Watercooler16 days ago

Hacker News Argued About Cloudflare While Lobsters Quietly Reported What Leaving Costs

A claim that 89.6 percent of CDN-using European companies sit behind Cloudflare drew 242 points and 205 comments in a day. We fingerprinted 24 large European company sites ourselves and found Cloudflare on exactly one of them.

The WJS Desk

Sep 8, 2026 · 7 min read

Photo by Engin Akyurt on Pexels

On 8 September a post from CipherCue reached the Hacker News front page with the headline finding that among European companies using a CDN, nearly nine in ten use Cloudflare. Precisely: 39,547 of 44,143, or 89.6 percent, against Amazon on 3,112, Fastly on 1,299 and Akamai on 396. It took 242 points and 205 comments inside a day, and was still climbing when we last checked.

The same morning, Lobsters was running a different thread about the same underlying question. A hands-on review of European cloud providers, 24 points and 18 comments, in which one person tried to actually buy a server from twelve of them. Read together, the two threads are more useful than either one, and they are not saying the same thing at all.

The argument, both sides at full strength

The concentration case is straightforward. One vendor terminating TLS for nine in ten of a continent's CDN-using companies is a single point of failure and a single point of leverage, and it happens to be American. That is a real systemic risk whatever you think of the politics.

The other side is not "concentration is fine." It is that Cloudflare is winning on merits that no policy has matched: a free tier that includes DDoS protection nobody else gives away, no sales call, and no monthly load balancer fee. Nobody chose concentration. Forty thousand people separately chose the thing that worked, and the aggregate is concentration.

The takes

jillesvangurp on Hacker News gave the cost argument with actual history: "We used Google's CDN for the last six years or so but it's pretty annoying to deal with and you have to pay for a load balancer every month in order to properly use it. That adds up to quite a bit per year."

em500 compressed the enterprise version into one line: "Tale as old as time: nobody ever got fired for buying IBM / Cloudflare / AWS / Azure."

The strongest framing of the risk came from parasxos, who borrowed a term from a regulated discipline:

In control systems, one vendor behind nine out of ten front doors has a name: common-mode failure. We get audited for it. The web apparently calls it best practice.

bborud made the market argument rather than the political one, which is the version that survives disagreement about American politics: "Having 90% of all eggs in one basket is neither good, nor does it constitute functioning market."

Against that, 8by3 put the suspicion plainly: "When someone says cloudflare is too good / cheap to be true... maybe think about it. They have shareholders, who wouldn't allow them to provide value for free."

And noir_lord gave the resigned read, which was the most-replied comment in the thread: Europe absolutely should unwind this, and will not, because "unwinding that is the expensive work of years/decades not months."

Then Lobsters, where the register changes completely. icy, who used to work at UpCloud, described what the alternative actually did:

We're now migrating all our stuff away from them due to terrible support. We were under a severe DDoS last week and UpCloud didn't bother informing us that they've apparently gone ahead and nullrouted our boxes, which is rather critical information when you're actively trying to deploy ratelimiting/migrate services elsewhere.

And plaes supplied the detail that should embarrass every sovereignty deck: of the providers reviewed, that "Estonian" one "isn't really Estonian. It's an Estonian company probably by an e-resident. Its address is using a known 'rent a legit-looking mailbox' service."

Where the two threads collide

Here is the part only worth writing if you read both. The Lobsters article's conclusion, published 7 September, was that after eliminating eight of twelve European providers, "that leaves UpCloud as the clear frontrunner" and the author would give them a shot. One of the two highest-scoring comments underneath, from someone who used to work there, is that they are migrating off UpCloud because it nullrouted them during a DDoS without telling them.

That is the whole argument in one thread. The recommended European alternative failed at precisely the job Cloudflare's free tier does automatically.

The rest of the review reads the same way. Twelve providers, offers obtainable from eight, half of those demanding a month minimum. OVH's console spun for ten minutes then reported no instance had been created, leaving behind a vRack the author could not delete without an internal server error. Scaleway never sent the mandatory phone verification code, so they could not become a customer at all.

Hacker News spent 205 comments on whether the concentration should exist. Lobsters spent 18 comments demonstrating why it does.

We ran the measurement ourselves

The study's method is HTTP header fingerprinting plus DNS observation, and it states its own biggest caveat: the cohort "skews toward small and mid-sized companies rather than large enterprises." We wanted to know how much that caveat is doing.

So we fingerprinted three well-known companies in each of the eight countries the study covered, 24 domains, checking response headers for cf-ray, x-amz-cf-id, Akamai markers and the rest.

Front door detectedCount of 24Share of the 15 with a detected CDN
Amazon CloudFront960%
Akamai533%
Cloudflare17%
No CDN header detected9n/a

One of 24. The single Cloudflare hit was brainly.com, and it answered our request with a 403 challenge, which is its own small comment on edge gatekeeping. Siemens, SAP, Inditex, Eni and Intercom were on Akamai. BT, Monzo, Booking.com, Ferrari, Ryanair, Cabify and Glovo were among the CloudFront set. Hetzner, ASML, Allegro, OVHcloud and Dassault Aviation showed no CDN header we recognise.

This does not refute the study. It confirms what the study already told you: 89.6 percent is a fact about small and mid-sized companies picking a free tier, and it does not describe the enterprise web at all. Two very different sentences, one number.

Our own method has limits and we would rather state them than let the table look stronger than it is. Twenty-four domains is a sample you can read in one screen, not a survey. "No CDN header detected" is not the same as no CDN: Adyen serves from Netlify behind Akamai nameservers, and our fingerprint caught neither. And we found two cases where header evidence and DNS evidence flatly disagree. Monzo and Ferrari both run Cloudflare nameservers while being served by CloudFront, and Ferrari's redirect chain also handed us a Fastly cache header. A DNS-led method files both under Cloudflare. A header-led method files them under Amazon. That is a swing on real companies, and it is why we would treat one decimal place on 89.6 as decoration.

The comment nobody upvoted

helsinkiandrew posted the only methodological objection in the thread and it drew no replies:

Doesn't this miss websites that serve their own site html but serve (static) assets from a CDN. This seems to be a common pattern with Wordpress sites, presumably because it makes cache configuration simpler.

That cuts the opposite way from our finding, and it is correct. The study counts front doors. A company on its own nginx with all its images on Cloudflare is invisible to it, so the real dependency is undercounted in one direction while being overweighted toward small sites in the other. Nobody engaged, because the thread had already moved to whether the EU can build anything.

Runner-up, from bildung: the UK shows 17,000 CDN-using sites against France's 4,000 and Germany's 6,000, and nobody answered whether that is real behaviour or sampling. It is the number in the study we trust least.

Our read

The honest disclosure first: whatjustshipped.com is served by Cloudflare. We checked our own headers while writing this and got server: cloudflare and a cf-ray ending in SIN. We are one of the 39,547, we chose it for exactly the reasons jillesvangurp described, and we have not moved.

Our read is that Hacker News had the wrong argument. The question is not whether Europe should have its own CDN, because it does: Bunny runs on its own edge, CDN77 runs on its own, Myra on Myracloud. We checked. The European alternatives exist and they eat their own cooking, which honestly surprised us and we had assumed we would catch at least one hiding behind Cloudflare.

The question is why almost nobody uses them, and the Lobsters thread answers it: because the operational floor is lower. Not the price, the floor. A provider that nullroutes you mid-attack and does not send an email has lost the argument before the sovereignty conversation starts.

You do not get out of a common-mode failure by choosing a vendor that fails differently. You get out by choosing one that does not fail, and that is the part nobody in either thread could point to.

What would change our mind is a European provider matching one specific thing: absorbing a volumetric attack on a free or near-free tier without a sales call. Not price parity, not feature parity. That single capability is what built the 89.6 percent, and the day someone in the EU ships it, the number starts moving on its own.

One last detail that we did not have to look for. The post reporting that nine in ten European companies use a CDN went down under Hacker News traffic, and readers were passing round an Internet Archive link to read it. We checked the host: bare nginx, no CDN detected. maxcoding reported it taking over 40 seconds to load from the EU, and cbg0 got the joke first.

Share

A study says 89.6% of CDN-using European companies sit behind Cloudflare. We fingerprinted 24 large European firms and found Cloudflare on exactly one. Both numbers are true. #Cloudflare #CDN #DevOps #Europe

Never miss a ship

The best stuff that shipped this week, delivered every Thursday. Free, no spam. We read all the boring stuff so you get the fun parts.

Keep reading