Email or username:

Password:

Forgot your password?
rabbit

Cloudflare is the only company that has ever given literal nazis my mother's phone number, so my opinion of them is slightly worse than my opinion of hot garbage.
infosec.exchange/@briankrebs/1

22 comments
Fi, infosec-aspected

@rabbit

Only company I've ever interacted with where filing a report resulted in getting death threats from the people I'd filed a report about.

Foone🏳️‍⚧️

@munin @rabbit yeah I gave them the most mild criticism once and within a couple hours my home address was on the fruitfarmer site, complete with a death threat.

rabbit

I have cost this company several million dollars the last time I tallied that score, either through sales I've directly scuttled in my own organizations or by having a conversation with my colleagues considering their services, and I don't intend to stop.

rabbit

If you have a need for things CloudFlare does, call Akamai and see if they can help you instead. Those folks have been nothing but amazing to me with every interaction.

rabbit

When Boston hospitals were placed under DDoS attack years ago, we called Radware, who were also great to work with. Anybody but CloudFlare.

NosirrahSec 🏴‍☠️

@rabbit Nazi-flare*

They host Nazis, kiwifarms(still right?), etc.

Fuck Cloudflare.

catte_salad clone (da_667)

@rabbit

cloudflare hosts malware. I don't give a fuck about the technicalities. If your resolvers are authoratative, and/or the resolved IP falls in your address space, That is hosting malware.

While I'm at it, fuck Cloudflare, and fuck their involvement for forcing the DoH RFC through, and being the default provider for many modern browsers.

Wonder how many dicks Matthew Prince had to suck for that.

Import Antigravity

@da_667 @rabbit Wow, one of us! I was the DNS manager for a CF competitor for a few years, and I gotta hand it to their marketing department the way they spun "We're changing DNS for your security!" for competitive advantage. I feel like Don Quixote and CF DNS are the windmills. It's nice to see someone in the wild see that.

Import Antigravity

@da_667 @rabbit Also, I'd like to plug Edgio (the previously mentioned competitor). They're having a bit of trouble lately, and even if I got laid off last year I still wish them well. There's a lot of good people there who will treat you right.

catte_salad clone (da_667)

@rabbit oh, and while we're on the cloudflare paintrain, at some point they claimed to handling 20% of internet traffic. Recently they claimed that 7% of all internet traffic is malicious. Exactly how do they know that, and how much of it is traffic to and from their infrastructure?

demize

@da_667 @rabbit there's one domain that we had proof was being used in an active scam targeting our customers (full email headers, etc)

we have brand protection through CSC

cloudflare completely ignored CSC and our only recourse would have been UDRP.

demize

@da_667 @rabbit at this point, I consider cloudflare in the same light I consider anyone else favored by threat actors: DNI at all costs

NosirrahSec 🏴‍☠️

@rabbit I have a cousin there, been there since almost day one, and it's a fantastic organization. 100% agreed.

Yulian Kuncheff

@rabbit honest question. Is there a competitor that offers good DNS, domains, analytics, and a Zero Trust solution that integrates with The DNS, and has a no egress cost for Backblaze, etc. I use a ton of CF services that allow me to expose to the Internet, but have some protection.

I would love to switch, but I don't have $1000s to pay for these services for my homelab/self-hosted stuff. And I get it all free from CF.

I also don't have a lot of time to manage stuff. Got 2 young kids and a job

Fi, infosec-aspected

@rabbit

They're pretty cop-brained. They set themselves up as -essential protectors- but refuse to do anything to -actually help- you if you've been injured by someone in their enclave.

Foone🏳️‍⚧️

@rabbit I saw this reply without context and whispered "please say you're talking about cloudflare" and then the context finally loaded and I went YEAH!

rabbit

@foone It's truly amazing that a company with a reputation this bad continues to be such a big part of the internet.

tanguyraton

@rabbit
@LenPennie if you see that, mind big tech are actual freaking fucking stalkers

xconde

@rabbit @schrotthaufen @briankrebs timely reminder that #Fastly now has a free tier with up to 50GB of traffic.

Go Up