Cloudflare Drop(cloudflare.com) |
Cloudflare Drop(cloudflare.com) |
And then sell its denizens malice protection services.
I want to push. And then edit. Commit. And push again.
I tried uploading a git repository that I have previously successfully published on Github pages. This is a "no build" website I have built with the help of Claude. It should just work but I keep getting an error. Who can I reach out to give them steps to reproduce? The website repository is public and I feel like anyone at Cloudflare who wants to reproduce my problem can quite literally clone my repo and upload it to cloudflare drop.
Please drop your cloudflare email address and I will reach out to you with my repository information.
Kevlar:
https://developers.cloudflare.com/bots/ https://www.cloudflare.com/products/turnstile/
Guns:
https://support.cloudflarewarp.com/
To be fair, CF mainly develops defensive cybersecurity products, the extent to which their tools might be used maliciously is pretty on par with other regular tools.
But, it just has bad optics and potential COI/Racketeering when CF is at both sides of the counter.
To be explicit, in case it isn't obvious,Cloudflare emerged as a DDoS protection company, detecting attacks from distributed sources is part of the raison d'etre, and domains and IP addresses are a key part of that infrastructure.
By subletting their own IP addresses for navigation with warp, and their own domains for hosting of webcontent with subdomain hosting, they are providing pooled anonimity for their customers, which is precisely what makes it very hard for defenders on the other side to implement foundational security measures like IP bans, or IP block bans, or domain bans, or Whois/RDAP domain analysis.
Is this a product or what? What's the purpose? Is there an API?
I ended up just embedding them directly in the HTML as base64 and sending him a 15mb file, but hypothetically this would have been a nice solution instead.
However, I see the appeal of this. Kind of surprised it hasn't happened yet to be honest.
you can check it out here: https://github.com/Amal-David/pagecast
"Something went wrong An unexpected error occurred. Please try again or contact support."
I'm definitely keeping an eye on them to see if it works out for them. And if I will need to start routing around them to sleep easily at night.
- drop my html into Cloudflare drop
- setup a CNAME DNS for my domain to point at cloudflare URL
- profit
?
If cloudflare wants to be the next "Megaupload" what business is it of yours?
There is a guy named kim DOT com. That is actually fucking cool. Whether or not he himself is actually cool. Or in prison.
https://news.ycombinator.com/item?id=48808481
https://github.com/SpeedcubeDE/speedcube.de-forum-archive is an example use case.
Sort of, but not quite, like cherry-picking files out of an archive blob in S3.
(I’ll see if Claude and I can come up with a WARC archive->zip file converter too)
Good to see great ideas making a comeback
Requires the server's sshd config to have GatewayPorts yes, or the server will bind to 127.0.0.1 instead
Here's the instructions my agents have:
> Shareable Deliverables → jlnk.us (default) The jlnk MCP server is configured machine-wide for all team agents. It publishes disposable public links: create_link(content, ttl) returns an unguessable URL anyone can open without logging in; it self-destructs after its TTL (4h/24h/72h, default 4h, max 5 MB). Also list_my_links() and delete_link(id).
> When handing a human (Founder, CEO reviewer) something to look at — QC screenshots, prototypes, reports, before/after comparisons — default to a jlnk.us link instead of a repo file path or local path. Use 72h for Founder review, shorter when the review window is same-day.
> Content must be ONE self-contained HTML file: inline CSS/JS, embed screenshots as base64 data URIs ().
> Downscale images to stay under the 5 MB cap.
> Links are public to anyone holding the URL. NEVER publish secrets, API keys, credentials, or private client data.
> Links expire — they are a viewing convenience, not the system of record. Durable artifacts still go to the repo and issue attachments as usual.
Creating a folder for some files. Dude, maybe you should file for disability for repetetive stress disorder for "double clicking" or even single clicking twice.
This aggression will not STAND man!
We need computers to go back to pencil and paper but STILL be computers! But not operated by me? Wierd operated by a fake bot me? Wait! thats malware! Wha?
By submitting, posting, or publishing your content, suggestions, enhancement requests, recommendations, feedback, information, data, or comments (“Content”) to any Website or Online Service, you are granting Cloudflare a perpetual, irrevocable, worldwide, non-exclusive, royalty-free right and license (with the right to sublicense) to use, incorporate, exploit, display, perform, reproduce, distribute, and prepare derivative works of your Content.
If you're ok with that, fine. But I'm not.
You do not need all that.
This is standard boilerplate for hosting companies so they don't run into issues putting your content on distributed CDNs, or if things are in their logs, etc.
https://vercel.com/legal/terms#feedback
https://fly.io/legal/terms-of-service/#2-ownership
https://www.netlify.com/legal/terms-of-use/#3-your-content
I want to be mad at Cloudflare as much as the next person, but Vercel, Netlify, Fly.io all have the same "legal-ese". I don't agree with it and it feels overly broad, but it seems hosting companies, at least US based ones, all have this same standard boilerplate around your content.
I hate AI with every fiber of my being. Yes, there are a few areas where it's beneficial, but in total it's a disaster for us. I don't need to get further into that discussion here as it's irrelevant to the initial topic.
Have a good day!
Not sure why cloudflare seems to be in such good standing on hn.
Clear red flag, only useful for whistleblowers.
Wouldn't it be fun to upload content of a big music label or smth like that?
Is this some "smart" way to get the Books2 dataset and claim it was uploaded by its owners?
We need these legal texts as short form TikTok content I am afraid.
Nobody except lawyers should have to bother with legalese.
https://nedroidcomics.tumblr.com/post/41879001445/the-intern...
You are now making me rethink using any of Cloudflare's tech. I need to go and read the fine print for their DNS (1.1.1.1). I also wonder what their Turnstile conditions are being imposed on all of us.
That sort of condition is disgusting.
https://developers.cloudflare.com/changelog/post/2026-07-08-...
But that won't stop people doing bad stuff for an hour I guess. Vibe code up some on-demand thing that you ping...
https://blog.cloudflare.com/a-simpler-path-to-a-safer-intern...
I have no idea what guardrails they have in place in the background that blocks malware, CSAM, warez and such on their free accounts.
Somewhat useful if you want a url that isn't a hash / is more self descriptive.
[1] Launch discussion: https://news.ycombinator.com/item?id=36296695
[2] This was a demo of the output of a design tool I'm working on, only the home/accommodations/about pages work.
That at least would bring back local bank branches at least. And movie rentals by mail.
I honestly miss those days of deployment simplicity.
Tried from two hosts, different countries.
Also it seems to me that this is a good way to exfiltrate data, rubber stamped by cloudflare themselves.
Several weeks ago, I got frustrated hitting the free tier limits on Netlify, and was looking for a self-hosted solution for this problem. I built it using a DO VPS and Caddy in the backend. It's free on Github. I was able to get the whole thing set up in an hour or two with the help of an agent. Feel free to give it a spin.
I have been hosting static websites with cloudflare for years and finding how to do it on the UI is getting harder as they add more things and reoranize.
Desktop mode doesn't show any more information either
Double click the html file.
The OS will run the web app using a browser that is just part of the OS.
CORS issues on a tainted canvas if you try to render an image from a file:// src.
I have a few qualms with this app.
Note how the error has zero information.
Looking in the network tab, a POST request to /upload returned 403 and an HTML page starting with "Sorry, you have been blocked", and to "email the site owner to let them know you were blocked".
I'm very tired of this adversarial approach to software coupled with vague errors.
EDIT: it was the file './git/hooks/fsmonitor-watchman.sample' created by default on git init. Maybe because it's Perl. Worse-than-useless "please try again" and "you've been blocked" for committing the sin of uploading a folder that's a git repository. Sigh...
https://drop-1e1a536f-10d.honeysuckle-gull.workers.dev/
It's minesweeper, but the logic uses xstate/store. The link in the bottom is broken; it's supposed to go to `building-minesweeper-with-xstate-store.html`
I have no need for this but I love that my friends could vibe out a website, drop it here, claim it, and host it for pennies. This is great.
"Your site is reachable within ~32ms of 95% of the world’s Internet-connected population" isn't new but it's cool to see that achieved so trivially.
https://github.com/mohsen1/session-recorder-chrome-extension
I built above chrome extension because anything in this area has been trying to monetize the solution. I wanted a free and open source version of this to exist.
Funny story: I used to work for a startup which had a trademark on "Airdrop". When Apple announced that feature, it took everyone there by surprise. Ended up reaching out and selling it to them for a buck or two in favor of maintaining goodwill.
The luxury blockchain resort island is just soaking somewhere in the ocean, collecting dust and guano, while its former inhabitants are all the rage about AI now :'(
Is it really more useful to have everyone expressing how much they like something instead of identifying problems?
Is seeing people talking about the things they don’t like something that makes you unhappy? Why?
> Don't be curmudgeonly. Thoughtful criticism is fine, but please don't be rigidly or generically negative.
https://news.ycombinator.com/newsguidelines.html
I think HN should be a place where I am excited to see what others have to add. When I see a post I am excited to see what takes and spins others have on it. I do want real criticism and a lively debate about important things, but there has to be a balance.
I want to see other comments that seem like they genuinely want to help steer something or build people up. Sometimes I get the impression that's not happening on HN.
Which is sad, because so much amazing stuff is happening on the world right now, and seems to be only accelerating. For everybody.
Probably (I'm just assuming) because that person observes negative/cautious/"I don't like this because X and Y and also Z"/etc sentiment too much and feels like people are only quick to notice issues while forgetting about good sides.
It's only an assumption, though.
Same here: CF is basically giving malicious actors an ability to ship contents/data publicly while laundering the legal responsibility of those actors.
Now tell me what is cool
That's awesome, glad to hear it
I'm already on board, you don't need to sell it to me!
Piracy is cool. Information wants to be free.
I hate the corporate bootlicking that is so prevalent here.
Not immediately being a copyright bootlicker.
The fact that you went straight to "BuT pIrAtEs" already shows who you actually care: Corpos, not people.
If my company presented such user agreement I would be quickly reported by users to local Office of Competition and Consumer Protection, audited, fined, and ordered to change that.
I think this would be even challenged at the level of "Abusive clauses registry" that office maintains, so the agreement would be quickly overruled in court.
If no specific clause would be challenged, this is an example of "grossly violates the consumer's interests" rule.
How is big tech allowed to push this shit anywhere? How is this legal in civilized world?
Perpetual is way harder to justify though.
Irrevocable and right-to-sublicense are the red flags for me. Nothing a company sells to us is irrevocable, but everything they take from us is expected to be.
They assign a subdomain automatically for uploads, same as cloudflare workers.
I don't know what they do, but implementing guardrails for this is possible nowadays with AI, but maybe they use a "mechanical turk"
Attempting to distribute/acquire illegal things through Cloudflare is an exercise in how to get caught.
For a web app, you might have to unzip it and launch the .html inside. CyberChef for example does offer a downloadable copy of its web app instructing you do just that.
Will it work for every bloated react app? no.
Will it work if you intentionally put the slightest amount of thought into the design? yes.
It's like, my dude last week this was an excel spreadsheet.
Officially it means they can legally do wat you want them to do (present the content to users, perhaps transforming it in various ways for some or all viewers), but of course it covers them being able to do far more than that.
If they needed permissions for conversion, they'd have made a specific mention of that and thereafter confirmed legal ownership.
I wished I could find all the science and technology as uplifting as my friends do.
What makes you say this?
(I might be butchering it, course it is an Office Space reference)
He was my absolute favorite character in that show.
I would get the point if this was someone's personal Show HN project but this is Cloudflare. They can withstand a little critique.
It’s just another take on shill / sheeple / etc. it gets old.
[1]: https://www.interpol.int/en/Crimes/Illicit-goods/Projects/Pr...
> The suspects subscribed to 40 Korean cable TV service accounts, re-broadcasting content to Indonesia and offering video-on-demand (VOD) services through customized TV boxes, applications, and web browsers.
> Criminals behind pirate sites can be part of organized crime groups. They can use the proceeds to fund other illegal activities, such as illegal online gambling, online sexual exploitation, drug trafficking, arms smuggling, and money laundering.
Another notable example would be Operation KRATOS 2 by EUROPOL[1]. The case was roughly the same — crime organization pirating video content. IPTV piracy is certainly a lucrative business, because videos are relatively more difficult to handle for normal people.
[1]: https://www.europol.europa.eu/media-press/newsroom/news/29-a...
There's more to the Internet than the world wide web, though. NNTP and IRC communities remain vibrant, if diminished in size
I've noticed the current version is largely accessed by Chrome which appears to be a trojan.
They can cause a long drawn out court battle, and abuse your data. Noyb is the real-world example here. Most companies depend on not being sued, and will fold if a regulater sends them notice.