Security Service Accidentally Makes Websites 60% Faster
EastDakota writes "CloudFlare was originally conceived by the team behind the open source community. Project Honey Pot as an easy way to protect any website from hackers and spammers. The concern from the beginning was that it would add latency. It was quite a surprise when the free service launched 8 months ago and ended up speeding up websites by 60%."
The article about the anti-spam article looks itself to be astroturf spam.
I've seen this before, I do not know how it works inside so I would NEVER trust it to be my server DNS provider.
According to the article, the speed boost comes from two things: 1) CloudFlare sniffs your content and inline replaces sections of it with equivalent content all served via the same connection... so the speedup comes from only having to use a single connection to get the entire page and 2) They are a globally distributed content system with 12 global data centers, similar to Akamai but smaller in scale, allowing content to come from a location closer to the end user.
Wow!
Could you at least try and hide the money you take to post ads as articles?
They offer a security product for websites, and in the process of designing it so that it didn't add much latency, they inadvertently made it into a CDN that speeds things up. There. Now we all know what the trick is.
Is this spam?
When God goes to war, He drops big bangs.
CloudFlare is touted for intercepting and altering HTML to and from client sites. Isn't this a Bad Thing? Passwords, PII, etc. all being captured, inspected, possibly altered, and sent along. What a lovely way to capture and control information. And it's spread across 12 datacenters (and growing) so who knows how many copies of your SSN there are across CF. But at least it allows IT admins to not have to care or think about customer data security.
I read the article and peaked at the site. $20 a month, for what is practically a CDN?
I'm assuming they have some pretty heavy limits on the amount of traffic you can get for that amount... Bandwidth isn't free after all.
That being said this seems like a cool service for smaller sites, especially when you don't want to do everything yourself.
.: Max Romantschuk
This is clearly just binspam. How the hell did it get approved?
While they can certainly protect a site from various threats better than the average programmer (XSS etc.), the downside is that all login and personal information also goes through their site, enabling them (or a rogue government) to collect it. Also, their concept is great for launching targeted attacks at specific users, i.e. sending them tailored content like trojans (of course such attacks by rogue governments are feasible without CF, but harder). The question is: should they be trusted more than your own employees and your ISP? Right now, here in Europe, I'd say: for important stuff, no.
That said, here's an idea for a useful "app": automated A/B-testing for your site (build 2 versions of your website and let them decide who sees what, combine with Google Analytics or other stats => see which version works better for your users).
"I love my job, but I hate talking to people like you" (Freddie Mercury)
I was looking to make websites faster after slowing them down with security. I accidentally reinvented CDN. Please give me congratulations and business :) kthxbye
Says the AC who can't even manage to post to the correct story :)
Here's an EASIER trick, with a FREE "Tool" you already own, that's only a single text file filter for your IP stack: A custom HOSTS file, that yields the same results!
(I think it'd be interesting to see this service, COMBINED w/ what I am about to speak of in custom HOSTS files usage, and benefits to the end-user).
"According to the article, the speed boost comes from two things" - by Anonymous Coward on Wednesday June 08, @12:42AM (#36371418)
The gains HOSTS files offer in both speed, & security, are twofold:
---
FOR ADDED SPEED:
1.) Blocks out adbanners & the lag they introduce into webpage loads/downloads for consumption
2.) Hardcoding in your favorite website (to avoid DNS roundtrip lookup & result return time)
---
FOR ADDED SECURITY:
1.) Blocks out KNOWN malicious sites/servers/hosts-domain names
2.) Protection vs. DNS issues (such as the "Kaminsky flaw", or downed/compromised DNS servers that have been "redirect poisoned")
---
They work, they're free, and you can obtain one easily!
(OR, just combine ALL of the ones listed in my 'p.s.' below, & a db import of the file using a SELECT DISTINCT query can do it for example, as a way, or mvps.org offers a tool called HOSTSMAN that does it also (there are others like it as well, I designed one, & so have others)).
You already can do this yourself since any OS that uses a BSD derived IP stack already has one (even ANDROID phones), easily, & populate the custom HOSTS file yourself from the sources noted above!
(I consolidate them all into a single de-duplicated/normalized version, that which currently blocks out 1,429,303++ KNOWN bad sites/servers/hosts-domains, AND, speeds me up VERY noticeably (via blocking out adbanners, a possible threat for years now in malicious code in them & a bandwidth + speed hog OR, by 'hardcoding in' my favorite sites (to bypass DNS lookup & return roundtrip time) also))
APK
P.S.=> Here are some reputable, & reliable sources for said HOSTS file security data (as well as prebuilt HOSTS files for instant download & usage on your parts):
http://safeweb.norton.com/buzz
http://doc.emergingthreats.net/bin/view/Main/HoneywallSamples
http://securehomenetwork.blogspot.com/search?updated-min=2011-01-01T00%3A00%3A00-05%3A00&updated-max=2012-01-01T00%3A00%3A00-05%3A00&max-results=12
http://www.malwaredomainlist.com/hostslist/hosts.txt
http://www.malwaredomains.com/
http://hosts-file.net/?s=Download
http://www.malware.com.br/lists.shtml
http://www.malware.com.br/lists.shtml
https://spyeyetracker.abuse.ch/monitor.php
https://zeustracker.abuse.ch/monitor.php?filter=online
http://www.malwareurl.com/
http://someonewhocares.org/hosts/
http://www.mvps.org/winhelp2002/hosts.htm
... apk
Bring on the marketing creatures.
I am very small, utmostly microscopic.
Great summary, better than the original summary, but the original article doesn't even get the number of data centers right:
"We run 10 (with more coming) data centers around the world and do DNS, caching, bot filtering and more for all of our users. " (http://blog.cloudflare.com/top-tips-for-new-cloudflare-users "posted 12 days ago".)
Slashdot is posting sponsored content now?
and its the choice of a new generation.. :drinks pepsi:
Maybe THE people who "modded you down" did it BECAUSE your posts are "too full" of random caps, quotes, bold, and broken ENGLISH, and they were "fed up w/ your" gibberish.
AC
P.S.=#&> STFU, GTFO, and DIAF!
Disprove my points on HOSTS I put up in this exchange then...
That is, IF you can (I am certain you cannot), in regards to your off-topic trolling statement here:
"Maybe THE people who "modded you down" did it BECAUSE your posts are "too full" of random caps, quotes, bold, and broken ENGLISH, and they were "fed up w/ your" gibberish." - by Anonymous Coward on Wednesday June 08, @10:44AM (#36374924)
So, show me in THIS post where my points here in this exchange are "gibberish", ok?
It appears the "best you have", is off-topic adhominem attacks, writing style trolling critiques (effete & useless, as you can see my post was modded up & complimented by others here also) as per your trolling usual, & nothing more...
(Typical!)
APK
P.S.=>
"STFU, GTFO, and DIAF!" - by Anonymous Coward on Wednesday June 08, @10:44AM (#36374924)
If the best you have is adhominem attacks, in attempts to attack myself, rather than the points I put out? You FAIL!
( & rather badly, as well as your being off-topic & obviously trolling on your part!)
... apk
Dearest trolls: The best it appears you have, is a "hit-&-run" down moderation of my post on HOSTS files - poor showing boys!
(If that's "the best you've got" here? You've FAILED, badly!)
As for myself? The more this gets out to uninformed users that are unaware of the combined benefits that HOSTS files give end-users (and server owners also) in more speed, and more "layered security", the more I have done my part!
APK
P.S.=> In the end/bottom-line here: I'd like to know what it is you apparently FEAR from HOSTS files, because I will "overcome your 'objections'" easily, and with valid technical fact, vs. your b.s.
(After all: I've done that to my "naysayers" here so many times, it does appear that the "best you have" is off topic ad hominem attacks, or, unjustified mod downs - poor showing on your part(s), trolls)
... apk
A HOSTS FILE IS CACHED UPON INITIAL READ INTO RAM (or the local DNS clientside cache in Windows, if you have a "smallish" HOSTS file)!
Are you THAT MUCH OF A NOOB IN COMPUTING YOU DON'T REALIZE THAT?
(Apparently so!)
---
"For anybody who takes this ass clown seriously, all major OSs scan the hosts file line by line every time. 300gigabyte hosts files are terrible for performance." - by Anonymous Coward on Wednesday June 08, @02:39PM (#36378356)
See above - "drink it in, & digest it" because it will help you "eat your words" (now flavored with the "bitter taste of defeat" (your defeat - worst part? You defeated yourself via your own ignorance, lol!)).
---
"However, you can replace it with tinydns (to serve 127.0.0.0 for blocked domains) and dnscache (to keep a local cache of real domains) and get a much better performance boost.." - by Anonymous Coward on Wednesday June 08, @02:39PM (#36378356)
Why? So folks can waste CPU, Memory, & other forms of I/O as well as increasing their electric bill by running yet another program??
Real "smart" that, lol (not)... though you CAN run DNS servers alongside HOSTS too? DNS definitely has problems/issues... would you like me to list some of those as well?
APK
P.S.=> Look @ the "bright-side" of things now: Now, finally, you know (although you have "egg on your face" now for it, no small wonder you posted as AC... lol, you don't feel confident enough in your know-how in computing, and trust me, based on your results here? You don't!)
... apk
Where you overlooked that the local diskcaching kernel mode subsystem all PC/Server OS' have cache larger HOSTS files (vs. the DNS clientside cache for Windows for smaller HOSTS files) in the URL link below:
http://it.slashdot.org/comments.pl?sid=2220314&cid=36379004
LMAO - you REALLY need to learn more of how modern Operating Systems work buddy...
---
"Hey Taco, could you update the lameness filter to exclude APK's ramblings? Thanks!" - by Anonymous Coward on Wednesday June 08, @11:01AM (#36375158)
Who's the one rambling now? You are!
From that link above, You also look quite stupid for it.
APK
P.S.=> I certainly wouldn't want to be YOU right now, lol... you look like a fool, especially from the URL link above where you messed up on a SIMPLE CONCEPT in computing called diskcaching!
Do yourself a favor - Learn more about computing and how it works, before you shoot your mouth off again and look stupid for it as you did in the link above!
... apk