The sites you speak of are using an insanely more expensive CF tier with both more granularity and dedicated support, as well as those companies having internal IT resources. Two very different SLA and response models :). Major customers and important traffic sites get custom solutions and fixes... R2R is not a blip on that radar. So apples and oranges.
That’s correct, however I gave this as an example of an extreme case to rule out any actual threats coming from a specific device or network.
There are other similarly sized websites that have the very same threat model as R2R, they most definitely aren’t using an enterprise account, nor extremely special and customized configuration that isn’t available on more affordable tiers.
It simply is something that needs to be looked at and be figured out in the bounds of what normal tiers allows to achieve.
And yes, it does possibly imply loosening some of the global filtration that is currently applied, and applying a more complex configuration instead.
We use the product in some instances, as it is easy to deploy and inexpensive for basic needs. For most reasonable priced tiers, CF is not overly configurable. For example, something as simple as page load timeout is NOT editable. To get granular features and control, you must pay for enterprise.
Actually, there are many different tiers and ratings coming from CF, for a site like R2R, I somewhat doubt it uses the absolute most basic tier, simply due to traffic limitations.
But I may possibly not evaluate the needs of a site like R2R correctly.
That being said, even if it does require some more granularity, it’s something that needs to be taken into consideration, and does not necessarily mean you will have to upgrade to an enterprise tier account, given that some features can be enabled selectively, for more sane pricing than the ridiculous and seemingly random pricing they ask for enterprise.
Anyway - this conversation is not going to help the OP or anybody else. Thanks for your input though.. interesting topic for some of us that may be better suited to a conversation in some other place :)
Well, The dive in was mainly to address the impression your first comment may have left on OP, and maybe others reading it - while possible, it is very unlikely this was caused due to a compromised network or device, simply due to the way this problem behaves.
Hopefully rev will figure this out.