Cloudflare was down, live updates: Huge chunk of internet taken down by outage

Forum › Forums › Kafeneio Chats › In a Greek kafeneio › Cloudflare was down, live updates: Huge chunk of internet taken down by outage

  • This topic has 17 replies, 8 voices, and was last updated Dec 4-4:33 pm by Brian Masinick.
Viewing 15 posts - 1 through 15 (of 18 total)
  • Author
    Posts
  • #190632
    Brian Masinick
    Moderator

      Cloudflare was down, live updates: Huge chunk of internet taken down by outage
      https://www.tomsguide.com/news/live/cloudfare-outage-november-2025-x-chatgpt

      Abstract: Cloudfare experienced a global network outage, here’s the latest updates
      Cloudflare, the global cloud network operating multiple websites on the internet, was down. The outage affected multiple platforms, including social media site X, ChatGPT, Uber and more.

      An initial spike of reports appeared on Down Detector around 6:30 am Eastern, though that quickly subsided. The real problems kicked off around 8:30 am and lasted until close to noon Eastern.

      --
      Brian Masinick
      Alternate "Search B":
      This search page

      #190635
      Robin
      Member

        Funny part: Even down detector was down here due to the cloudflare issue. Do we now need a down detector down detector? 🙂

        But worse for me was: leo.org dictionary was also down today, affected by cloudflare.dĂĽsseldorf. Meanwhile up again. I can understand small websites need the backing of huge infrastructure to protect for massive DDOS attacks, which they no longer can stem on their own, but if whole world uses a single protection service, this is a single point of failure, and also contradicts the original idea of decentralised structure of the internet. Easy to collect data if every site (or at least the majority of sites) uses this protection, so user is connected to the servers of this enterprise wherever he goes in the www.

        Windows is like a submarine. Open a window and serious problems will start.

        #190636
        Brian Masinick
        Moderator

          My last couple of jobs before retirement were with financial services companies who rely on the availability of their networks and services. One of them is a privately held company that sells financial investments. As far as I know they purchased direct access trunks, which I would have previously assumed meant just that, but who knows with the way this Cloud Flare stuff affected things. Is any service truly a dedicated service unless it has a hard block between it and other elements?

          It would be interesting to find out more about that.

          --
          Brian Masinick
          Alternate "Search B":
          This search page

          #190642
          sybok
          Member

            Despite growing oldermaturing I (somewhat) remain to be a naive chump that expects the companies designing web-pages (and their large-customers such as governments) do some tests about unavailability of components loaded by their web pages and minimising the number of these components to minimum.
            This is e.g. to avoid government web-pages inaccessible because of Google captcha or Google fonts not loadable etc.
            Also, it would avoid Covid-vaccination registration web-pages not send private data via Google analytics.

            Nah, too much work to code without it…
            Besides, these Google, CloudFlare, Amazon AWS corporations are too big to fail… right?

            #190654
            Brian Masinick
            Moderator

              Despite growing oldermaturing I (somewhat) remain to be a naive chump that expects the companies designing web-pages (and their large-customers such as governments) do some tests about unavailability of components loaded by their web pages and minimising the number of these components to minimum.
              This is e.g. to avoid government web-pages inaccessible because of Google captcha or Google fonts not loadable etc.
              Also, it would avoid Covid-vaccination registration web-pages not send private data via Google analytics.

              Nah, too much work to code without it…
              Besides, these Google, CloudFlare, Amazon AWS corporations are too big to fail… right?

              I’m often naive too, despite being retired. Nevertheless, when it comes to stuff like this, the way I’ve designed my own backup and usage strategy, while certainly using the services above, I try in many ways NOT to rely on only one thing. This means, for example, EVEN when no networking at all is available, I CAN do certain things. For example, if I want to write something, I still have text editors that are NOT in the Cloud, though I have some of both. I can’t get on the network when it’s not working but I can still use my systems for other things.

              As far as companies go, using Cloud-based services as ONE of their mechanisms is fine, RELYING UPON Cloud-based services to manage the entire network infrastructure is clearly ridiculous, as we have seen multiple times already. Just this year alone, and the year is not over yet, Amazon’s AWS has had a major outage like this CloudFlare outage, and for CloudFlare, I think this is the THIRD major outage they’ve had in the past ten years. That wouldn’t be a horrible record, EXCEPT that so much relies on this stuff, so it’s an unacceptable record. Any “you bet your business” infrastructure MUST have multiple ways to remain running, so if they use ONLY one technology, EVEN if it’s replicated, that’s a BAD idea indeed. Same for any other providers.

              Why they can’t have combinations of Satellite, Microwave, Ethernet, and copper wired physical networks and the same number of choices for their software implementation is beyond me. One of the financial services companies I worked for went to extremes to keep their services running, multiple key sites, even multiple continent backups if stuff failed provisions for hurricanes, volcanoes, and other natural disasters, but if they too rely on these kinds of networks without their own way to circumvent this, they too are affected, so if they DID get caught I’d be willing to bet that they’ll come up with (or already have) a mitigation strategy for stuff like this! There’s too much business at stake to not have alternatives!

              --
              Brian Masinick
              Alternate "Search B":
              This search page

              #190655
              Brian Masinick
              Moderator

                Oh by the way, I DO remember Hurricane Helene, which came INLAND last year and took out many things in our area. For a storm that technically was no longer a hurricane because the winds were slightly below 74 miles per hour (they were 50-60 MPH in sustained winds), that storm brought enough wind and rain to down trees and power lines all over the place and brought destruction all the way from the Atlantic Ocean’s “Gulf of Mexico”, through many southern states, then to the North through parts of Ohio, then it finally veered to the East and eventually back toward the Atlantic.

                I don’t know too much about what it did when it got North, but my sister lives about five miles from the Ohio/Kentucky border (which is the Ohio River), and it knocked over a tree on her property, barely avoiding serious damage.

                As for us, we were without power across most of our campus, except for the few rooms that did have auxiliary power, so most of us gathered in those places and had much more person to person contact than usual, so in that regard it was good; millions of dollars of damage across a three state region within a couple of hours of us, and there is one interstate highway, I-40 in Tennessee that still has lane closures – an entire cliff edge fell off there, so that one isn’t a quick fix at all! You can get through there, but to this day there are still lane limitations!

                So we always have to be careful about weather, the networks we use, and many other things. A few disasters, whether from weather, closed or destroyed services or other factors can seriously disrupt every day activities. It’s always necessary to have other ways to do things; otherwise the impact is quite obvious, even to the naive among us!

                --
                Brian Masinick
                Alternate "Search B":
                This search page

                #190657
                sybok
                Member

                  One of the good things useful to keep stored on PC (or in human memory) is how to change DNS and the IPs of the alternate DNS.

                  EDIT: Or have a fixed-IP server in a local-network with working DNS.

                  • This reply was modified 10 months, 1 week ago by sybok.
                  #190661
                  stevesr0
                  Member

                    I am familiar with selecting dns supplier in web browser and there are “slots” for two choices.

                    Makes sense to select two different “vendors”, such as Cloudflare and (say) Google to maximize chance of avoiding problem?

                    #190669
                    Brian Masinick
                    Moderator

                      I am familiar with selecting DNS supplier in web browser and there are “slots” for two choices.

                      Makes sense to select two different “vendors”, such as CloudFlare and (say) Google to maximize chance of avoiding problem?

                      The thing is, I don’t know if CloudFlare serves Google, Amazon AWS and Google, or if all three have their own physical services but it’s quite clear that CloudFlare has a controlling hand over a huge amount of network features because it affected, for all intents and purposes the entire Internet.

                      Now whether that is literally true or not, from a practical standpoint my local ISP was seriously affected; in our case that meant wireless phone service, Internet and television signals. That’s pretty big. Also, while the “outage” as CloudFlare considers it, and the total length of the disruption, was about half a day rather than “just” an hour or two. By the time things were back to “normal”, in my area it was after noon! Also, even when stuff was “better”, an example of the ripple effect: my wife has certain afternoon shows and evening shows that she records so that she can skip around content she doesn’t need to see. Even into the EVENING there was an after effect!

                      I was able to watch a basketball game on my tablet and for the most part that went well, yet near the end of the game, there were a few blips or delays; they may not have had anything directly to do with the outage, but given the number of hours the outage affected things, indirectly it may have been because of people catching up with things they couldn’t do 10-12 hours earlier.

                      --
                      Brian Masinick
                      Alternate "Search B":
                      This search page

                      #190672
                      vitforlinux
                      Member

                        I have a little program in bash that sets the DNS in /etc/resolv.conf and make chattrib +i. Some might consider it harmful because it doesn’t do backups, and I have to modify it because echo -e should no longer be used.

                        However when I want to change DNS it’s quite easy for me, but due to my limited bash programming skills it can’t go back to the original link.

                        $ cat /etc/resolv.conf 
                        nameserver 86.54.11.13

                        My european DNS

                        Sorry for my spaghetti english, i'm italian. Happy XORG user. GNOME? No thanks!

                        #190684
                        Robin
                        Member

                          My european DNS

                          If you want censorship-free and non-logging dns, rather use something like 5.9.164.112 / 2a01:4f8:251:554::2 (digital courage) or 5.1.66.255 / 185.150.99.255 / 2001:678:e68:f000:: / 2001:678:ed0:f000:: (ffmuc.net)

                          $ cat /etc/resolv.conf

                          If you set the external dns servers already in you Internet Router instead of the default DNS automatically assigned by your ISP, you can set in antiX the IP address of your local router as DNS simply, no need to reconfigure all devices on their own.

                          Unfortunately only very recent routers can do DoT (RFC 7858), and if you want to have it (the digital courage DNS server from above demands it), you need to configure your devices individually again, so you can enter the needed ingredients.

                          But I have not seen a way to configure connman to use DoT (RFC 7858), there is no entry field in the cmst GUI for the required port (853) nor for the sha256 SPKI pinset. So most likely connman can’t do that. You may try to run stubby or unbound instead, and point connman to this locally running DoT client as DNS. Have not tested myself that setup yet. If somebody already has experience with DoT on antiX, please bark up.

                          Windows is like a submarine. Open a window and serious problems will start.

                          #190685
                          xinomilo
                          Member

                            another european provider, free, with no-log policy :
                            https://libreops.cc/radicaldns.html
                            also running DoT/DoH on : https://libredns.gr/

                            First they came for the socialists, and I did not speak out—because I was not a socialist.
                            Then they came for the trade unionists, and I did not speak out—because I was not a trade unionist.
                            Then they came for the Jews, and I did not speak out—because I was not a Jew.
                            Then they came for me—and there was no one left to speak for me.

                            —Martin Niemöller

                            #190686
                            vitforlinux
                            Member

                              My little program in bash is “multi distro” and I have to change /etc/resolv.conf because I use netguard, and my phone gives me thetering but doesn’t resolve the DNS… I have a strange life, I change the DNS on a whim, just for operational reasons.

                              Sorry for my spaghetti english, i'm italian. Happy XORG user. GNOME? No thanks!

                              #190710
                              stevesr0
                              Member

                                Re: slowdowns.

                                My systems seem to be sending and receiving from the internet slowly. Haven’t tried pinging Google or Couldflare yet (just thought of it).

                                #191440
                                booker
                                Member

                                  nobody with dnscrypt , dnssec?

                                Viewing 15 posts - 1 through 15 (of 18 total)
                                • You must be logged in to reply to this topic.