Forum › Forums › Kafeneio Chats › In a Greek kafeneio › Cloudflare was down, live updates: Huge chunk of internet taken down by outage
- This topic has 17 replies, 8 voices, and was last updated Dec 4-4:33 pm by Brian Masinick.
-
AuthorPosts
-
November 18, 2025 at 5:28 pm #190632
Brian MasinickModeratorCloudflare was down, live updates: Huge chunk of internet taken down by outage
https://www.tomsguide.com/news/live/cloudfare-outage-november-2025-x-chatgptAbstract: Cloudfare experienced a global network outage, here’s the latest updates
Cloudflare, the global cloud network operating multiple websites on the internet, was down. The outage affected multiple platforms, including social media site X, ChatGPT, Uber and more.An initial spike of reports appeared on Down Detector around 6:30 am Eastern, though that quickly subsided. The real problems kicked off around 8:30 am and lasted until close to noon Eastern.
--
Brian Masinick
Alternate "Search B":
This search pageNovember 18, 2025 at 6:14 pm #190635Robin
MemberFunny part: Even down detector was down here due to the cloudflare issue. Do we now need a down detector down detector? 🙂
But worse for me was: leo.org dictionary was also down today, affected by cloudflare.dĂĽsseldorf. Meanwhile up again. I can understand small websites need the backing of huge infrastructure to protect for massive DDOS attacks, which they no longer can stem on their own, but if whole world uses a single protection service, this is a single point of failure, and also contradicts the original idea of decentralised structure of the internet. Easy to collect data if every site (or at least the majority of sites) uses this protection, so user is connected to the servers of this enterprise wherever he goes in the www.
Windows is like a submarine. Open a window and serious problems will start.
November 18, 2025 at 6:35 pm #190636
Brian MasinickModeratorMy last couple of jobs before retirement were with financial services companies who rely on the availability of their networks and services. One of them is a privately held company that sells financial investments. As far as I know they purchased direct access trunks, which I would have previously assumed meant just that, but who knows with the way this Cloud Flare stuff affected things. Is any service truly a dedicated service unless it has a hard block between it and other elements?
It would be interesting to find out more about that.
--
Brian Masinick
Alternate "Search B":
This search pageNovember 19, 2025 at 2:32 am #190642
sybokMemberDespite
growing oldermaturing I (somewhat) remain to be a naive chump that expects the companies designing web-pages (and their large-customers such as governments) do some tests about unavailability of components loaded by their web pages and minimising the number of these components to minimum.
This is e.g. to avoid government web-pages inaccessible because of Google captcha or Google fonts not loadable etc.
Also, it would avoid Covid-vaccination registration web-pages not send private data via Google analytics.Nah, too much work to code without it…
Besides, these Google, CloudFlare, Amazon AWS corporations are too big to fail… right?November 19, 2025 at 7:31 am #190654
Brian MasinickModeratorDespite
growing oldermaturing I (somewhat) remain to be a naive chump that expects the companies designing web-pages (and their large-customers such as governments) do some tests about unavailability of components loaded by their web pages and minimising the number of these components to minimum.
This is e.g. to avoid government web-pages inaccessible because of Google captcha or Google fonts not loadable etc.
Also, it would avoid Covid-vaccination registration web-pages not send private data via Google analytics.Nah, too much work to code without it…
Besides, these Google, CloudFlare, Amazon AWS corporations are too big to fail… right?I’m often naive too, despite being retired. Nevertheless, when it comes to stuff like this, the way I’ve designed my own backup and usage strategy, while certainly using the services above, I try in many ways NOT to rely on only one thing. This means, for example, EVEN when no networking at all is available, I CAN do certain things. For example, if I want to write something, I still have text editors that are NOT in the Cloud, though I have some of both. I can’t get on the network when it’s not working but I can still use my systems for other things.
As far as companies go, using Cloud-based services as ONE of their mechanisms is fine, RELYING UPON Cloud-based services to manage the entire network infrastructure is clearly ridiculous, as we have seen multiple times already. Just this year alone, and the year is not over yet, Amazon’s AWS has had a major outage like this CloudFlare outage, and for CloudFlare, I think this is the THIRD major outage they’ve had in the past ten years. That wouldn’t be a horrible record, EXCEPT that so much relies on this stuff, so it’s an unacceptable record. Any “you bet your business” infrastructure MUST have multiple ways to remain running, so if they use ONLY one technology, EVEN if it’s replicated, that’s a BAD idea indeed. Same for any other providers.
Why they can’t have combinations of Satellite, Microwave, Ethernet, and copper wired physical networks and the same number of choices for their software implementation is beyond me. One of the financial services companies I worked for went to extremes to keep their services running, multiple key sites, even multiple continent backups if stuff failed provisions for hurricanes, volcanoes, and other natural disasters, but if they too rely on these kinds of networks without their own way to circumvent this, they too are affected, so if they DID get caught I’d be willing to bet that they’ll come up with (or already have) a mitigation strategy for stuff like this! There’s too much business at stake to not have alternatives!
--
Brian Masinick
Alternate "Search B":
This search pageNovember 19, 2025 at 7:45 am #190655
Brian MasinickModeratorOh by the way, I DO remember Hurricane Helene, which came INLAND last year and took out many things in our area. For a storm that technically was no longer a hurricane because the winds were slightly below 74 miles per hour (they were 50-60 MPH in sustained winds), that storm brought enough wind and rain to down trees and power lines all over the place and brought destruction all the way from the Atlantic Ocean’s “Gulf of Mexico”, through many southern states, then to the North through parts of Ohio, then it finally veered to the East and eventually back toward the Atlantic.
I don’t know too much about what it did when it got North, but my sister lives about five miles from the Ohio/Kentucky border (which is the Ohio River), and it knocked over a tree on her property, barely avoiding serious damage.
As for us, we were without power across most of our campus, except for the few rooms that did have auxiliary power, so most of us gathered in those places and had much more person to person contact than usual, so in that regard it was good; millions of dollars of damage across a three state region within a couple of hours of us, and there is one interstate highway, I-40 in Tennessee that still has lane closures – an entire cliff edge fell off there, so that one isn’t a quick fix at all! You can get through there, but to this day there are still lane limitations!
So we always have to be careful about weather, the networks we use, and many other things. A few disasters, whether from weather, closed or destroyed services or other factors can seriously disrupt every day activities. It’s always necessary to have other ways to do things; otherwise the impact is quite obvious, even to the naive among us!
--
Brian Masinick
Alternate "Search B":
This search pageNovember 19, 2025 at 8:00 am #190657
sybokMemberOne of the good things useful to keep stored on PC (or in human memory) is how to change DNS and the IPs of the alternate DNS.
EDIT: Or have a fixed-IP server in a local-network with working DNS.
- This reply was modified 10 months, 1 week ago by sybok.
November 19, 2025 at 8:55 am #190661stevesr0
MemberI am familiar with selecting dns supplier in web browser and there are “slots” for two choices.
Makes sense to select two different “vendors”, such as Cloudflare and (say) Google to maximize chance of avoiding problem?
November 19, 2025 at 12:25 pm #190669
Brian MasinickModeratorI am familiar with selecting DNS supplier in web browser and there are “slots” for two choices.
Makes sense to select two different “vendors”, such as CloudFlare and (say) Google to maximize chance of avoiding problem?
The thing is, I don’t know if CloudFlare serves Google, Amazon AWS and Google, or if all three have their own physical services but it’s quite clear that CloudFlare has a controlling hand over a huge amount of network features because it affected, for all intents and purposes the entire Internet.
Now whether that is literally true or not, from a practical standpoint my local ISP was seriously affected; in our case that meant wireless phone service, Internet and television signals. That’s pretty big. Also, while the “outage” as CloudFlare considers it, and the total length of the disruption, was about half a day rather than “just” an hour or two. By the time things were back to “normal”, in my area it was after noon! Also, even when stuff was “better”, an example of the ripple effect: my wife has certain afternoon shows and evening shows that she records so that she can skip around content she doesn’t need to see. Even into the EVENING there was an after effect!
I was able to watch a basketball game on my tablet and for the most part that went well, yet near the end of the game, there were a few blips or delays; they may not have had anything directly to do with the outage, but given the number of hours the outage affected things, indirectly it may have been because of people catching up with things they couldn’t do 10-12 hours earlier.
--
Brian Masinick
Alternate "Search B":
This search pageNovember 19, 2025 at 1:20 pm #190672
vitforlinuxMemberI have a little program in bash that sets the DNS in /etc/resolv.conf and make chattrib +i. Some might consider it harmful because it doesn’t do backups, and I have to modify it because echo -e should no longer be used.
However when I want to change DNS it’s quite easy for me, but due to my limited bash programming skills it can’t go back to the original link.
$ cat /etc/resolv.conf nameserver 86.54.11.13My european DNS
Sorry for my spaghetti english, i'm italian. Happy XORG user. GNOME? No thanks!
November 19, 2025 at 8:00 pm #190684Robin
MemberMy european DNS
If you want censorship-free and non-logging dns, rather use something like 5.9.164.112 / 2a01:4f8:251:554::2 (digital courage) or 5.1.66.255 / 185.150.99.255 / 2001:678:e68:f000:: / 2001:678:ed0:f000:: (ffmuc.net)
$ cat /etc/resolv.conf
If you set the external dns servers already in you Internet Router instead of the default DNS automatically assigned by your ISP, you can set in antiX the IP address of your local router as DNS simply, no need to reconfigure all devices on their own.
Unfortunately only very recent routers can do DoT (RFC 7858), and if you want to have it (the digital courage DNS server from above demands it), you need to configure your devices individually again, so you can enter the needed ingredients.
But I have not seen a way to configure connman to use DoT (RFC 7858), there is no entry field in the cmst GUI for the required port (853) nor for the sha256 SPKI pinset. So most likely connman can’t do that. You may try to run stubby or unbound instead, and point connman to this locally running DoT client as DNS. Have not tested myself that setup yet. If somebody already has experience with DoT on antiX, please bark up.
Windows is like a submarine. Open a window and serious problems will start.
November 20, 2025 at 2:29 am #190685
xinomiloMemberanother european provider, free, with no-log policy :
https://libreops.cc/radicaldns.html
also running DoT/DoH on : https://libredns.gr/First they came for the socialists, and I did not speak out—because I was not a socialist.
Then they came for the trade unionists, and I did not speak out—because I was not a trade unionist.
Then they came for the Jews, and I did not speak out—because I was not a Jew.
Then they came for me—and there was no one left to speak for me.—Martin Niemöller
November 20, 2025 at 5:31 am #190686
vitforlinuxMemberMy little program in bash is “multi distro” and I have to change /etc/resolv.conf because I use netguard, and my phone gives me thetering but doesn’t resolve the DNS… I have a strange life, I change the DNS on a whim, just for operational reasons.
Sorry for my spaghetti english, i'm italian. Happy XORG user. GNOME? No thanks!
November 20, 2025 at 5:03 pm #190710stevesr0
MemberRe: slowdowns.
My systems seem to be sending and receiving from the internet slowly. Haven’t tried pinging Google or Couldflare yet (just thought of it).
December 4, 2025 at 3:56 pm #191440booker
Membernobody with dnscrypt , dnssec?
-
AuthorPosts
- You must be logged in to reply to this topic.