TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Cloudflare's Disruption

578 pointsby oedmarapover 3 years ago

28 comments

stevebmarkover 3 years ago
In 2017 Cloudflare had an HTML parser bug that caused encrypted HTTP traffic to be leaked. Any website served by Cloudflare was vulnerable to having all of its traffic leaked into the HTML body response of the website that Cloudflare proxied. Given that Cloudflare is the proxy service for 80% of websites that use proxies, this affected a significant portion of the internet.<p>Cloudflare served private HTTP traffic in response bodies, meaning that website results contained cookies, session data, encrypted traffic, all personally identifiable, and because it was served as response bodies, it was *indexed by search engines*, not to mention anyone else who was scraping websites during the time of the incident. It included credit card information, frames from videos, PII, the works, all linked to individual users.<p>This was ongoing for *months.*<p>Anyone savvy could use this information to hijack accounts, scrape personal information, view private browsing habits. Even when Cloudflare publicly announced it (and tried to blame others) when they thought they had cleaned up most of the data, you could still easily use search engines to find people&#x27;s personal information by searching for the Cloudflare header strings that started the leaked session information.<p>Many countries have legal policies around data breaches, including required disclosure policies and penalties. In the greatest blind eye turn of the history of the internet, Cloudflare managed to get away with a single blog post, and no other penalties. <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;incident-report-on-memory-leak-caused-by-cloudflare-parser-bug&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;incident-report-on-memory-leak-c...</a><p>THAT is Cloudflare&#x27;s disruption.
评论 #28715414 未加载
jerfover 3 years ago
&quot;More importantly, AWS itself is locked-in to its integrated approach: the entire service is architected both technically and economically to be an all-encompassing offering; to modularize itself in response to Cloudflare would be suicidal.&quot;<p>Eh, somewhat. AWS is already modular in a lot of ways. You want S3? You got it, no matter where you are. (We&#x27;re talking after them doing some sort of fee drop here.) You want to run exactly one EC2 instance? No problem. You want a message queue? You don&#x27;t <i>need</i> anything else. You can integrate it with the notification service but it&#x27;s optional.<p>Sure, some of their services are integrated, but a lot of that integration is just &quot;this service pulls from S3 and writes to S3&quot;, not massive integration at every level.<p>There is some stuff that is deeply tied in, yeah. But it&#x27;s not like every single AWS service is deeply tied into half the other ones and the moment you open an EC2 instance you also are buying into a dozen other services. (It may feel like it if you put together a network and override the default block storage, but that&#x27;s really just giving you knobs that are simply preset elsewhere, not really &quot;lockin&quot;.) A lot of it is already pretty modular.
评论 #28713843 未加载
评论 #28709215 未加载
评论 #28714828 未加载
评论 #28710949 未加载
评论 #28713185 未加载
评论 #28712878 未加载
评论 #28710690 未加载
kureikainover 3 years ago
Cloudflare is truly amazing.<p>They almost compete with everyone now.<p>DNS: They eat simpledns lunch Pages: They eat Netlify lunch Worker: They eat serverless&#x2F;lambda as in AWS&#x2F;GCP lunch R2: They eat AWS Lunch<p>And finally<p>Email Forwarding: They eat ... my own lunch (I&#x27;m founder of hanami.run an email forwarding service)<p>That&#x27;s being said, from a user perspective, if my domain is already on CloudFlare, I can just host everything on it.<p>Right now, cloudflare workers is pretty great to add some dynamic stuff. And pages is great for static site.
评论 #28712512 未加载
评论 #28709595 未加载
评论 #28710071 未加载
评论 #28712839 未加载
评论 #28716105 未加载
评论 #28726640 未加载
评论 #28711610 未加载
评论 #28712691 未加载
评论 #28709983 未加载
notacowardover 3 years ago
If Cloudflare is able to do this now, why wasn&#x27;t Akamai able to do exactly the same thing when AWS was still a baby? Serious question. Was it lack of vision? Poor execution? Technology or market just not ready yet? Without such an answer, we might have to consider the possibility that Cloudflare <i>isn&#x27;t</i> any more able to do this than Akamai was.
评论 #28710880 未加载
评论 #28710571 未加载
评论 #28712449 未加载
评论 #28716923 未加载
评论 #28709604 未加载
ksecover 3 years ago
&gt; The service will be called R2 — “one less than S3,” quipped Cloudflare CEO Matthew Prince in an interview with Protocol ahead of Cloudflare’s announcement<p>Oh I never thought of that. So the next one is Q1 and final one would be P0.
评论 #28708575 未加载
评论 #28710230 未加载
评论 #28708791 未加载
评论 #28709160 未加载
评论 #28709043 未加载
评论 #28708823 未加载
评论 #28727496 未加载
72f988bfover 3 years ago
&gt; S3&#x27;s margin is R2&#x27;s opportunity<p>Indeed, it looks like &quot;your margin is my opportunity&quot; motto can work both ways for Amazon :)
评论 #28714313 未加载
mathattackover 3 years ago
The egress costs are finally coming to light for CIOs and CFOs. (And pissing them off)<p>Cloudflare has a lot to gain by fixing this.<p>Fascinating company.
评论 #28710220 未加载
评论 #28709496 未加载
评论 #28709470 未加载
tyingqover 3 years ago
It feels like if they released a serverless&#x2F;Lambda equivalent they would start taking a lot of business from the big 3. Workers are somewhat close, but the v8&#x2F;isolate pattern limits them to narrower use cases. A more traditional serverless that could sit at the center and be optionally fronted by Workers would be nice.
评论 #28709363 未加载
评论 #28708522 未加载
评论 #28708421 未加载
评论 #28709524 未加载
pjfover 3 years ago
&gt; Cloudflare’s unique advantages in a world where the Internet is increasingly fragmented<p>Wait, it&#x27;s the opposite, at least on the infrastructure side. The Internet is increasingly centralized, due to Cloudflare and other big players.
tommek4077over 3 years ago
How was it ever possible for S3 to take such a market share. Or is this market share not existing? Coming from the 90ies I could never imagine paying for outgoing traffic when already paying for a server with internet connection. There was a.early time where you would get throttled to 100MBit (and much earlier in time to 10MBit&#x2F;s) but this is long gone. What do you do with S3 that such prices seem fair for anything other than rarely accessed files?
评论 #28710528 未加载
评论 #28709095 未加载
评论 #28710730 未加载
评论 #28710332 未加载
评论 #28709504 未加载
erulemanover 3 years ago
A great example of counter-positioning. Cloudflare is positioning itself in the market in a way that its competitor (AWS) cannot replicate — their lock-in is predicated on egress fees.
评论 #28710509 未加载
aborsyover 3 years ago
AWS Lightsail now offers S3 object storage with reduced egress fees: 250 GB storage, 500 GB transfer, 5$&#x2F;month.<p>With standard S3, that egress traffic would cost 45$ -50$.<p>Sounds like AWS is competing with itself.
评论 #28715203 未加载
评论 #28712914 未加载
janandonlyover 3 years ago
After reading this I felt the urge to buy Cloudflare stocks... anyone else as well?
评论 #28708681 未加载
评论 #28708920 未加载
评论 #28709288 未加载
评论 #28710381 未加载
评论 #28710044 未加载
评论 #28710457 未加载
评论 #28708806 未加载
muttanttover 3 years ago
Cloudflare is incredibly undervalued as a public company.
评论 #28709088 未加载
评论 #28709020 未加载
dabinatover 3 years ago
I thought I could save money by hosting some backend services in-house but soon realized it ended up being more expensive than EC2 solely because of the egress fees.<p>So whether or not Amazon intended it that way, it functions as something that’s anti-competitive because it forces you to go all-in with AWS.
vjustover 3 years ago
I like this. AWS feels like a proprietary mainframe system (will get downvoted for saying this).<p>Anytime a majority of developer job postings mention a specific product&#x2F;company certifications, (think PMP, or Microsoft developer certs) , its time to pivot your skill sets.
评论 #28712418 未加载
评论 #28716048 未加载
busymom0over 3 years ago
The post right about this post on HN&#x27;s front page is titled &quot;Slack is experiencing a service disruption&quot;. So for a second I thought CF was having some disruption (outage) which caused Slack to go down.
aasasdover 3 years ago
&gt; <i>It’s impossible to overstate the extent to which AWS changed the world, particularly Silicon Valley. Without the need to buy servers, companies could be started in a bedroom, creating the conditions for the entire angel ecosystem and the shift of traditional venture capital to funding customer acquisition for already proven products, instead of Sun servers for ideas in Powerpoints.</i><p>So the author thinks that shared hosting or servers-for-rent did not exist before AWS&#x27; popularity?
raywuover 3 years ago
Good write up. Classic Christensen.
评论 #28708371 未加载
评论 #28708636 未加载
jiveturkeyover 3 years ago
&gt; Hotel Seattle
pbreitover 3 years ago
Why is it still so ridiculously difficult to put some DB-backed, servable, editable code up in the cloud?
bob-a-fetover 3 years ago
Can we use R2 for video? Workers KV prohibit use for video. Video streaming is the #1 growth area since the pandemic. Why is it that we can use it and Workers KV to store images but not video (chunked) ?
评论 #28737911 未加载
throwaway1777over 3 years ago
I wonder how this relates to 5G which also pushes more storage and even compute to the edge.
评论 #28709144 未加载
aborsyover 3 years ago
Would this compel AWS to eliminate or lower egress fees for S3?
评论 #28712921 未加载
luggedover 3 years ago
10%.. disrupted.
m_keover 3 years ago
Cloudflare could really shake things up on the ML side of things. The egress costs and GPU prices on AWS and GPC make them a nonstarter for most companies, forcing people to rack their own hardware.
评论 #28708824 未加载
评论 #28711231 未加载
andrewstuartover 3 years ago
&gt;&gt; &quot;The most familiar API for Object Storage, and the API R2 implements, is Amazon’s Simple Storage Service (S3).&quot;<p>Ugh - a clone of S3&#x27;s functionality - that&#x27;s not competing.<p>There&#x27;s been zero innovation in cloud storage beyond S3&#x27;s primitive capabilities. None of the competing services have gone beyond S3&#x27;s stunted functionality.<p>Online storage should provide:<p>* An SFTP interface (and no, Amazon&#x27;s &quot;charge by the hour SFTP interface to S3&quot; doesn&#x27;t count)<p>* The ability to query and apply filters to queries PLEASE! For goodness sake its 2021.<p>* A webDAV interface<p>* The ability to incorporate object metadata into filtering queries<p>Why is there zero competitive drive in this space?
评论 #28713822 未加载
评论 #28713620 未加载
julianlamover 3 years ago
I find it deliciously ironic that CloudFlare is eating AWS&#x27; lunch with their launch of R2, after Amazon did basically the same thing with a bunch of their services built upon open source projects.<p>I suppose it&#x27;s now corporations stealing market share from each other...
评论 #28708784 未加载
评论 #28708729 未加载
评论 #28708742 未加载