really... it is kind of ridicoulus to keep fixing on cloudflare... We need to protect our service from DDOS. All these services who protect you would be a problem for you. How would you solve the problem? In my expierience I saw many thos and other dervices who came online and get DDossed from the concurrent services. So protecting us from DDOS must be done.
I'm not trying to be a dick here... But there's a reason why we focus on cloudflare...
Did you read the post i linked to? Did you understand what it said?
You're running a service that helps people achieve a certain degree of anonimity, but at the same time you're giving EVERY piece of data they exchange with your site to a US company (unencrypted!!!). This means that *any* three letter agency, and probably most friendly nations will only require a very limited amount of paperwork in order to unmask every client your site has ever had.
They'll know deposit addresses, they'll know ip's, they'll know timestamps, they'll know browser fingerprints, they'll know which address your customer likes to receive his mixed funds.
Basically, by using cloudflare, you turn your whole operation m00t.There are other (technical*) sollutions to the DDos problem. If you really chose cloudflare, your site should show a very big, clear warning that the US governement, all it's actors and all it's friends (aswell as a big private company) have access to your mixer's logs (well, not in the literal sense, but they might just aswell have had access to your mixer's logs.. if you don't log anything, they'll have more info on your clients than you will have yourself).
* with technical sollutions, i mean going to a bulletproof datacenter that has purchased physical devices to mitigate DDos attacks (like, for example, this line of products:
https://carrier.huawei.com/en/products/fixed-network/b2b/Security/DDoS-Protection-System/AntiDDoS8000) OR concentrate on tor.