Live data from Hacker News

Viewing profile — xxdesmus

xxdesmus

HN member
Joined
Mon, Apr 25, 2011, 8:55 PM UTC
HN karma
354
Public activity
270 items

About xxdesmus

Head of Trust & Safety @Cloudflare.

Former Threat Intel lead @Cloudflare.

Former Head of Support @Cloudflare.

[ my public key: https://keybase.io/xxdesmus; my proof: https://keybase.io/xxdesmus/sigs/AG0bUkTiBs4OzR1wX3GxsemdzN9ha4auRytqLYZcjHY ]

Recent public activity

  1. comment
    Comment #48740875

    I run Trust & Safety at Cloudflare. The best route to request a takedown of this domain and luaventures{.}xyz (the other domain mentioned in your blog post) would be at the host an…

  2. comment
    Comment #47102125

    I run the trust & safety team at Cloudflare. In the vast majority of cases, Cloudflare is not the hosting provider of a website resolving to our IPs. In those cases we have no capa…

  3. story
  4. comment
    Comment #43213786

    While Cloudflare has been publishing transparency reports for a long time, this year we chose to revamp the report in light of new reporting obligations under the DSA, and our goal…

  5. story
  6. comment
    Comment #41954685

    Please drop me an email with what you’re seeing - justin (at) cloudflare.com ? That doesn’t sound like old info - that sounds like someone might still be reporting it for abuse eve…

  7. comment
    Comment #37414836

    I look forward to the phishinhg. Hopefully you can block known bad hashes.

  8. comment
    Comment #36527327

    1) Thanks for the heads up 2) Is this the beta channel? or official builds? 3) You've already notified 1Password of this possible bug/risk?

  9. comment
    Comment #35404804

    Self hosting option? Looks great, but I’d rather avoid a SaaS service if possible.

  10. story
  11. comment
    Comment #32132704

    CNAME flattening works just fine and is supported by a variety of DNS providers at this point, but yes — there’s an RFC otherwise.

  12. comment
    Comment #31609722

    Hello, I’m the Head of Trust & Safety at Cloudflare. I wanted to clarify our processes, which were described inaccurately in this Hacker News post. As part of our standard fraud re…

  13. comment
    Comment #31574099

    Hello, I'm the Head of Trust & Safety. Please forward me the email? This is very likely legitimate and from our team, but I'd like to confirm. justin@ cloudflare.com

  14. story
  15. comment
    Comment #28794958

    Cloudflare sends the origin IP directly to the hosting provider -- with a copy of the abuse report.

  16. comment
    Comment #28793557

    Not true -- according to the OP -- we'll tell you who the hosting provider is -- as in, the name and abuse email of the host. The origin IP is not needed.

  17. comment
    Comment #28793522

    >> "You also have a Cloudflare account to file a complaint, which I found to be odd." That's incorrect. Anyone can fill out the web reporting form here: cloudflare.com/abuse -- abs…

  18. story
  19. story
  20. comment
    Comment #26814634

    To clarify — the website owner can fully add Tor to your allow list if you’d like to. That’s entirely your choice if you’re concerned about Tor users being CAPTCHA’d. Also you cont…

  21. comment
    Comment #24038323

    Completely agree. I closed the tab as soon as I saw those were the only 2 signup options.

  22. comment
    Comment #23933985

    To be clear -- the website owner can always reply to the email they receive from our Trust & Safety team. That goes directly to our team. This individual could also do that if they…

  23. comment
    Comment #23305260

    waves author here. To be clear: I do this research in my free time. This is 100% independent of my $dayjob at Cloudflare.

  24. story
  25. comment
    Comment #23138790

    (1) setup a VPN server at a hosting provider (you pick) (2) turn off all logging (3) make it available to the public (you pick how) (4) get flooded with abuse reports (5) get shut …