• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Another internet outage

Status
Not open for further replies.

trainmania100

Established Member
Joined
8 Nov 2015
Messages
3,031
Location
Newhaven
Sounds like there's another major internet outage happening at the moment.

Metro reports:
Multiple social media websites are down for thousands of users, including Facebook and X.

Issues with the platforms, which also include PayPal and ChatGPT, began at around 11.20am.

Several of the platforms have their servers hosted on Cloudflare, which provides tools to protect them from cyberattacks and allows sites to load content more quickly amid heavy traffic.

It also acts as a domain name server – a directory for websites and a tool tied to mass outages in recent months

Not that long ago, maybe a few years, another Cloud flare outage happened. Seems to be happening a lot lately.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

trainmania100

Established Member
Joined
8 Nov 2015
Messages
3,031
Location
Newhaven
Twice this morning the forum has failed to load for me with a Cloudflare error
Just been trying to bypass cloudflare for my site rail record but it's not loading at all. Unfortunately any security platform like this is subject to the occasional outage, Amazon AWS was only a few weeks ago..
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,790
Location
Epsom
It was Cloudfare again; seems to be back up now.

Screenshot below shows the error message off Twitter earlier:

1763469229906.png
 

TheGrew

Member
Joined
31 Jul 2012
Messages
511
Cloudflare offers a popular free service (alongside many paid ones!) that a number of websites use to protect against attacks.
Because many sites redirect their DNS to route traffic through them it isn't easy to change back as TTL values are not always observed and DNS caching would need to be flushed.
 

jfollows

Established Member
Joined
26 Feb 2011
Messages
10,075
Location
Wilmslow
With luck, more sites will stop using Cloudflare, it’s an obnoxious user experience.
 

Mike395

Forum Staff
Staff Member
Administrator
Joined
23 May 2009
Messages
3,379
Location
Bedford
With luck, more sites will stop using Cloudflare, it’s an obnoxious user experience.
The problem with that is - it's the most effective of the (generally) reliable, free, minimal-configuration firewall/caching setups you can get. We wouldn't be looking to move away any time soon realistically; whilst I acknowledge it has its flaws (not least as a single point of failure per yesterday), as a volunteer-run site where someone isn't available to monitor the server 24/7, being able to click a button and entirely block automated traffic from an IP/range/country (such that they can't even then reach the actual server) whilst still giving these users the option to complete a CAPTCHA if legitimate so as not to affect legitimate users too much is invaluable.

There is a problem sometimes where administrators haven't configured the firewall properly Cloudflare-side (e.g. just being lazy and leaving Under Attack mode on permanently!) but I like to think we get a reasonable balance here and Cloudflare isn't too noticeable for the majority.
 
Last edited:

jfollows

Established Member
Joined
26 Feb 2011
Messages
10,075
Location
Wilmslow
No, it’s generally fine for my use of this forum, but when it goes into CAPTCHA mode for other sites it times out far too quickly and ends up in an endless loop for the user daring to run a computer that isn’t fast enough.
 

Ediswan

Established Member
Joined
15 Nov 2012
Messages
3,415
Location
Stevenage
On the bright side, with every broken website I encountered, it was clear from what was displayed that the problem lay with Clouflare, so no time wasted looking elsewhere.
 

bleeder4

Member
Joined
19 Jan 2019
Messages
792
Location
Worcester
For those who are interested, Cloudflare have published an incident report on their blog:

I'm sure someone more techie than me will be able to interpret it better, but my understanding is that basically the anti-bot system couldn't connect to a file to check if users' IP addresses were legitimate, so it blocked the connection. To me, I would have thought that if the file was unavailable then the default action of the anti-bot system should be to accept the incoming connection, rather than reject it. (Innocent until proven guilty).
 
Joined
21 May 2014
Messages
959
I'm sure someone more techie than me will be able to interpret it better, but my understanding is that basically the anti-bot system couldn't connect to a file to check if users' IP addresses were legitimate, so it blocked the connection. To me, I would have thought that if the file was unavailable then the default action of the anti-bot system should be to accept the incoming connection, rather than reject it. (Innocent until proven guilty).

'Innocent until proven guilty' is the polar opposite of the cyber security principle of 'zero trust' - no user, no device, no connection is trusted until its safety can be proven.
 

ainsworth74

Forum Staff
Staff Member
Global Moderator
Joined
16 Nov 2009
Messages
31,067
Location
Redcar
'Innocent until proven guilty' is the polar opposite of the cyber security principle of 'zero trust' - no user, no device, no connection is trusted until its safety can be proven.
And kills the DDoS protection meaning that some sites that are protected from going down by malicious actors are suddenly unprotected. Reality is that denying the connections is the "fail safe" condition in this scenario even if it's annoying!
 

yorkie

Forum Staff
Staff Member
Administrator
Joined
6 Jun 2005
Messages
78,180
Location
Yorkshire
.... To me, I would have thought that if the file was unavailable then the default action of the anti-bot system should be to accept the incoming connection, rather than reject it. (Innocent until proven guilty).
Would I be right in guessing that you don't have experience of working in the area of internet security/computer networking?
 
Status
Not open for further replies.

Top