| ▲ | binarymax 9 hours ago |
| Why not use those providers directly? Does Cloudflare need to be in the middle of everything? |
|
| ▲ | rithdmc 9 hours ago | parent | next [-] |
| It would be difficult for them to provide intelligence to the US without being in the middle of everything. |
| |
|
| ▲ | hobofan 8 hours ago | parent | prev | next [-] |
| I think Cloudflare is (for companies already using it) approaching the status of trusted main cloud supplier (which usually would be AWS, GCP, Azure) via which the majority of cloud costs are billed (so you don't have to go through a fresh procurement process). |
| |
| ▲ | ryandvm 8 hours ago | parent | next [-] | | I don't know what you mean by "trusted", but how many times do folks have to go through the same loop? - Company has great initial product
- Company gets popular
- Shareholders demand infinite growth
- Company becomes rent-seeker
- GOTO 10
I'm with OP - a company that wants to insert itself in the middle of everybody's business is not being altruistic, they're playing the long game. | | |
| ▲ | viraptor 8 hours ago | parent | next [-] | | > I don't know what you mean by "trusted", It means "hi spending approver, I'm going to add $100 to our CF account" instead of "hi accounting+management+security, please initiate the process of evaluating new third party vendor Foo for use in my project, I hope we can get it approved and integrated into SSO sometime next month". | |
| ▲ | tomrod 5 hours ago | parent | prev | next [-] | | CloudFlare is FedRAMP high. This is a pretty big deal for a lot of a certain type of system owners. | |
| ▲ | deadbabe 5 hours ago | parent | prev [-] | | There is nothing wrong with “inserting yourself in the middle of everybody’s business”. That is how you reduce friction between parties and make optimizations that are only possible by being able to manage both sides of the connection. It’s also a really good way to make money. | | |
| ▲ | ryandvm 4 hours ago | parent [-] | | Well... there's "nothing wrong" with being a car dealership either. "Wrong" is a funny way to look at it. |
|
| |
| ▲ | ricardobeat 2 hours ago | parent | prev | next [-] | | This practice of having the one provider should be eliminated. Companies self-inflict lock-in to large platform providers, prevent their own teams from using better technology options and stifle innovation. It's crazy that even with a pile of SOC/ISO/PCI/HIPAA/NIS certificates, procurement is still a months-long process, it should be much easier to do business. | |
| ▲ | ttul 4 hours ago | parent | prev [-] | | I think their strategy is: "AI coding means we can build everything. Our infrastructure approach is incredibly quick to build upon, so why not build it all ourselves and then anyone with half a brain will move their stuff to Cloudflare and leave AWS in the dust." |
|
|
| ▲ | patwolf 9 hours ago | parent | prev | next [-] |
| I've been using the web search in OpenRouter, which is similar in that it's a wrapper around other search engine providers. It's really convenient to be able to experiment with new models and new search engines without having to go through corporate hoops to subscribe to a new service. |
|
| ▲ | unified101 9 hours ago | parent | prev | next [-] |
| Ease of integration and billing. Failover. Higher trust. |
| |
| ▲ | not_math 9 hours ago | parent | next [-] | | To add to this, some organizations just prefer using one provider for their cloud service. So if they build on Azure/Google Cloud/AWS, then everything needs to be on there. Cloudflare probably wants to offer the same here, where everything can be built on Cloudflare. | |
| ▲ | binarymax 9 hours ago | parent | prev | next [-] | | Not sure where the trust claim lands, but the first two are now exceedingly trivial with code agents. A little more work perhaps, but not hard at all. I’ve done this myself (not with those providers) with several search platforms. | | |
| ▲ | bayesianbot 9 hours ago | parent | next [-] | | CloudFlare AI Gateway was quite convenient for me - I wanted to give my zeroclaw instance a limited budget to services like Image generation/Replicate/Fal.ai, which would mean for each service I'd have to run my own proxy that stores the keys and cuts off the real calls if we go over the limits. Easy to do but still extra thing to build and maintain. Instead I put my API keys to cloudflare, set limits, and gave the agent the CloudFlare token, and in minutes it could contact tens of services. edit: not to mention instead of loading balance to each service I could just keep balance on cloudflare that covers them all | |
| ▲ | JumpCrisscross 2 hours ago | parent | prev [-] | | > A little more work perhaps, but not hard at all Extremely hard to verify it's been done properly across a large organization. |
| |
| ▲ | goalieca 8 hours ago | parent | prev | next [-] | | Curious what other people’s experience is with cloudflare billing. When you go through an AE, everything seems made up anyways. | |
| ▲ | 478336632929 8 hours ago | parent | prev [-] | | Why would anyone trust Cloudflare? | | |
| ▲ | wongarsu 8 hours ago | parent | next [-] | | Same way people trust Microsoft: "We already use them, and using them for this additional service exposes no data they wouldn't already have access to from all the other services we buy from them" | |
| ▲ | ForHackernews 8 hours ago | parent | prev [-] | | I trust Cloudflare more than I trust some other players in the arena. They have a decent track record of being neutral infrastructure provider. They seem technically strong, deploying Rust widely and caring about performance in a way that most firms do not. They're likely covertly funded by intelligence services so they don't have economic incentives to enshitify their offerings or deliberately screw me over. Put it this way: I'd rather Cloudflare owns the Internet than Google, Meta, Amazon or Alibaba. | | |
| ▲ | OutOfHere 7 hours ago | parent [-] | | > or deliberately screw me over. Cloudflare is however known to deliberately screw over some of their clients. > I'd rather Cloudflare owns the Internet I'd rather no one does, certainly not a firm that feeds into the NSA. | | |
| ▲ | Muromec 5 hours ago | parent | next [-] | | >I'd rather no one does, certainly not a firm that feeds into the NSA. The government always wins this given enough time. | |
| ▲ | ForHackernews 6 hours ago | parent | prev [-] | | Citation? The only case I'm aware of is when they removed DDoS protection for the Daily Stormer[0], and tbqh that made me feel more positively toward them. Yes, it was an impulsive, emotionally-motivated choice but that was relatable to me. [0] https://blog.cloudflare.com/why-we-terminated-daily-stormer/ | | |
| ▲ | ppseafield 3 hours ago | parent | next [-] | | It wasn't an impulsive decision. They kept the Daily Stormer's account active up until Andrew Anglin said CF kept offering him their services because they quietly agreed with him. > Our terms of service reserve the right for us to terminate users of our network at our sole discretion. The tipping point for us making this decision was that the team behind Daily Stormer made the claim that we were secretly supporters of their ideology. > Our team has been thorough and have had thoughtful discussions for years about what the right policy was on censoring. Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network. We could not remain neutral after these claims of secret support by Cloudflare. https://blog.cloudflare.com/why-we-terminated-daily-stormer/ | |
| ▲ | OutOfHere 6 hours ago | parent | prev | next [-] | | Cloudflare is known to extort customers. https://news.ycombinator.com/item?id=44150898 (2025) https://news.ycombinator.com/item?id=40481808 (2024) https://robindev.substack.com/p/cloudflare-took-down-our-web... Reddit comments report more such incidents, with Cloudflare demanding an upgrade to Enterprise. This has also come up for other sites, such as gambling sites. Also, Cloudflare implicitly screws over everyone by leaking data to the NSA. | | |
| ▲ | esseph 3 hours ago | parent [-] | | > Also, Cloudflare implicitly screws over everyone by leaking data to the NSA I have always operated under the assumption that every cloud provider and telco does this, so this claim has always seemed very silly to me. | | |
| ▲ | OutOfHere 3 hours ago | parent [-] | | Huh. When you don't use a man-in-the-middle service, you don't have this problem. When you host on a cloud vendor, you don't have this problem because you control the HTTPS certificate and don't leak it to the MITM. The assumption as such seems silly to me. | | |
| ▲ | esseph 3 hours ago | parent [-] | | Your DNS lookups and IPs in use provide a lot of info. It's not always the data inside an encryption layer that is the most important. That said, these are US companies subject to FISA court orders and NSLs or National Security Letters. If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. Any idea that your data is protected because you're not even using a provider WAF or doing TLS termination for load balancing is a fantasy. | | |
| ▲ | OutOfHere 2 hours ago | parent [-] | | > Your DNS lookups I control which DNS server I use. It is not relevant to the matter at hand. > If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. You're confusing bulk data collection with highly selective court-ordered data collection. The two are not alike. Attempting to equate them is a dumb attempt at deception on your part. There is no obligation for a firm to share bulk web data with the NSA. |
|
|
|
| |
| ▲ | encom 4 hours ago | parent | prev [-] | | >impulsive, emotionally-motivated Yes that's precisely how I want infrastructure to operate. |
|
|
|
|
|
|
| ▲ | simultsop 3 hours ago | parent | prev | next [-] |
| How else you are going to make them give you search second party API's, they just bridge it for you reliably |
|
| ▲ | ForHackernews 9 hours ago | parent | prev | next [-] |
| Cloudflare are setting themselves up as the arbiter who will decide which requests are a) human, b) authorized AI bots, c) illicit/banned bots. Given the number of people on HN who report massive problems from scrapers and other bots, it sounds like if Cloudflare doesn't do this, someone else will need to. I might have thought bandwidth was cheap enough now for it not to matter, but I guess the bots are costing some sites a lot of money. |
| |
| ▲ | timpera 9 hours ago | parent | next [-] | | Cloudflare seems to be very excited to eventually get a 30% cut on pay-to-crawl. As for the bots, I thought the same thing, but it is indeed a huge problem. They've brought my websites down pretty frequently recently. I tried Cloudflare but visitors complained, and I think you can't win against the bots anyway, so I've resorted to performance improvements and serving every request. | |
| ▲ | codingdave 3 hours ago | parent | prev | next [-] | | It isn't bandwidth that causes problems. It is the various types of load that they can add to your servers. Which is why no centralized vendor can decide the proper caching or what bots should be blocked, allowed, rate limited, etc. Those things do not have standard answers - it depends on what your apps do, your audience, their usage patterns, and sometimes the regulatory environment in which you run. | |
| ▲ | someonebaggy 8 hours ago | parent | prev [-] | | Cloudflare doesn't block bots. It's trivial to use residential proxies and your very obvious bot will only get blocked maybe 5% of the time when using rotating IPs. | | |
| ▲ | viraptor 7 hours ago | parent [-] | | They give you the tools. Your options are: - let more traffic in, eat the compute cost - block larger cohorts of traffic, affect many real users - babysit the rules to get them just right, lose time doing that In my experience the residential proxies exist but are not that common and many aren't trying as hard as they could. It's really a war of which side wants to spend more attention on the problem. | | |
| ▲ | someonebaggy 6 hours ago | parent [-] | | The last sentence is certainly true. Lazy bots you can block yourself and don't really need CF to help with. |
|
|
|
|
| ▲ | moralestapia 7 hours ago | parent | prev | next [-] |
| You tell us, you're the president of bonsai.io. Why would I use bonsai? Why not use ElasticSearch directly? |
|
| ▲ | tucnak 9 hours ago | parent | prev [-] |
| National security, bro. |