Comment by aliasxneo

20 hours ago

Tunneling was something that recently fell out of the work I've been doing [1]. I've used Cloudflare Tunnels before but I just have low trust with them recently with how big they are getting. All of these nice things come at the cost of pushing _a lot_ of traffic through their systems.

[1]: https://dntls.substack.com/p/the-new-internet

Reality check - you are not pushing “_a lot_” of traffic relative to any hyperscaler or large scale CDN. They push hundreds of Tbps sustained. You don’t peak at a few Mbps.

They can monitor extreme outliers. It’s not an issue for them.

  • In hindsight, that was probably a confusing sentence. I was more pointing out how much traffic flows trough their systems which ends up making it an attractive honeypot, especially as a U.S. company.

    • Sure any centralization of infra is an obvious risk for a myriad of reasons eg DoS, manipulation, honeypots, etc.

      But again my point applies - the chances they get enough people using it that it becomes a meaningfully worse security target than lots of other existing things seems … super low.

      It’s a big world, people make many choices I can’t understand (nix? Haskell? Php? <flame wars to /dev/null>). Even if this product nailed it - the number of people who can use it is minuscule - yes even as we add Claude-enabled PMs to the software dev ranks.

      Alt view with the old saying - “put all your eggs in one basket … and watch that basket!”

If there's any company in the world that can survive a lot of extra traffic being pushed through their systems it's Cloudflare.

I bet these new tunnels end up being a fraction of a percentage point of their network traffic.

  • Yeah, I don't doubt their infrastructure at all. In fact, I rate them fairly high in terms of reliability and performance. I've honestly been a fan of them for a very long time - it's just I'm watching all of this centralization happen and it sets my Spidey sense off. Like I'm waiting for the other shoe to drop.

    • The "centralization" which is cloudflare basically running its own walled garden version of the interent (how often do you see a cloudflare page checking if you're human?) is exactly why a lot of people do NOT like cloudflare. And if you've known about CF and its leadership since their inception you'd be even more wary of sticking your stuff over there.

      I've migrated many companies off of cloudflare, usually because they end up pissing off companies when a contract renewal comes up and they slam them with massively increased bills and almost useless support if you aren't very high paying enterprise. I don't know how many CF support tickets I've just given up on over the last 15 years, usually related to their admin page, workers or some weird thing their system does that wasn't documented and I just stop getting responses and definitely don't get fixes.

      If you ever worked in webhosting the Cloudflare wordpress/etc extensions are everywhere and back when I did work in hosting tons of support tickets were made because of CF. Could be way better now, I don't go near that industry these days.

      The casual CF user sticking it in front of a blog they rarely look at and the business forced CF user has a very different experience. I cringe and seriously consider if I'm interviewing for an infra role and they use cloudflare. Usually it's startups that grew into larger businesses.

  • It’s a concentration of power issue.

    • Given they seem to mostly offer services that are about as easy to switch away from as you could hope for, compared to, say, companies who write loads of CF that only runs on AWS, and I can't imagine why this keeps on being said for Cloudflare specifically. What power do they have?

      1 reply →

  • Don’t the free tunnels have explicit limits on bandwidth and streaming?

  • They see all the traffic in cleartext. Plus you have to trust them not to maliciously alter your traffic. As a US company, their options may be limited if they are coerced by their government to do so.

Interesting how 4/4 other replies didn't get the centralisation concern despite it being a fairly often discussed topic

Your opening piqued my interest, but:

“The substrate itself consists of a few systems…”

I doubt that this is how wordy your communication is.

“It consists of a few systems” would be adequate. And if we had prior context about what else exists that surrounds “the substrate” the “substrate itself” distinction would be meaningful, but it’s not, because you are referring to one object, which is the system you built, and I doubt any enzymes act on it, so it’s likely not a substrate.

Yeah, it reminds me of Google. Fool me twice ...

I'm not trusting any of these corporates any more

Cloudflare want you to push traffic through their systems. This is yet another traffic generator to drive up Cloudflare’s leverage when negotiating peering with carriers & service providers, in order to drive down the marginal cost of bandwidth for Cloudflare’s actual product viz. the enterprise DDoS protection.

  • True. Same reason Hurricane Electric peers promiscuously. I'm surprised more networks don't, to be honest - wouldn't say DTAG prefer that you peer with DTAG than peer with HE upstream of DTAG?

This is pretty great and I think this will be quite important in the age where everyone has their self-hosted services.