Hacker Newsnew | past | comments | ask | show | jobs | submit | damoncloudflare's commentslogin

We do not cache the entire site with Always Online. The Always Online feature will display a limited cache of the site's content.


Also:

Clarifying that forcing direct does not mean a null route. Forcing direct = going direct to the site's server (we still resolve the DNS).


Hi,

We only force a site direct if the attack is too large & starts to impact other customers as well. If the attack doesn't impact other customers, then we won't force the site direct (we generally only force a few sites direct per week & these are monster attacks).


How was it that the Lulzsec attacks were not as large? What qualifies a sufficient size attack?


CloudFlare does have a feature to minimize some resources called Auto Minify. http://blog.cloudflare.com/an-all-new-and-improved-autominif...


We actually have the backend all built for this. It is just a matter of doing just a little bit more testing before releasing it into the wild. We've used a handful of beta testers to help us identify potential problems.


We actually talk about the announcement today on our blog here: http://bit.ly/nLkE9Y

We also do far more than just act as a CDN.


We will have CNAME pointing available in the very near future.


This issue is being fixed & should be done by tomorrow or so.

It isn't affecting ALL domains. It appears to be an issue with CNAMEs/APEX only.


Similar to many other companies operating on the internet these days, CloudFlare operates on a freemium model (free vs paid products). We also have some other opportunities to make money with other product integrations & will be launching enterprise products in the future.

We're not going anywhere:)


Can you explain your technology more directly? Your web site doesn't have a lot of technical detail, perhaps because people who would understand the technical details aren't your target audience.

For the HN crowd, understanding what pieces are in play would help a great deal. I figure it's probably a nice cache + CDN service?

I'll admit that I don't get your security claims -- it seems like entirely the wrong layer to deal with security issues.


Sure. At a high level: We run out of 12 data centers scattered around the world (Singapore, Hong Kong, Tokyo, Los Angeles, San Jose, Dallas, Chicago, New York, Ashburn, Paris, Amsterdam, and Frankfurt). We use Anycast (listen to the same IP out of multiple locations) as well as GeoIP DNS in order to route a request from a visitor to the website to the nearest data center. In each data center we run a reverse proxy that does full inspection (down to Layer 7) of each request looking for threat signatures. The data centers also run caching where we automatically detect static objects that make up a website and store them to be closer to the visitor. Requests for objects that are not cached are passed back to the origin server. The origin server's response passes back through CloudFlare's proxy, which can scan, analyze, and rewrite the content without blocking delivery.


This is so helpful and interesting! I've been intrigued by yall since I saw your sign in the old SocialMedia building in PA, but figured you were just scareware because the descriptions on your web site are so fluffy.

It would be awesome if this explanation was on there under "technical details" or something.


"They use VigLink to add affiliate tags to the external links of the sites that use them."

This is actually an optional service (Outbound Links) that can be turned on or off (opt-in by default). No affiliate links are added without turning the feature on.


And by enabling this feature it generates affiliate revenue for the user, not for CloudFlare. (Correct me if I'm wrong, Damon.)


Yes. If you enable Viglink through CloudFlare Apps then the webmaster is paid Viglink's standard a commission for any affiliated links.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: