Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It really depends. A lot of people, myself included, use their free tier service which is excellent for the grand price of zero, however it does not really come with much real DDoS protection. Script kiddies might give up after seeing an IP address belonging to CF, but the more experienced and determined attackers will keep ramping up bandwidth until Cloudflare takes notice and cut you off because you are now more trouble than worth. Free tier breaks only with a little bit of traffic, whereas paid users have some headroom but it is not infinite. From their point of view it's still preferable to lose you as a customer than having every other customer's site lagging because of you.

Apparently even business tier is not immune, Brian Krebs' security blog was DDoS'ed off Akamai after the then-ongoing mitigation cost ended up being far more than they could agree on, and it took him days to find another provider[0].

[0]:https://krebsonsecurity.com/2016/09/the-democratization-of-c...



What's not obvious from outside of Cloudflare is that DDoS attack traffic doesn't increase our costs. While someone like AWS charges based on bytes delivered, we instead pay for bandwidth based on the capacity of our connection. Importantly, we pay for the greater of the traffic into our network (ingress) or out from our network (egress).

To make it tangible with made up numbers, imagine we pay $10/megabit per second per month. If our egress (out) is 10Mbps and our ingress (in) is 1Mbps then we'd pay 10 x $10 = $100/month. If our ingress went up to 9Mbps and our egress stayed at 10Mbps then we'd still pay 10 x $10 = $100/month.

Since we're a caching proxy, you'd expect egress (out) to be higher than ingress (in). That is in fact the case. While DDoS attacks push the ingress up, the spread between ingress and egress is so large that even the largest attacks don't push ingress above egress. In fact, even attacks that are many times larger than the largest attacks ever seen would still not increase our bandwidth costs.

This is different from other providers that run separate networks for DDoS mitigation, or only provide DDoS mitigation without providing other caching services. My understanding is that Akamai runs a separate network for DDoS from their CDN, which is why large attacks drive up their costs. We made different architectural decisions, which is why it doesn't for us. And, as our caching services get more popular, it effectively increases the size of the largest theoretical attack we could handle without it driving up our bandwidth costs.

So, yes, there is a theoretical limit of an attack we could not handle today. That, however, is at least an order of magnitude bigger than the largest attacks the Internet has ever seen. And, if such an attack did happen, I think there would be other parts of the Internet that would fall over before we did.

For the record: since we announced Unmetered DDoS mitigation in September 2017 we haven't terminated any customer, free or paying, for an attack they've received.


All Cloudflare plans have unmetered DDoS protection. Where did you get the idea that they would cut you off if you were on the free tier?


Until late last year that was their policy: https://blog.cloudflare.com/unmetered-mitigation/

Also they specifically refer to volumetric mitigation' as the thing which everyone gets.

The harder to deal with attacks are probably the application aware resource attacks.


I've seen it happen multiple times. Besides, "unmetered" is almost always marketing hype whenever you see it. If your website uses >10TB of non-DDoS traffic per day on CF you are likely to get a call from their sales team soon asking you to upgrade to a pro or business account.

A brief DDoS was (not sure if still is) a common method to expose the real IP because the CDN edge servers could often be easily spooked by a brief surge in traffic and start redirecting DNS back to origin. I suspect this is the kind of "protection" they were really offering: your site will still be down, but at least the backend is never revealed to the world.


They've publically stated that they do not drop traffic for any plans (at least as of 2017) no matter the size. So whatever you have seen is likely no longer the case. Unless you have sources that they are still doing this?


[flagged]


I'd be more likely to believe what you're saying if you provided some backup for what you're claiming.


In earlier times they had to encourage people to move. By now, CF is so big that they can handle losing money on some customers with high traffic on a free plan. The gain from not dropping any customers outweighs the cost caused by that client.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: