I think I’ve seen that asked before, but can’t find the post now. I also know quite some instances of Fedi use Cloudflare.

  • @Thorry84@feddit.nl
    link
    fedilink
    94 days ago

    I assume it’s to handle DDOS attacks? If somebody has beef with your instance, it would be very easy to bring it down for an extended period of time without some kind of protection in front.

    It’s kind of like a fire extinguisher, everything is fine without it, right up to the point it isn’t.

    • hendrik
      link
      fedilink
      English
      0
      edit-2
      4 days ago

      Supposedly, yes. Though I only ever read about attacking with uploaded images, maybe lots if requests which are crafted to result in expensive database queries… I’m not sure if it’s ever something Cloudflare could protect from? I mean all their advertising about security, mitigation and prevention sure goes down like oil. But I sometimes wonder if it’s just 100% snake-oil for use-cases like this…

      I think the fire-extinguisher is a proper set up of Linux, updates, backups, and a web application without a lot of issues in the program code, and a minimum of attack surface.