• VivianRixia@piefed.social
    link
    fedilink
    English
    arrow-up
    103
    ·
    8 months ago

    It just means the internet is built on a very flimsy stack of technologies and any of them failing causes huge downstream issues. We saw that with AWS, and now with Cloudflare.

    It’s only concerning if there are no alternatives, but as it stands there are other companies that all of these websites could have done a failover to when both AWS or Cloudflare went down. But they decided that their websites having a single point of failure was worth the risk over paying for having a proper backup system ready to go.

  • gedaliyah@lemmy.world
    link
    fedilink
    arrow-up
    54
    ·
    8 months ago

    I remember experts saying 5 or 10 years ago that the increased standardization and centralization of the internet would lead to more frequent and widespread internet blackouts.

    First AWS, and now this. It looks like they’re right.

    • RememberTheApollo_@lemmy.world
      link
      fedilink
      arrow-up
      26
      arrow-down
      1
      ·
      8 months ago

      Two things happen when we centralize. Doesn’t matter if it’s big business or infrastructure.

      1. Profits go up for the controlling few

      2. consumers get fucked.

      We get fucked when things go wrong, the system fails, our data gets hacked, our power goes out, our rents go up, insurance rates go up… etc etc. MegaCorps all say sorry, give us 50¢ off our next purchase and a free credit check, and carry on while we eat the losses and increasing costs.

    • jaybone@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 months ago

      What’s the fear there, that they would figure out what domain names you are resolving?

      • Hazor@lemmy.world
        link
        fedilink
        arrow-up
        8
        ·
        8 months ago

        I’m guessing the concern would be resolving them to the wrong address, either to censor or to serve disinformation.

      • Valmond@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        8 months ago

        Try to do secure communication without that sweet domain mame… You can’t!

        My thoughts is that they feel the need to control everything. And we all know how that goes usually…

  • socsa@piefed.social
    link
    fedilink
    English
    arrow-up
    31
    arrow-down
    3
    ·
    edit-2
    8 months ago

    .

    Edit - cloudflare now says it was a misconfigured config, not a DOS attack as they initially reported

      • socsa@piefed.social
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        1
        ·
        8 months ago

        Most of the reporting I have seen suggests a massive traffic spike. Do you have some more information about the config file?

    • wellheh@lemmy.sdf.org
      link
      fedilink
      arrow-up
      5
      ·
      8 months ago

      “30 minutes”- me when I lie on the internet. Where did you get that number? You realize we can check the news and see that big sites like x and chatgpt were down like 4 hours? Not only that, they said themselves it was not an attack but a misconfiguration. News were reporting it fixed around evening utc while the issue popped up around noon. That’s not a 30 min outage and is a huge failure.

  • DFX4509B@lemmy.wtf
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    1
    ·
    edit-2
    8 months ago

    The fact that Cloudflare controls half the web is concerning both for unintentional crashes like this, and for something even more insidious; what if they’re coerced to cause an intentional outage should cyber war ever break out? An intentional outage for half the web in a cyber war would be devastating to put it nicely.

  • mechoman444@lemmy.world
    link
    fedilink
    arrow-up
    21
    ·
    8 months ago

    You know back in my day websites would protect themselves, as was the style at the time.

    Now a days they just get cloudflare and put up a cookie notice.

    Just one of those things lazy devs do.

    • Evotech@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      8 months ago

      Why reinvent the wheel.

      It’s not lazy, they just spend that time on other features.

      The Internet is way more secure today, partially because of centralised security efforts. Like if a site is behind Cloudflare you might aswell just not try.

    • Ninjasftw@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      8 months ago

      Well the average website isn’t going to be able to protect itself from DDoS attacks or easily provide local cache copies of its content in multiple regions all over the world or create secured tunnels protected from general attacks. My company was affected by this and we are putting in contingency plans for this happening again but the whiteboard that we’ve created with all the features we need to reinvent is very full…

  • 9point6@lemmy.world
    link
    fedilink
    arrow-up
    15
    ·
    8 months ago

    Being a good CDN is an expensive exercise that requires the ability to run POPs in many countries around the world.

    Cloudflare captured the market by basically being simultaneously much cheaper, better distributed and ultimately better performing than the incumbents at the time (Akamai and Limelight IIRC)

    The rest of the story is capitalism doing capitalist things

  • BarneyPiccolo@lemmy.today
    link
    fedilink
    arrow-up
    14
    ·
    8 months ago

    There was the Crowdstrike failure that tangled the airports last year, and the AWS outage that took out half the Internet just a few weeks ago. It seems like some one might be probing for vulnerabilities. One day, EVERYTHING might go down, for a while.

    We’ll get a chance to find out what it was like to read a book instead of a screen.

  • northernlights@lemmy.today
    link
    fedilink
    arrow-up
    11
    ·
    8 months ago

    I find it at least concerning for CloudFlare’s change control process. Apparently some new traffic analysis config took half the web? Maybe test things a little more?

  • iii@mander.xyz
    link
    fedilink
    English
    arrow-up
    8
    ·
    8 months ago

    It’s good that it goes down once in a while, so that people notice.

  • StrawberryPigtails@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    8
    ·
    8 months ago

    How does one company have that much impact?

    Because they are a very good CDN and provide excellent DDos protection. They then expanded to do a whole host of other things, to the point where they do pretty much everything. Basically, they have become the first name most folks think of when they want to put something on the internet. A one stop shop for your web hosting needs. Wouldn’t surprise me to learn they rent servers and VPS’s as well.

    Been seeing it in the selfhosting communities and subreddits for a while now. “Oh I want to put this selfhosted service on the internet. I should put it behind Cloudflare!” Most of the time it’s not needed in that context.

    Do you think that’s concerning?

    Well, they did just take out “half” of the internet today so… In general, if it seems like “everyone” is using a single service, it’s probably a good idea to see if an alternative exists and will suit your needs. Which reminds me, I should probably start looking for a replacement for Tailscale. They’re starting to look a bit like Cloudflare to me, in the sense that “everyone”, including myself tends to recommend them as a VPN.

  • higgsboson@piefed.social
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    8 months ago

    I mean… not only is it not very concerning, I barely noticed. If not for news about it here on fediverse, I might not have known. I guess I dont visit the corpo internet all that much.

    • KaChilde@sh.itjust.works
      link
      fedilink
      arrow-up
      5
      ·
      8 months ago

      I have been concerned recently that despite my best efforts I am still too attached to the corporately owned internet.

      The fact that I felt no impact from this was a nice treat to start my week.

  • Valmond@lemmy.world
    link
    fedilink
    arrow-up
    7
    ·
    8 months ago

    So, and I’m gonna pull my shameless plug ofc, but what about a decentralised internet?

    Check out tenfingers or the sub (I put the weblink, is it !lemmy.world/c/tenfingers on lemmy browser apps?).

    What about we take the internet back?

    • BluesF@lemmy.world
      cake
      link
      fedilink
      arrow-up
      2
      ·
      8 months ago

      This seems interesting but I struggle to see how it helps, seems more like its for file sharing. Or is the suggestion that it could form the host side of a web ecosystem, with files for websites hosted in this decentralised way?

      • Valmond@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        8 months ago

        Exactly.

        File sharing, a chat, backup systems, are just the low hanging fruit IMO. You can make a takedown safe “web” presence, with whatever you want on it. Decentralised, accessible with your PC off. And FOSS.

        You can try it out, the new “web” WIP, if you have a couple of minutes and access yo a PC (Linux works, would love to get feedback from other platforms).