[HN Gopher] Cloudflare CDN Partial Outage
___________________________________________________________________
Cloudflare CDN Partial Outage
Author : ericholscher
Score : 104 points
Date : 2022-10-25 17:07 UTC (5 hours ago)
(HTM) web link (www.cloudflarestatus.com)
(TXT) w3m dump (www.cloudflarestatus.com)
| nop_slide wrote:
| Got a similar message on Digital Ocean for their App
| Platform/static pages, does DO use Cloudflare underneath?
| alberth wrote:
| Yes, DO uses Cloudflare to at least protect (and cache) their
| main website.
|
| https://hostingchecker.com is a good resource to see where a
| website is hosted.
| busymom0 wrote:
| Looks like that site has a misleading name. It isn't telling
| me who I am hosting with. It's only telling me that I have
| cloudflare in front of it.
| alberth wrote:
| If Cloudflare is masking your origin to provide WAF
| capabilities, which it does for most - then I'd say this is
| expected results.
| busymom0 wrote:
| It is expected result yes. Not disagreeing with you on
| that. I am simply saying that CF is not "hosting" the
| site. It's the middle man. The host is hidden.
| geocrasher wrote:
| Experience shows that there are also a plethora of 403's with
| "cloudflare-nginx" in the message.
| encryptluks2 wrote:
| Does this mean I won't get annoying captchas on some of the sites
| I visit since Cloudflare seems to be using their services to
| train some AI model.
| jgrahamc wrote:
| https://blog.cloudflare.com/end-cloudflare-captcha/
| encryptluks2 wrote:
| I see a bunch of corporate talk about how they use captchas
| but now it is a different type that is less difficult?
| nonrandomstring wrote:
| I would have liked to read that. Instead here's what I see:
|
| > Checking if the site connection is secure
|
| > Enable JavaScript and cookies to continue
|
| > blog.cloudflare.com needs to review the security of your
| connection before proceeding.
|
| What does it mean to "review the security" of my connection?
|
| Wouldn't that be my business? (Feel free to review the
| security of _your_ connection by all means) :)
|
| Why would that "need" running JavaScript here on my browser
| (which I don't for fairly obvious security reasons) Other
| websites seem to have no problem delivering basic content
| without that.
|
| Also, no thank-you to cookies. We're not entering into a
| "session" relationship here, I merely wanted to read the
| document you advertised at the URL.
| thefreeman wrote:
| Cool. That is certainly your choice. It is also the choice
| of the website operators whose sites you try to visit to
| block your traffic since you won't opt in to their security
| precautions.
| nonrandomstring wrote:
| But I don't invite people to my house and then slam the
| door in their face.
| sbuk wrote:
| No, but you _do_ have undiscussed conditions to enter...
| encryptluks2 wrote:
| Explains why I start getting captchas due to using uBlock
| to disable JavaScript. How freaking annoying!
| jlmb wrote:
| This is not specifically about Cloudflare's
| "challenges"/etc, but --
|
| The reality of operating a big site/service on the internet
| in 2022 is that it's sometimes necessary to use methods
| that annoy a few people (with _very_ non-standard browser
| settings) in order to protect the service as a whole from a
| million bots trying to attack it at any given time.
| nonrandomstring wrote:
| > operating a big site/service
|
| This sounds like a very plausible argument. I've heard
| many of the arguments and don't dispute the threat model
| to something like Cloudflare.
|
| And yet something about it still doesn't add up.
|
| It turns power into a weakness.
|
| How is it that much smaller sites - still able to serve
| something as simple as a plain-text blog to millions of
| users from a modest rack shack - operate perfectly well
| without any impediment?
|
| Wouldn't an operation with all the power, might and money
| of Cloudflare be able to do a better job and still
| maintain the QoS (accessibility, interoperability etc) as
| Basement Bob with her Raspberry Pi?
|
| Remember, all I want to do here is _read_ a static web
| page of (I guess) less than 1000 words.
|
| I'll take a punt: if "defending against millions of bots"
| is Cloudflare's business offering, then being able to
| serve a static site off a Raspberry Pi doesn't look good
| :)
| yunohn wrote:
| Is your claim that Basement Bob's raspberry pi could
| withstand the kind of attacks that companies like
| Cloudflare handle?
|
| Eg - https://blog.cloudflare.com/26m-rps-ddos/
| csande17 wrote:
| I think the parent comment's claim is that serving a
| CAPTCHA page to potential attackers may actually be
| _more_ resource intensive than serving a lightweight page
| that has the actual content on it.
| nonrandomstring wrote:
| No. It's that Basement Bob's Raspberry Pi doesn't need
| to.
| sideproject wrote:
| Yesterday, I started getting HTTP 409 errors on some of the
| domains. It's still happening - wondering if this is related at
| all.
| 0xbadcafebee wrote:
| The only question I have is: how partial? I would hope they
| designed so it's impossible for a single change to affect the
| entire network.
| doctoboggan wrote:
| This seems to have affected many services:
|
| https://downdetector.com/
|
| Shopify admin pages and "some storefront images" were down for a
| few hours and I suspect its related to this cloudflare outtage.
| ec109685 wrote:
| Interesting Amazon shows up there who doesn't use CloudFlare.
| wongarsu wrote:
| I'd just chalk that up to DownDetector having a false
| positive. They aren't directly looking at those services but
| rely on sources such as users checking Downdetector and
| reporting problems, sentiment analysis of social media, etc.
| jgrahamc wrote:
| Fix is rolling out.
| throwthere wrote:
| Is this related to switching the firmware on the Minitel 2?
| jgrahamc wrote:
| I knew I shouldn't have done that:
| https://blog.jgc.org/2022/10/adding-mode-switch-to-my-
| minite...
| stavros wrote:
| I'd like to read an article about how the firmware caused
| the outage. It wouldn't be _true_ , but it'd be a fun read.
| jgrahamc wrote:
| 10 years ago we bought every Minitel in existence from
| eBay and connected them into a giant X.25 network
| spanning the globe. Unfortunately, one EPROM didn't have
| a cover over its window and bright sunlight in Madrid
| caused firmware corruption.
| ThePowerOfFuet wrote:
| > 10 years ago we bought every Minitel in existence from
| eBay and connected them into a giant X.25 network
| spanning the globe. Unfortunately, one EPROM didn't have
| a cover over its window and bright sunlight in Madrid
| caused firmware corruption.
|
| What a tease. If only.
| geocrasher wrote:
| Many thanks sir, from a company that uses Cloudflare Enterprise
| for delivery.
| stingraycharles wrote:
| (Parent is CTO of CloudFlare for those unaware)
| outworlder wrote:
| I wish my CTO even knew what HN was.
| carlhjerpe wrote:
| Some would be happy if their CTO knew anything about
| computing!
| qwertox wrote:
| Nice. In that case I'll try to get an update on Pingora's
| release date. Haven't heard anything about it lately :(
| ehPReth wrote:
| Thank you! What happened out of curiosity?
| outworlder wrote:
| Doubtful anyone would post anything here before there's time
| to write a proper RCA.
| jgrahamc wrote:
| Team is writing it up. Will get it out later today.
| tikotzky wrote:
| We were seeing some pages with cookies incorrectly getting
| cached, causing users to get logged in as other users. We
| quickly disabled cache on the dashboard, is this related to
| that?
| jgrahamc wrote:
| Please email me details (jgc).
| ehPReth wrote:
| Awesome - thanks :)
| kayson wrote:
| Is this impacting MS Teams? Been having screen sharing issues all
| day
| harryvederci wrote:
| That's probably just Teams impacting Teams.
| kayson wrote:
| One hopes that teams is not just a steaming pile of garbage,
| but the hopes are always dashed...
| metadat wrote:
| Here is the status messaging, pasted below for context (since
| it'll ostensibly be scrubbed once the issue is resolved):
|
| --
|
| _Increased HTTP 530 Errors_
|
| Identified
|
| The issue has been identified and a fix is being implemented.
|
| Posted 1 hour ago. Oct 25, 2022 - 16:29 UTC
|
| Investigating
|
| Cloudflare is investigating an increased level of HTTP 530
| errors.
|
| We are working to analyse and mitigate this problem. More updates
| to follow shortly.
|
| Posted 2 hours ago. Oct 25, 2022 - 15:53 UTC
|
| This incident affects: Cloudflare Sites and Services (CDN/Cache).
| metadat wrote:
| Also, I was unfamiliar with the 530 status code; turns out it's
| unofficial and somewhat arbitrary:
|
| > 530 Site is frozen
|
| Curious what this means in Cloudflare land.
|
| https://en.m.wikipedia.org/wiki/List_of_HTTP_status_codes
| bhaney wrote:
| > 530 Site is frozen
|
| That's how Pantheon uses the code, not how Cloudflare uses
| it. The wikipedia article you linked has a whole section
| dedicated to Cloudflare's use of unofficial error codes.
|
| Specifically, it doesn't mean much in particular for
| Cloudflare other than "check the other error code we returned
| elsewhere in the response to see what the actual issue is"
| c7b wrote:
| WhatsApp and Cloudflare on the same day?
| robbiet480 wrote:
| iMessage as well
| JohnJamesRambo wrote:
| Nice decentralization.
| qeternity wrote:
| Yeah because BGP never goes haywire.
| mrbuttons454 wrote:
| It's not DNS
|
| There's no way it's DNS
|
| It was DNS
| ThePowerOfFuet wrote:
| This is better and more relevant with each passing year.
|
| Beautiful calligraphy, too.
___________________________________________________________________
(page generated 2022-10-25 23:01 UTC)