digizuite/55250-canadian-sma... "Percentage of Canadian small businesses that have experienced a cybersecurity incident"

The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.

reply
What exactly are you arguing? I already said 5%. Your personal experience of DDoS being super rare doesn't seem to match the real world.
reply
For small businesses? None. Nobody is ddosing a cake shop and if they do, the cake shop doesn't really care enough, because their business is in the store not online, and can afford to let the ddoser waste their money for a few days.
reply
I think their delusion is probably in what they consider a small business. A lot of people on here, given their work experience, think of small as something with a few hundred employees.
reply
Given that we're on HN I probably should've said startup, though depending on the business itself it's not unrealistic for some of those 200-400 employee companies to sit on a free Cloudflare plan if their entire website is static + a back-office CRUD app.

If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.

reply