[HN Gopher] Cloudflare CDN Partial Outage
       ___________________________________________________________________
        
       Cloudflare CDN Partial Outage
        
       Author : ericholscher
       Score  : 104 points
       Date   : 2022-10-25 17:07 UTC (5 hours ago)
        
 (HTM) web link (www.cloudflarestatus.com)
 (TXT) w3m dump (www.cloudflarestatus.com)
        
       | nop_slide wrote:
       | Got a similar message on Digital Ocean for their App
       | Platform/static pages, does DO use Cloudflare underneath?
        
         | alberth wrote:
         | Yes, DO uses Cloudflare to at least protect (and cache) their
         | main website.
         | 
         | https://hostingchecker.com is a good resource to see where a
         | website is hosted.
        
           | busymom0 wrote:
           | Looks like that site has a misleading name. It isn't telling
           | me who I am hosting with. It's only telling me that I have
           | cloudflare in front of it.
        
             | alberth wrote:
             | If Cloudflare is masking your origin to provide WAF
             | capabilities, which it does for most - then I'd say this is
             | expected results.
        
               | busymom0 wrote:
               | It is expected result yes. Not disagreeing with you on
               | that. I am simply saying that CF is not "hosting" the
               | site. It's the middle man. The host is hidden.
        
       | geocrasher wrote:
       | Experience shows that there are also a plethora of 403's with
       | "cloudflare-nginx" in the message.
        
       | encryptluks2 wrote:
       | Does this mean I won't get annoying captchas on some of the sites
       | I visit since Cloudflare seems to be using their services to
       | train some AI model.
        
         | jgrahamc wrote:
         | https://blog.cloudflare.com/end-cloudflare-captcha/
        
           | encryptluks2 wrote:
           | I see a bunch of corporate talk about how they use captchas
           | but now it is a different type that is less difficult?
        
           | nonrandomstring wrote:
           | I would have liked to read that. Instead here's what I see:
           | 
           | > Checking if the site connection is secure
           | 
           | > Enable JavaScript and cookies to continue
           | 
           | > blog.cloudflare.com needs to review the security of your
           | connection before proceeding.
           | 
           | What does it mean to "review the security" of my connection?
           | 
           | Wouldn't that be my business? (Feel free to review the
           | security of _your_ connection by all means) :)
           | 
           | Why would that "need" running JavaScript here on my browser
           | (which I don't for fairly obvious security reasons) Other
           | websites seem to have no problem delivering basic content
           | without that.
           | 
           | Also, no thank-you to cookies. We're not entering into a
           | "session" relationship here, I merely wanted to read the
           | document you advertised at the URL.
        
             | thefreeman wrote:
             | Cool. That is certainly your choice. It is also the choice
             | of the website operators whose sites you try to visit to
             | block your traffic since you won't opt in to their security
             | precautions.
        
               | nonrandomstring wrote:
               | But I don't invite people to my house and then slam the
               | door in their face.
        
               | sbuk wrote:
               | No, but you _do_ have undiscussed conditions to enter...
        
             | encryptluks2 wrote:
             | Explains why I start getting captchas due to using uBlock
             | to disable JavaScript. How freaking annoying!
        
             | jlmb wrote:
             | This is not specifically about Cloudflare's
             | "challenges"/etc, but --
             | 
             | The reality of operating a big site/service on the internet
             | in 2022 is that it's sometimes necessary to use methods
             | that annoy a few people (with _very_ non-standard browser
             | settings) in order to protect the service as a whole from a
             | million bots trying to attack it at any given time.
        
               | nonrandomstring wrote:
               | > operating a big site/service
               | 
               | This sounds like a very plausible argument. I've heard
               | many of the arguments and don't dispute the threat model
               | to something like Cloudflare.
               | 
               | And yet something about it still doesn't add up.
               | 
               | It turns power into a weakness.
               | 
               | How is it that much smaller sites - still able to serve
               | something as simple as a plain-text blog to millions of
               | users from a modest rack shack - operate perfectly well
               | without any impediment?
               | 
               | Wouldn't an operation with all the power, might and money
               | of Cloudflare be able to do a better job and still
               | maintain the QoS (accessibility, interoperability etc) as
               | Basement Bob with her Raspberry Pi?
               | 
               | Remember, all I want to do here is _read_ a static web
               | page of (I guess) less than 1000 words.
               | 
               | I'll take a punt: if "defending against millions of bots"
               | is Cloudflare's business offering, then being able to
               | serve a static site off a Raspberry Pi doesn't look good
               | :)
        
               | yunohn wrote:
               | Is your claim that Basement Bob's raspberry pi could
               | withstand the kind of attacks that companies like
               | Cloudflare handle?
               | 
               | Eg - https://blog.cloudflare.com/26m-rps-ddos/
        
               | csande17 wrote:
               | I think the parent comment's claim is that serving a
               | CAPTCHA page to potential attackers may actually be
               | _more_ resource intensive than serving a lightweight page
               | that has the actual content on it.
        
               | nonrandomstring wrote:
               | No. It's that Basement Bob's Raspberry Pi doesn't need
               | to.
        
       | sideproject wrote:
       | Yesterday, I started getting HTTP 409 errors on some of the
       | domains. It's still happening - wondering if this is related at
       | all.
        
       | 0xbadcafebee wrote:
       | The only question I have is: how partial? I would hope they
       | designed so it's impossible for a single change to affect the
       | entire network.
        
       | doctoboggan wrote:
       | This seems to have affected many services:
       | 
       | https://downdetector.com/
       | 
       | Shopify admin pages and "some storefront images" were down for a
       | few hours and I suspect its related to this cloudflare outtage.
        
         | ec109685 wrote:
         | Interesting Amazon shows up there who doesn't use CloudFlare.
        
           | wongarsu wrote:
           | I'd just chalk that up to DownDetector having a false
           | positive. They aren't directly looking at those services but
           | rely on sources such as users checking Downdetector and
           | reporting problems, sentiment analysis of social media, etc.
        
       | jgrahamc wrote:
       | Fix is rolling out.
        
         | throwthere wrote:
         | Is this related to switching the firmware on the Minitel 2?
        
           | jgrahamc wrote:
           | I knew I shouldn't have done that:
           | https://blog.jgc.org/2022/10/adding-mode-switch-to-my-
           | minite...
        
             | stavros wrote:
             | I'd like to read an article about how the firmware caused
             | the outage. It wouldn't be _true_ , but it'd be a fun read.
        
               | jgrahamc wrote:
               | 10 years ago we bought every Minitel in existence from
               | eBay and connected them into a giant X.25 network
               | spanning the globe. Unfortunately, one EPROM didn't have
               | a cover over its window and bright sunlight in Madrid
               | caused firmware corruption.
        
               | ThePowerOfFuet wrote:
               | > 10 years ago we bought every Minitel in existence from
               | eBay and connected them into a giant X.25 network
               | spanning the globe. Unfortunately, one EPROM didn't have
               | a cover over its window and bright sunlight in Madrid
               | caused firmware corruption.
               | 
               | What a tease. If only.
        
         | geocrasher wrote:
         | Many thanks sir, from a company that uses Cloudflare Enterprise
         | for delivery.
        
         | stingraycharles wrote:
         | (Parent is CTO of CloudFlare for those unaware)
        
           | outworlder wrote:
           | I wish my CTO even knew what HN was.
        
             | carlhjerpe wrote:
             | Some would be happy if their CTO knew anything about
             | computing!
        
           | qwertox wrote:
           | Nice. In that case I'll try to get an update on Pingora's
           | release date. Haven't heard anything about it lately :(
        
         | ehPReth wrote:
         | Thank you! What happened out of curiosity?
        
           | outworlder wrote:
           | Doubtful anyone would post anything here before there's time
           | to write a proper RCA.
        
           | jgrahamc wrote:
           | Team is writing it up. Will get it out later today.
        
             | tikotzky wrote:
             | We were seeing some pages with cookies incorrectly getting
             | cached, causing users to get logged in as other users. We
             | quickly disabled cache on the dashboard, is this related to
             | that?
        
               | jgrahamc wrote:
               | Please email me details (jgc).
        
             | ehPReth wrote:
             | Awesome - thanks :)
        
       | kayson wrote:
       | Is this impacting MS Teams? Been having screen sharing issues all
       | day
        
         | harryvederci wrote:
         | That's probably just Teams impacting Teams.
        
           | kayson wrote:
           | One hopes that teams is not just a steaming pile of garbage,
           | but the hopes are always dashed...
        
       | metadat wrote:
       | Here is the status messaging, pasted below for context (since
       | it'll ostensibly be scrubbed once the issue is resolved):
       | 
       | --
       | 
       |  _Increased HTTP 530 Errors_
       | 
       | Identified
       | 
       | The issue has been identified and a fix is being implemented.
       | 
       | Posted 1 hour ago. Oct 25, 2022 - 16:29 UTC
       | 
       | Investigating
       | 
       | Cloudflare is investigating an increased level of HTTP 530
       | errors.
       | 
       | We are working to analyse and mitigate this problem. More updates
       | to follow shortly.
       | 
       | Posted 2 hours ago. Oct 25, 2022 - 15:53 UTC
       | 
       | This incident affects: Cloudflare Sites and Services (CDN/Cache).
        
         | metadat wrote:
         | Also, I was unfamiliar with the 530 status code; turns out it's
         | unofficial and somewhat arbitrary:
         | 
         | > 530 Site is frozen
         | 
         | Curious what this means in Cloudflare land.
         | 
         | https://en.m.wikipedia.org/wiki/List_of_HTTP_status_codes
        
           | bhaney wrote:
           | > 530 Site is frozen
           | 
           | That's how Pantheon uses the code, not how Cloudflare uses
           | it. The wikipedia article you linked has a whole section
           | dedicated to Cloudflare's use of unofficial error codes.
           | 
           | Specifically, it doesn't mean much in particular for
           | Cloudflare other than "check the other error code we returned
           | elsewhere in the response to see what the actual issue is"
        
       | c7b wrote:
       | WhatsApp and Cloudflare on the same day?
        
         | robbiet480 wrote:
         | iMessage as well
        
           | JohnJamesRambo wrote:
           | Nice decentralization.
        
             | qeternity wrote:
             | Yeah because BGP never goes haywire.
        
       | mrbuttons454 wrote:
       | It's not DNS
       | 
       | There's no way it's DNS
       | 
       | It was DNS
        
         | ThePowerOfFuet wrote:
         | This is better and more relevant with each passing year.
         | 
         | Beautiful calligraphy, too.
        
       ___________________________________________________________________
       (page generated 2022-10-25 23:01 UTC)