Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As this is a DNS based service, If I were a hacker, couldn't I just skip all the protection CloudFlare offers by hardwiring the website's domain + IP in my hosts file?


CloudFlare is actually a CDN proxy, so you could overcome this by hardwiring your web server firewall rules to the CloudFlare platform.


Ah, so basically use IPTables to detect if the request is originating from CloudFlare's CDN, and if it is not redirect it via CloudFlare?


No, you would configure your firewall to only allow requests from CloudFlare's infrastructure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: