Live data from Hacker News

CloudFlare and Google Cloud Platform

cloudflare.com

91–100 of 133 posts

Re: CloudFlare and Google Cloud Platform

#91
post #80

Earlier quoted context omitted.

Shouldn't you also be upset over all the other service providers including your own ISP that also doesn't block those sites? Unless it's specifically against protecting people against criminal activity, in which case we are really going down a slippery slope.

>Shouldn't you also be upset over all the other service providers including your own ISP that also doesn't block those sites? I would argue that the moral dilemma is different if you choose to allow ISIS traffic to pass through you, vs have them as a client.

It might, but the business model Cloudflare is on makes the distinction less clear. For example with their free plans would they need to identify all clients, scan their content and judge accordingly?

For paid clients, I might be more sympathetic to the argument, but even then the (moral?) rules (for nonbusiness) are incredibly tricky to figure out and keep consistent. Selective enforcement is bad for everyone in the uncertainty it spawns.

Re: CloudFlare and Google Cloud Platform

#92
post #86

Earlier quoted context omitted.

I think it's perfectly valid ISIS have a platform. Gagging angry people is not going to calm them down or prevent them from communicating.

That's not entirely true. ISIS fuels its ground combat force with angry young people recruited via predominately through social media. The social media often consists of video sharing and much of the video is served up from sites like isdarat.tv (now apparently gone) that are/were fronted by CloudFlare. YouTube and Facebook are efficient with their censoring; ISIS needs stable hosting for these videos for maximum eff…

Citation, please. I hugely doubt censorship has clear, measurable effect on recruitment. Among other things it's got to increase resentment of the western world.

Finally, there may be extenuating circumstances of which we aren't aware. Perhaps CloudFlare is granting them use of data in exchange for not cutting cables. When you're that big your presence is indistinguishable from the internet itself.

Re: CloudFlare and Google Cloud Platform

#93
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

I tried their enterprise tier out about 9 months ago and was entirely unimpressed. Moving a site from Akamai -> CF increased page load times dramatically. We ended up quickly switching back. CloudFlare's complicity with ISIS, however, was what turned me off permanently. For those unaware, CloudFlare was providing proxy shielding of ISIS's propaganda websites. The CF CEO publicly refused to discontinue their service,…

CloudFlare is also complicit with DDoS for sale websites. People have asked them to remove them or reveal their ips to report but they have refused. Here are a few of them.

http://cyberstresser.com/

https://spboot.net/

https://alphastress.com

https://vdos-s.com/

Re: CloudFlare and Google Cloud Platform

#94
post #72

Earlier quoted context omitted.

pretty neat from a routing standpoint and devastating to user privacy on the whole I'm interested. Please expand on the privacy point. I thought the general move to CloudFlare was a good thing for privacy, as it provides an easy mechanism for getting sites onto HTTPS without having every site to worry about managing certificates.

Besides Cloudflare being the biggest man-in-the-middle on the internet, their DDoS mitigation offering is also questionable. If you google "clouflare bypass" [1], you get to websites that can tell you the origin IP address of a cloudflare customer's domain name. So, malicious guys could hit the real IP directly. [1] https://www.google.com/search?q=cloudflare+bypass

> If you google "clouflare bypass", you get to websites that can tell you the origin IP address of a cloudflare customer's domain name.

Those rely on a known DNS history from before CloudFlare was added to a domain. If bypass is a concern, changing the server's IP and making sure it never shows up in a public DNS record again solves things.

Re: CloudFlare and Google Cloud Platform

#95
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

[deleted]

Re: CloudFlare and Google Cloud Platform

#96
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

I have a non-critical website with them for free and it randomly becomes unreachable with an error 522 in certain locations. Which seems to indicate it is a problem on their end.

When I talked to support about it, they keep telling me I needed to whitelist their IPs when I didn't have any firewall rules in place. All I had was iptables and it had no rules.

Re: CloudFlare and Google Cloud Platform

#97
post #18

I want to love CloudFlare, I really do. We currently use them, but sadly the number of times that CloudFlare has been the cause of a service interruption is somewhere around 50% mark. They are no longer in use on any critical/important end points, I just don't need PagerDuty waking us up over an issue I have no control over. This is not a problem I expect to improve. As they start to cover all of the web, i imagine t…

Would you mind posting the types of problems you've had? I use CF for many critical websites I manage and haven't noticed any problems.

Most of the times cloudflare is fine, they've gotten a lot better over the years.

However we have found random areas to temporarily go down for random periods of times. You will not be able to see these downtimes if you are only checking from 1 location.

Re: CloudFlare and Google Cloud Platform

#98
post #92

Earlier quoted context omitted.

That's not entirely true. ISIS fuels its ground combat force with angry young people recruited via predominately through social media. The social media often consists of video sharing and much of the video is served up from sites like isdarat.tv (now apparently gone) that are/were fronted by CloudFlare. YouTube and Facebook are efficient with their censoring; ISIS needs stable hosting for these videos for maximum eff…

Citation, please. I hugely doubt censorship has clear, measurable effect on recruitment. Among other things it's got to increase resentment of the western world. Finally, there may be extenuating circumstances of which we aren't aware. Perhaps CloudFlare is granting them use of data in exchange for not cutting cables. When you're that big your presence is indistinguishable from the internet itself.

EDIT: Have a look at this: http://docs.house.gov/meetings/FA/FA18/20150127/102855/HHRG-...

I cannot readily cite any scholarly papers on this subject; this is from my observations as a frequent reader of /r/syriancivilwar, jihadology.net, and Iraq/Syria-related social media content. The typical pattern is for ISIS to release a video to their propaganda sites and for jihadist social media users to tweet the link.

al-Ḥayāt Media Center (ISIS's media outlet) relies on the ease of distribution via protected (proxied) channels to reach their large audiences. The reach of this content would be more limited if companies like CF wouldn't shield it.

Re: CloudFlare and Google Cloud Platform

#99

Earlier quoted context omitted.

It should be entirely up to the ISP. Consequently, the ISP's customers can judge (with their spending) whether they approve of such blocking.

No they can't, at least not in America.

Actually they could, but they would lose their common carrier (see a sibling comment) protections.

Re: CloudFlare and Google Cloud Platform

#100
post #99

Earlier quoted context omitted.

No they can't, at least not in America.

Actually they could, but they would lose their common carrier (see a sibling comment) protections.

To the extent that they are not prohibited from doing so, they would also not lose common carrier status if they did. The rules applied to ISPs under Title II -- the FCC's recent Open Internet Order -- do not prohibit blocking unlawful content, only lawful content.
Post reply on HN