• 0 Posts
  • 14 Comments
Joined 7 months ago
cake
Cake day: December 7th, 2023

help-circle




  • The costs are definitely a huge consideration and need to be optimized. A few years back we ran a POC of Open Shift in AWS that seemed to idle at like $3k/mo with barely anything running at all. That was a bad experiment. I could compare that to our new VMWare bill, which more than doubled this year following the Broadcom acquisition.

    The products in AWS simplify costs into an opex model unlike anything that exists on prem and eliminate costly and time consuming hardware replacements. We just put in new load balancers recently because our previous ones were going EoL. They were a special model that ran us a about a half-mil for a few HA pairs including the pro services for installation assistance. How long will it take us to hit that amount using ALBs in AWS? What is the cost of the months that it took us to select the hardware, order, wait 90 days for delivery, rack-power-connect, configure with pro services, load hundreds of certs, gather testers, and run cutover meetings? What about the time spent patching for vulnerabilities? In 5-7 years it’ll be the same thing all over again.

    Now think about having to do all of the above for routers, switches, firewalls, VM infra, storage, HVAC, carrier circuits, power, fire suppression.



  • The core features of a WAF do require SSL offload, which of course means that the data needs to be unencrypted with your certificate on their edge nodes, then re-encrypted with your origin certificates. There is no other way in a WAF to protect from these exploits if the encryption is not broken, and WAF vendors can respond much faster than developers can to put protections in place for emerging threats.

    I had never considered that Akamai or Cloudflare would be doing any deeper analytics on our data, as it would open them up to significant liability, same as I know for certain that AWS employees cannot see the data within our buckets.

    As for the captcha prompts, I can’t speak to how those work in Cloudflare, though I do know that the AWS WAF does leave the sensitivity of the captcha prompts entirely up to the website owner. For free versions of CF there might be fewer configurable options.


  • MSids@lemmy.worldtoTechnology@lemmy.worldCloudflare launches a tool to combat AI bots
    link
    fedilink
    English
    arrow-up
    10
    arrow-down
    1
    ·
    edit-2
    12 days ago

    Can you educate me on the negatives of Cloudflare?

    My company is on Akamai, who has a pretty solid combined offering of WAF, DNS, and CDN, and yet I still feel like their platform is antiquated and well overdue for a refresh.

    Thinking back to log4j, it was cloudflare who had the automatic protections in place well ahead of Akamai, who we had to ask for custom filters. Cloudflare also puts out many articles on Internet events and increase adoption of emerging best practices, sometimes through heavy shaming.


  • MSids@lemmy.worldtopolitics @lemmy.worldBiden Must Resign
    link
    fedilink
    arrow-up
    5
    arrow-down
    3
    ·
    edit-2
    12 days ago

    Do you really look at him and think he’s the best person to continue running the country? Look at what happened with RBG, who died in office allowing Republicans to load the supreme court with judges who are objectively bad.

    Biden was fine and all, but it’s starting to feel like Weekend at Bernies. Better democrat candidates exist.

    Edit: I get the down votes, but the truth is that it’s a real concern and confidence is waning. Voters need to be excited and feel confident in their candidate or the turnout will suffer like it did with Hillary. Right or wrong it’s the truth. Strategy is important even if it means making hard uncomfortable decisions.






  • When I worked at an internet provider, Netflix sent us a cache (I’m sure they have several at that ISP now). I can’t imagine it cost them more than a few thousand dollars, as it was just a bare bones box full of hard drives. We gave them free power, internet, and rack space in our data center. Every night during the slow period it would fill up with whatever they thought would stream the next day.

    There was nothing to do with neighborhoods, the cache served customers all over Maine and they didn’t pay us anything. Netflix’s costs are more likely content and licensing.