Among European Companies That Use a CDN, Nearly 9 in 10 Use Cloudflare
Posted by adulion 5 hours ago
Comments
Comment by jillesvangurp 3 hours ago
We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year. Even if all you are doing is routing domains to some bucket with a website.
We migrated most of our gcloud stuff to Hetzner beginning of the year. That left a load balancer and a few static websites hosted in Google buckets. I migrated all of that to Cloudflare just a few months ago.
I still have a few buckets in gcloud proxied via a vm in hetzner with a proxied domain in Cloudflare. Not the most elegant route but it works. I might optimize some of that later. At this point, we pay for some Google buckets and not much else in gcloud.
Honestly, Google and AWS need to start paying attention to Cloudflare more. Their complexity is chasing people towards Cloudflare. The hoops you have to jump through with both of them to host a simple website with their CDNs is embarrassing. I've gone through the process with both of them. Although my experience with Route53 is a bit stale at this point. On Cloudflare, getting an new website up and running with a freshly registered domain takes only a few minutes.
Comment by snorremd 1 hour ago
Now stuff like Cloudflare D1, the distributed SQLite based database, have its limitations. Writes are directed to a specific datacenter/region behind the scenes, so some regions might get slower writes. But this is basically something that happens behind the scenes and just works. You need to think about where your primary base of customers live when you create the database, after that you don't think about regions. R2 (S3 compatible storage) just works globally as well.
A lot of what Cloudflare offers now feels like magic in a good way. I realize they don't have everything AWS, Google Cloud and Azure have. But they have enough that you can build serious systems on top of their infrastructure. They are no longer just a CDN/proxy provider. And their offering is seriously cheap.
Comment by pocksuppet 3 hours ago
Comment by esperent 3 hours ago
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
Comment by icantevenhold 18 minutes ago
Comment by 9864325789976 14 minutes ago
Comment by ExoticPearTree 1 hour ago
I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.
Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.
I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
Comment by petcat 1 hour ago
Comment by p-e-w 1 hour ago
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
Comment by belorn 8 minutes ago
I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.
Comment by jgtrosh 1 hour ago
https://en.wikipedia.org/wiki/Room_641A
Public information shows that the NSA has been active intercepting as much data as possible.
It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
Comment by jgtrosh 1 hour ago
Comment by otabdeveloper4 50 minutes ago
"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)
Comment by Forgeties79 1 hour ago
Comment by bulbar 1 hour ago
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
Comment by aranelsurion 2 hours ago
I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
Comment by thorbutt 3 hours ago
Comment by cassianoleal 3 hours ago
Comment by lukan 3 hours ago
Literally? What is the reference here?
Comment by a2ff6eeb0 3 hours ago
Comment by lukan 3 hours ago
Comment by a2ff6eeb0 3 hours ago
Comment by lxgr 49 minutes ago
It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.
Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
Comment by kakacik 3 hours ago
Or clouds in general, its all wishful thinking and pinky promises.
Comment by spacebanana7 1 hour ago
Comment by tg180 1 hour ago
Comment by mopsi 1 hour ago
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
Comment by CommanderData 3 hours ago
Comment by bcye 3 hours ago
Comment by CommanderData 3 hours ago
Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
Comment by samlinnfer 3 hours ago
Comment by stef25 43 minutes ago
Comment by Betelbuddy 1 hour ago
"Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752
Comment by matthewdgreen 1 hour ago
Comment by ghoul2 1 hour ago
I am guessing the real reason (and at this point I am discounting incompetence - this has been true for years, so they are aware). You switch to the pro plan for the zone and everything now routes within india, 100s of milliseconds of latency saved.
Its even worse for workers and workers AI and embedding search. I found multiple seconds of latency, all vanishing the moment the zone is on pro plan (It seems R2, workers, workers AI - none of them are deployed in an India POP - unconfirmed, of course, cause there is no way to actually communicate with cloudflare).
Now 25$/month isn't much - though it does change calculations compared to "FREE!!" - but I would have liked to know this going in, instead of discovering this after having made the commitment. Seems like a deliberate dark pattern, to force people into the pro plan.
Shame, really - I love the CF stack(workers and DO are just so fantastic to build on), but these shenanigans, plus the utter refusal to provide ANY level of support, keep souring me on them.
Comment by piperswe 1 hour ago
Comment by jerkstate 49 minutes ago
Comment by dizhn 3 hours ago
You don't need to register your domain with them. Only make their DNS servers your domain name servers.
Comment by noir_lord 4 hours ago
Not really unexpected, US domination of "tech" is near total, even if the sustained political will exists (and I'm not sure it will for long enough) unwinding that is the expensive work of years/decades not months.
Doing it in a way that won't invite retaliation from the US Gov (which seems more and more like the PR arm of US big tech) is even trickier.
Personally I think we absolutely should, I just don't think we will.
Barring them doing something so egregiously awful we don't have the choice, Governments can move fast when they want to but efficient government scares the shit out of me because it rarely happens outside of a genuinely serious crisis.
Comment by zkmon 3 hours ago
Not quite when considering China having the tech freedom they wanted. Also switching internet services is far easier than switching physical supply chains. The only thing that might be hard to switch is the part of the interent backbone infra that is controlled by USA.
Comment by shevy-java 3 hours ago
Comment by aivisol 2 hours ago
Comment by pjc50 9 minutes ago
(When is the first war going to be started purely downstream of social media beef? Was it arguably the Iran war?)
Comment by nonethewiser 2 hours ago
Comment by Roark66 1 hour ago
Consider these points: - US withdrawing it's "Intel support" just as Russia started a major offensive last year. - US starting the war on Iran clearly to help their pal Putin on oil prices, now they try to use Ukraine as a scapegoat for "attacking Russian oil export infrastructure" - Another "side effect" of war in Iran. No more patriots or modern weapons for any country that ordered them from the USA in recent years and was expecting deliveries just about now. - US committing actual act of war (threatening force has been considered an act of war for centuries) against the EU by talking about invading Greenland (most certainly if Russia attacked Estonia US would try their luck with Greenland on same day, does it remind you anything from history?) - US essentially waging an economic war on the rest of NATO. - US companies with full support of the state trying to deny computing hardware to the rest of the world in hope they manage to monopolise compute capability using AI as cover (yes China is a real ally in this).
And much more.
Yes, the US is a much higher threat to the EU than China now.
Comment by foldr 1 hour ago
https://en.wikipedia.org/wiki/List_of_military_aid_to_Ukrain...
Comment by atakan_gurkan 2 hours ago
Comment by hdgvhicv 13 minutes ago
Comment by petcat 1 hour ago
Ukraine is never going to retake the territory they've lost without European soldiers on the ground. Macron famously said that he would have to send troops to Odesa and yet 3 years later there are still no French troops in Ukraine. Meanwhile Putin has captured even more land and is now actively bombarding Kyiv.
It is painfully obvious that Europe lacks the political will to do any kind of substantial intervention. The war is at a complete standstill and it will last for another horrible decade if no concessions are made.
It's the unfortunate reality of the situation.
Comment by pjc50 13 minutes ago
Ukraine rightly has no interest in ceding land to achieve a temporary ceasefire to allow Russia to re-arm and then attack again.
Meanwhile it is also important that we don't have two nuclear armed states (France and Russsia) officially at war.
Comment by foldr 1 hour ago
There is a slight hope that the current Russian regime will collapse before then and be replaced by one that doesn't want to continue the war. (Though, that said, it could equally well be replaced by a regime that's even more ultranationalist than the current one.)
While Europe certainly does lack the political will to make a substantial intervention, it's not just a question of political will. There is the small matter of not starting the third world war to consider.
Comment by Vaslo 29 minutes ago
Comment by pjc50 12 minutes ago
Comment by thesmtsolver2 3 hours ago
They all consider China to be the aggressor because they are. E.g., Tibet or India.
Comment by hvb2 2 hours ago
Comment by JumpCrisscross 2 hours ago
I think it’s fair to say the U.S. and Russia are Europe’s principal geopolitical adversaries, today, while for anyone in Asia or Oceania it’s China. (Africa and South America are being weirdly carved up—it’s not particularly clear who is trying to colonize versus trade with them.)
Comment by iso1631 1 hour ago
Very similar pressures in reality.
Comment by kakacik 3 hours ago
China? It wants to sell its cars here, and thats about it. Incomparable.
Comment by broken-kebab 1 hour ago
Comment by kakacik 39 minutes ago
Ask/look around in places that dared to stood apart or directly up to whatever US wanted, the story is everything but nice and bloodless. Ask those that fought for them, and were completely abandoned to be then murdered one by one (vietnam, afghanistan).
Rest of your post is just wishful thinking, US is in semi-lawless state now with new oligarchy ruling the country based on emotions and whims and hardly any laws, so prior experiences do not guarantee any form of future. I personally would literally, objectively, trust Xi more than trump if I had to choose (which I don't, nobody does), any day any night.
Comment by DarmokTanagra 2 hours ago
Comment by zerozerotwo 2 hours ago
Comment by expedition32 8 minutes ago
Comment by carlosjobim 2 hours ago
But I've learnt that iPhones and social media is American imperialism, but thousands of troops in dozens of military bases on European soil is not, somehow.
Comment by zerreh50 1 hour ago
Mostly from the US serving politicians scared of losing power.
Comment by watwut 2 hours ago
Presence of allies is not colonialism. Threat to annex Greenland is. Threat to annex Canada is. Keeping pet dictator in Venezuela and taking their oil is.
On the other hand, when Germans, France and other European soldiers came to Greenland to defend against an American threat, it was not colonialism. It was being allies.
> and withdrawing troops from European soil, the response is outrage.
The response to withdrawing troops from European soil was mockery and frustration from army that is loosing valuable bases. Either way, it is not an anti-colonial thing.
> When Trump talks about doing the anti colonial thing
Trump is modern colonialist. He is not talking about doing "the anti colonial thing" ever, instead he is bragging about making America colonial.
------
Trying to frame Trump as somehow anti-colonial is really new level of post-fact dishonesty. It does not work, because his appeal is based on dominance, violence and willingness to steal.
Comment by carlosjobim 1 hour ago
To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
Comment by js8 28 minutes ago
The Americans are there as a front of US empire (IIRC Rammstein is being used for Iran war).
Comment by watwut 1 hour ago
America was a trusted, respected and liked allied nation. It was not a threat. Then Trump supported by people like you turned into a threat to Canada (another former ally), Greenland, democracy and freedom. So, America is not respected or liked, except by neo-nazi it supports. There is no double think involved here.
> To me the question is crystal clear: No country should want to have foreign troops permanently stationed on their soil, no matter how good friends they are.
It is irrelevant what you think about what other countries should or should not want. The question is what is colonialism.
Comment by carlosjobim 1 hour ago
This is a sign that you cannot think clearly about these matters, unfortunately. You are enraged from mass media pressure, and that's why you have to make up things about me which you wouldn't know.
> It is irrelevant what you think about what other countries should or should not want. The question is what is colonialism.
Colonialism begins (and ends) by having your troops permanently stationed on foreign soil.
> Then Trump supported by people like you turned into a threat to Canada (another former ally), Greenland, democracy and freedom. So, America is not respected or liked, except by neo-nazi it supports.
Then if that's how you feel, then maybe you'd want their troops out of your country? That's what a rational person would want.
The double think is off the rails, I would say!
Why do you want to have the military of somebody you yourself call "a threat", "not respected", "neo-nazi" in your land?
Comment by Neil44 57 minutes ago
Comment by bryanrasmussen 4 hours ago
Comment by k__ 4 hours ago
Comment by jonnybgood 3 hours ago
You mean the US government working towards the interests of its people and economy? Which government wouldn't? It's kinda what we want it to do.
Comment by plufz 3 hours ago
Comment by dofm 1 hour ago
Comment by thesmtsolver2 3 hours ago
Comment by simondotau 2 hours ago
I’m Australian, and if I was worried about the practical legal risk of being tracked online by a government, it’s mostly concern about my own. A foreign friendly government is mid tier: it’s unlikely that five eyes is an intel firehouse, so it’s unlikely for your petty domestic matter to be communicated. A foreign hostile government is probably safer if you’re committing domestic crimes.
Comment by lukan 3 hours ago
Comment by ExoticPearTree 2 hours ago
should read as "everyone the US likes", not everyone everyone.
Comment by JumpCrisscross 2 hours ago
France has global geopolitical projects, as does China in South America, Central Asia and Africa. Both export arms into conflicts and conduct global intelligence operations.
Comment by lukan 2 hours ago
Comment by JumpCrisscross 1 hour ago
This is currently a legitimately open question.
America acts like a global hegemon. My point is simply that France and China act similarly, too—they both project power across oceans and continents. (To what end is, as with America’s power projection, a good question.)
Comment by quadrifoliate 1 hour ago
It's not the so-called retaliation of the US government that leads to European inefficiencies like paying notaries thousands of euros to read out a contract to you (several discussions going around about this in Germany recently).
This is ultimately just a boogeyman. European governments love to blame someone else for their inefficient and bureaucratic processes that stifle innovation and are slowly becoming the laughing stock of the tech world.
If they really want a thriving tech industry, EU should:
- Normalize laws and regulations relating to commerce and online activities throughout the EU. Get rid of the notary crap. While you are at it, get rid of the impressum (why the fuck should I need to post my home address on my website?).
- Ensure that these normalized regulations are available in the tens of languages across the EU
- Invest heavily in telecom and data center infrastructure and software on a European-wide basis. The current AI bubble will see a downturn but data centers and connectivity infrastructure can be reused for EU-based cloud services.
- Invite the UK back in once they are an actual economic powerhouse that can speak with one voice.
Of course none of this will ever get done because EU bureaucrats would rather be in a perpetual hand-wringing mode while blaming the Big Bad US Boogeyman for all their problems.
Comment by bell-cot 57 minutes ago
Comment by embedding-shape 4 hours ago
I'm thinking the opposite might be the way to go here.
We already know that "retaliation" comes from the US government regardless if you did something or not, so most of us (Europeans) have stopped pretending there is a way of preventing it.
Even more, if we piss off Trump enough, he might be dumb enough to try to block European access to CloudFlare, or something similar and maybe even dumber.
So with this, maybe the goal should actually be to try to piss off Trump and the US administration as much as possible, in order for them to start reacting and cutting off some stuff, so we (again, Europeans) basically gets forced off CloudFlare et al.
Lots of companies already finished moving away from storing their primary data in the US, lots of companies is in process of doing so (albeit some look like they'll take forever) but also lots of companies still aren't prepared for the future, would be nice if US government could make the decision a bit easier for them to make :)
Comment by microtonal 4 hours ago
So for the most part, the EU has to work slowly and under the radar.
That said, my worry is that we'll be back to business as usual if the midterms look favorable. Even the urgency present during January's Greenland threats was gone after a few months. I fear that we don't have the long-term focus and planning to make sovereignty really happen. But I'd love to be surprised.
Comment by quadrifoliate 1 hour ago
How convenient. If it wasn't for the US, the EU would work really fast and in the open! That is totally believable.
Comment by eckesicle 3 hours ago
https://www.reddit.com/r/sweden/comments/1w8p0z4/comment/p84...
Comment by embedding-shape 3 hours ago
Comment by pocksuppet 3 hours ago
Question:
> Hello, Sweden (and Europe) is facing three almost existential risks over the coming term of office that we have never really had to take a position on to the same extent before. The climate. A new UN report from last week has shown that El Niño will probably contribute to between 3 and 4 degrees of warming in addition to last year's heat wave. I live abroad and we had 44 degrees warm for a couple of days this summer (2025). It was also over 30 degrees in Norrbotten for over 3 weeks. Unbearable. How do you prioritize this against the many other budget items? How should we now prepare for what will inevitably lead to an IPCC 3-4 degree scenario?
> AI. AI development is just going faster and faster. At my workplace, we have already replaced many employees with AI-driven processes. We buy all our computing capacity from the US and China. There are no European alternatives and it is not possible to buy Swedish. What do you want to do to, at the European level, prevent us from ending up in the AI lap of the US and China in 5 years? Where should we buy chips from when all manufacturing takes place in Taiwan, Korea, China and the US? We risk a situation where Swedish office workers are rarely replaced with US AI tokens. Surely this must be an initiative at EU level?
> American foreign policy. Trump's second term has been tumultuous, to say the least. We were probably as close to the brink of war in Europe (Greenland) as there is in living memory. Trade agreements are being torn up, sticks are being put in the works for Gripen agreements, etc. Even when he is gone, the illusion of America as a close ally has probably finally been broken in the eyes of many Swedes, myself included. What do you want to do to reduce Sweden's and the EU's dependence on foreign superpowers?
Answer:
> There is a lot in this. A completely unique geopolitical time - both militarily and economically - presents a small country like Sweden with important choices. NATO was one of them. We are now cooperating with all our neighbors around the Baltic Sea, for example our own defense build-up, another example, the largest since the 50s. And all the new free trade agreements when the United States messes up world trade.
> The climate is also one of these, and what the EU is now doing together is the single most important thing, in parallel with Swedish fossil-free energy. We can make ourselves completely national energy independent with the new Swedish nuclear power programme. German energy policy, I think, proves why this is needed, in addition to the wars in the Middle East.
> EU: no single EU issue is more important than our support for Ukraine and increasing European competitiveness in relation to both the US and China. And it starts with the internal market - where 70 percent of all Swedish goods exports end up. If it can be as good for services including digital services, it would be good for both the EU and Sweden. But I am genuinely concerned that Europe is lagging behind.
> last China: we will have an intense autumn regarding a common European response against China to get "level playing fields" when it comes to trade. Today's situation is not sustainable. even extremely free trade-friendly countries like Sweden see this. we should not have protectionism but the same opportunities for the EU in China as for China in the EU. We are not there now.
Comment by philipallstar 4 hours ago
Comment by embedding-shape 4 hours ago
There are troops deployed on Greenland right now ready to defend the island. The threat is not gone from the minds of the people there or in the rest of Europe just because you stopped reading about it on CNN or whatever.
Edit: I got curious if this part is even possible:
> leaving NATO completely
Apparently not. Congress enacted a specific prohibition in 2023, now codified at 22 U.S.C. §1928f. It says that the president may not "suspend, terminate, denounce, or withdraw" the US from the North Atlantic Treaty unless either two-thirds of senators present consent, or Congress passes an Act authorizing it. It also prohibits federal funds from being used to carry out an unauthorized withdrawal.
Seems some parts of the US has indeed managed to setup defenses against such idiocracy.
Comment by pocksuppet 3 hours ago
Comment by embedding-shape 3 hours ago
Why not take even two seconds to check if what you're guessing about, might actually be correct or not? Or the goal is just FUD here?
> And yet, this hasn't deterred European businesses from using Cloudflare and blocking their own customers.
Maybe because the impact of these blocks aren't as large as you allude to? Things change, these blocklists get updated. What was blocked 6 months ago no longer is, when these anti-piracy blocks happen.
Don't get me wrong, I don't agree with these blocks at all, and AFAIK, they break both national laws and wider "rights", but lets not pretend it's bigger than what it is in reality.
Comment by shevy-java 3 hours ago
I think many millions in the EU want to. The problem is that the current EU "politicians" are just US lobbyists. You can see it when Leyen signed the surrender treaty with her Overlord-buddy Trump. You can not fix the EU with such lobbiysts in place - and it's not just Leyen alone. Look at Merz - the guy basically is a tool used by US companies. He is not the brightest but very loyal to the USA. More than to the people who voted for him (and now curse themselves for having made such a big mistake).
Comment by expedition32 4 hours ago
Comment by throwaway613746 2 minutes ago
Comment by cbg0 4 hours ago
Hey Claude, can you move the ciphercue blog to Cloudflare so it can deal with traffic from HN?
On a more serious note, Cloudflare comes packed with features even on its free plan which makes it useful for any size website. For a real business it's one of the cheapest options for DDoS protection on the market. Some years ago you would have paid a fortune for Akamai or Level3 to help keep you online and now you can get by on a $200 a month plan for a small business.
Comment by embedding-shape 4 hours ago
You're delusional if you think that $200/month is appropriate for a small business to pay to host a website... Most websites don't need a CDN nor DDOS protection, you need to configure your webserver to rate limit stuff that suck bandwidth/CPU from you, but besides that, you've basically fallen for the marketing from Cloudflare that everything requires CDN and that somehow $200/month is a small amount of money for a small business.
Comment by cbg0 4 hours ago
Comment by cyphar 3 hours ago
* of course it's not unlimited unlimited but I've not heard of anyone being cut off.
Comment by viraptor 4 hours ago
This works for cases where the traffic takes too long to process. Once you get 3gbit traffic on your 1gbit link, you can't do anything yourself - the only thing that can save you is a bigger pipe.
Comment by embedding-shape 3 hours ago
Realistically, out of the DDoS we typically see, how many are in fact "they had bigger pipes than you"? I've come across that once in my ~3 decade career maintaining infrastructure for websites, some quite popular. Most of the time the attacks are relatively low-effort and easy to stave away, there been one time when the attacker seemed to have basically endless amount of resources, and yes, that time we ended up with emergency calls to Akamai.
But again, those sort of attacks seem to happen seldom, and I don't think people should default to trying to prevent them. Deal with that once you get there, because most websites and services never get there in the first.
Comment by viraptor 3 hours ago
> and I don't think people should default to trying to prevent them.
It's the usual instance calculation - how much will you lose if you're down for a day vs how much would you pay per month. Some people will not care, some will happily pay tens of thousands.
Then there's business specific stuff. It would extremely hurt a florist to go offline for a week before Valentine's Day. (If they take online reservations)
Comment by cbg0 3 hours ago
https://www.bdc.ca/en/articles-tools/blog/cyberattacks-small...
Comment by embedding-shape 3 hours ago
The data from the graph: Phishing 61%; Malware 27%; Network intrusion 12%; Ransomware 12%; Data breach 7%; DDoS 5%; No cybersecurity incident 27%.
Comment by cbg0 3 hours ago
Comment by embedding-shape 3 hours ago
Second most answered option was "No cybersecurity incident" shared with "Malware". The least experienced type of attack was DDoS, which is exactly what I claimed too, DDoS attacks are way less common than the internet at large seems to believe.
> Your personal experience of DDoS being super rare doesn't seem to match the real world.
What I claimed was that DDoS attacks where the attackers pipes are larger/can send more traffic than your pipe can handle, is extremely rare. The typical script kiddie DDoS which is more easily managed, is much more common, in that I agree.
Comment by pocksuppet 3 hours ago
Comment by Hikikomori 2 hours ago
Comment by theideaofcoffee 2 hours ago
> But again, those sort of attacks seem to happen seldom
[citation needed] and direct experience suggests otherwise. The wider internet is a cesspool and you never know the inanity that will spur a bored, annoyed script kiddie with some booter credits to take it out on the local cake shop, like another commenter put it.
Comment by bryanrasmussen 3 hours ago
Comment by cbg0 3 hours ago
If you're building a tiktok competitor, that's definitely going to require an enterprise plan, even if you have only 4 employees.
Comment by bell-cot 1 hour ago
Yes, plus a strong bias toward IT-heavy businesses. Vs. if my company is doing commercial landscaping, or machining gears for automobile transmissions? Several hundred employees still gives me no reason to pay much for web hosting.
Comment by mschuster91 2 hours ago
A CDN not, and certainly not a global one.
But unfortunately, you absolutely need DDoS protection, especially as a business. Too many shady actors and skiddies pulling off extortion/protection racket scams - a complete and utter lack of telco regulations, AI, tons of unsecured IoT devices and shitcoins truly have made for a terrible mixture.
Sure, a 50€ a month server at Hetzner, OVH or whatever is more than enough to host a website. If you're not running some NodeJS garbage, a 5€ VPS can be enough. But at the first sign of you being targeted by a troublemaker, your hoster will cut you off just to protect their other customers.
Comment by dwroberts 4 hours ago
Comment by microtonal 4 hours ago
I would even be happy to pay for it, but for individuals and small business the 'black swan' events that could bankrupt them will keep them from switching to a pay-as-you-go service.
Comment by cbg0 4 hours ago
Comment by glimshe 4 hours ago
Comment by 8by3 1 hour ago
They have shareholders, who wouldn't allow them to provide value for free, its just not obvious to you how they are extracting that value. Maybe its by capturing a huge % of unencrypted https traffic because if you let them do your certs it means they can read all your real traffic.
Comment by smw 26 minutes ago
Comment by boesboes 26 minutes ago
Comment by thih9 1 hour ago
Edit: I found https://european-alternatives.eu/alternative-to/cloudflare , which lists among others: https://bunny.net/ , https://www.keycdn.com/ , https://blazingcdn.com/ , https://www.myrasecurity.com/en/product-content-delivery-net..., https://www.leaseweb.com/cdn . If anyone has any personal experiences with any of these please share.
Comment by Havoc 4 hours ago
Comment by jarco 4 hours ago
Comment by viraptor 3 hours ago
You assigned a new https certificate around that time, didn't you? Those are public now and will cause an immediate scan.
Comment by bcye 3 hours ago
Comment by AndroTux 3 hours ago
Comment by boesboes 22 minutes ago
Service has been great, prices like 10% of cloudflare too once you get the real pricing :P
Comment by kosinus 3 hours ago
Agree discord sucks.
Comment by frevib 3 hours ago
We don’t miss Cloudflare one bit.
Comment by tao_oat 4 hours ago
Comment by s_dev 3 hours ago
Comment by sparkling 3 hours ago
Comment by s_dev 1 hour ago
Comment by boesboes 21 minutes ago
Comment by jarym 4 hours ago
Comment by bakugo 2 hours ago
Comment by CommanderData 4 hours ago
I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.
Comment by ramon156 4 hours ago
Comment by CommanderData 4 hours ago
10+ BT trackers using CF likely free tier. Low-end EACH 300-500 MILLION HTTP requests/24hr uncached, some exceed a billion reqs/day (using statistics from other open trackers) 20TB-40TB daily, ~1-3 Gbps sustained.
That's a crap load of transfer and compute to process those tiny network connections. As someone that's run a Tunnel on a normal site in the millions, the daemon uses a sizeable amount of CPU and I can't see any reason why it's not the same on the other end.
Whatever source CF has going on, kudos to them and their engineering team.
Comment by viraptor 2 hours ago
Comment by pjmlp 4 hours ago
It will take similar amount of years to go back into the cold war heterogeneous computing landscape of the 60, early 90s.
This assuming there would be an willingness across all European countries to actually push for that, and not jump out when it gets too hard and search for compromises instead.
This is why most sovereignty initiatives focus mostly on SaaS products and hardly on actual computing devices.
Comment by sajithdilshan 3 hours ago
Only time will tell how far this sovereign movement would go. Maybe when the US would have a president/government from the Democratic Party someday in the future. EU would cozy up again to US and go back to how things were. There’s no permanent enemies or allies when it comes to politics and at the end of the day it all revolves around money
Comment by mrits 2 hours ago
Comment by pjmlp 1 hour ago
In which country do fast food workers get higher salaries than office workers, unless we are talking about tourism industry outside Europe, with said workers getting tips in Euros and Dollars instead of local currency?
Comment by reincoder 1 hour ago
Comment by maxcoding 4 hours ago
Comment by dotcoma 4 hours ago
Comment by unglaublich 4 hours ago
Comment by ramon156 4 hours ago
Comment by roshanabdullah1 22 minutes ago
It provides you with all the tools necessary to scale your app.
Comment by piskov 20 minutes ago
It will not get down with half of the internet the next time cloudflare has issues.
Comment by stef25 42 minutes ago
Comment by drchaim 26 minutes ago
Comment by helsinkiandrew 1 hour ago
Doesn't this miss websites that serve their own site html but serve (static) assets from a CDN.
This seems to be a common pattern with Wordpress sites, presumably because it makes cache configuration simpler
Comment by arjie 1 hour ago
Comment by pessimizer 35 seconds ago
Comment by nottorp 1 hour ago
Comment by ericpauley 4 minutes ago
Comment by bborud 1 hour ago
Even in the previous political climate this should, objectively, be deemed a problem. Having 90% of all eggs in one basket is neither good, nor does it constitute functioning market.
I'm not sure what the Cloudflare market share is in the US, but if it is the same as in Europe, this is a problem for US companies as well.
Comment by parasxos 1 hour ago
Comment by em500 4 hours ago
9 out of 10 corporate decisions are for blame avoidance / ass covering.
Comment by chpatrick 3 hours ago
Comment by viraptor 3 hours ago
Comment by viraptor 35 minutes ago
Comment by edelbitter 3 hours ago
Comment by Danoch 3 hours ago
Comment by Zaheer 1 hour ago
Comment by bildung 4 hours ago
I can hardly imagine there being so many more big companies in the UK, so it's either cargo-culting webscale deployment in the UK, or usage of more conservative stacks in France and Germany?
Comment by embedding-shape 4 hours ago
Maybe our countries are just small enough to not be overwhelmed by traffic? Most websites I've built and launched for Spanish national companies, that only have other Spaniards as users and customers, haven't needed any CDN at all, because you don't suddenly get 1K req/s. Meanwhile, launch a global website in English, that even get the slightest amount of popular, and all of a sudden you reach 1K req/s very quickly. Add on top that people usually don't even give two cents about performance, and adding CDN on top as a saving grace seems like an easy tradeoff.
So, why add a CDN when you don't need it? :) Probably 80% of everything I've ever deployed never needed a CDN in the first place, but I also save it as a thing in my toolbox to be used sparingly, rather than a default thing I slap on top of everything.
Comment by ivlad 4 hours ago
If all your users are in Spain and you don’t care how fast your site loads for a techbro in California, you indeed don’t need CDN.
Comment by JimBlackwood 2 hours ago
For both France and the UK, less than 15% of sites are behind a CDN. For both, around 95% use Cloudflare.
So in terms of percentages, there’s not much of a difference.
Comment by wiether 4 hours ago
I wanted to check if the 5 customers for which I already did a change on their Cloudflare settings today where on the list, but can't do.
Comment by pajamasam 4 hours ago
Also, funny that their page with for "Companies running Cloudflare" says there are only "887 European organisations using Cloudflare."
Comment by jamesnorden 2 hours ago
Comment by bell-cot 2 hours ago
Or, they discuss their free stuff at length here - https://www.sec.gov/Archives/edgar/data/1477333/000147733326....
(That is Cloudflare's 10-K for calendar 2025 - scrutinized by serious investors, and with heavy penalties for lying.)
Comment by christkv 38 minutes ago
Comment by vaylian 4 hours ago
Comment by viraptor 4 hours ago
- Your public traffic costs you so much to repeatedly process that it's cheaper to let some service cache the common responses instead. (Where the cache size is larger than anything you'd want to support yourself. For example, if it's <1G and survives your service restarts, you may want to do it yourself)
- Your customers on the other side of the world start complaining that the resources take ages to load.
- Someone floods you with enough traffic that you can't respond to real customers traffic anymore. You get a ransom email to pay them to stop. But there are enough groups doing that that paying is useless because someone else will try again in a few days. If you're providing a service where people pay you to use the website, you're losing money until you solve this problem.
Comment by _joel 4 hours ago
Comment by pluc 4 hours ago
Comment by vaylian 4 hours ago
Comment by unglaublich 4 hours ago
Not only would transfer be slow, they would also be much more pressing on the network as the request would occupy huge stretches and many interconnects and switches.
Furthermore, it hardens the website against DDoS and adds robustness for regional failures.
Comment by ivlad 3 hours ago
So, while average request may have to travel quarter (not half) of the Internet globe, median request from the set of requests that matter has much lower latency.
Barcelona to Stockholm is about 65ms, ~35ms to Amsterdam, ~43ms to Frankfurt.
HTTP/3 is ubiquitous, you don’t get TCP handshake penalty anymore in major browsers.
Comment by esseph 4 hours ago
Lol
Comment by embedding-shape 4 hours ago
If you have a very inefficient backend (maybe legacy project?), you have massive amount of traffic (say 100K req/s or above) or you really must have sub-500ms latency absolutely everywhere in the world, then it might make sense to slap a CDN (or similar) on top of that.
In pretty much any case outside of that, it makes no sense to waste the time, money or effort on CDNs. But, all the CDN companies seemingly have convinced half the internet that you absolutely must use a CDN, otherwise you'll get hacked/broke/killed/sent to the moon, and they've been successful with this campaign too seemingly.
Comment by bdauvergne 3 hours ago
Comment by embedding-shape 3 hours ago
If your server is in Europe, and you have Australian users, there is a physical limit how low the response times can go, serving bits over that distance, so only way you can make it go below that limit, is by moving where you serve the data from closer to the user.
Lots of websites have horrible performance for whatever reasons, and lots of freelancers/consultants basically default to throwing a CDN on top of those when they get approached by businesses to fix the slow website browsing, as they're not the ones who have to pay the monthly subscription, and the less work they have to do, the better $ per hour spent for them.
I agree that it's a shit solution and there is much better sustainable ways of solving these things.
Comment by esseph 4 hours ago
If anything else, the AI machine wants near constant streams of new data, even if it already checked with you 30ms ago.
A CDN helps immensely.
Also keeps you from getting DDoS'd if you did something like run it off your home connection.
Comment by embedding-shape 4 hours ago
CDN is something you do once you run out of options, not something you should reach for immediately, it makes no sense in most cases of just hosting a website.
Comment by viraptor 2 hours ago
And for large services implementing a CDN properly takes days/weeks of preparation. Once you're down it's way too late.
Comment by embedding-shape 2 hours ago
If your problem is AI crawlers, then simple rate limits help, I've helped countless of businesses with this already. For the ones that it isn't enough, you continue adding more roadblocks. There is no "one size fits all here" and that you seemingly is under that belief, leads less credence to what you're saying, not more.
Comment by amelius 4 hours ago
Comment by AndroTux 2 hours ago
Comment by pyvpx 3 hours ago
Going from one CDN to another can be infuriating even at a surprisingly small scale. Mostly (imo) from caching semantics and counting.
Comment by amelius 3 hours ago
Comment by kypro 3 hours ago
For it to be a commodity there would be no good reason to pick Cloudflare over any alternative and this absolutely isn't the case.
Comment by shevy-java 3 hours ago
Comment by ObscureScience 3 hours ago
Comment by simondotau 2 hours ago
Comment by Tepix 2 hours ago
If you use their unique features, you're locking yourself in. Is it worth it?
Comment by postepowanieadm 1 hour ago
Comment by raverbashing 2 hours ago
Comment by schnebbau 4 hours ago
Also in this list of GOATed companies: Tailscale, Ubiquiti.
Comment by VBprogrammer 3 hours ago
Comment by viraptor 3 hours ago
Comment by cassianoleal 2 hours ago
Comment by dakolli 4 hours ago
"In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year."
--Matthew Prince's Wikipedia page.
Dont for a second think cloudflare's generous free tier offerings are out of the goodness of their heart. They're a giant fkin MiTM project for the US governemnt. And of course, cloudflare isn't the only one.
Comment by hn45e7pbij 23 minutes ago
Comment by tunahanfaruksav 4 hours ago
Comment by miu33 1 hour ago
Comment by iamislida 3 hours ago
Comment by herbertyang 1 hour ago
Comment by dansmet 3 hours ago
Comment by chrocni380 4 hours ago
Comment by Steve16384 4 hours ago
Comment by ilikerashers 4 hours ago
The US deserves it's success.
Comment by Yash16 3 hours ago
Comment by tolusky 3 hours ago
Comment by cassianoleal 2 hours ago
Comment by throw93947309 3 hours ago
Comment by AndroTux 2 hours ago
Comment by bdauvergne 3 hours ago
Comment by tonyhart7 3 hours ago
what stopping europe from using their home ground solution ??? nothing
this is just a skill issue take
Comment by CrimsonRain 2 hours ago
This article is as useful as writing sky is blue. Nothing stopped an european cdn to become cliudflare but euro bureaucracy and europoor risk averse mentally.
Comment by bean469 1 hour ago
Subtle
Comment by DuncanCoffee 2 hours ago