Live data from Hacker News

Cloudflare's abuse policies and approach

blog.cloudflare.com

31–40 of 1001 posts

Re: Cloudflare's abuse policies and approach

#31

If this is in response to Kiwi Farms, I would say this is very disappointing. Love CloudFlare, think they are amazingly innovative, huge amount of respect for the people who work there. I see where they're coming from, but I don't see how KF is defensible whilst 8chan et al aren't.

If you actually read their article, it seems they are saying that 8chan WASNT defensible to them and was a mistake for them to do so.

then why don’t they publicly invite back 8chan and the daily stormer, possibly for a discount/free? similarly, are they lobbying to get FOSTA revised so they can bring back Switter?

their opinion is that it is (almost always?) ethically wrong for them to withhold security products. for the two websites i mentioned, nobody is stopping them from providing services. for a third, they could lobby to fix fosta and/or not transit switter traffic in the us.

Re: Cloudflare's abuse policies and approach

#33

> While we believe we have an obligation to restrict the content that we host ourselves, we do not believe we have the political legitimacy to determine generally what is and is not online by restricting security or core Internet services. If that content is harmful, the right place to restrict it is legislatively. Agreed, but realistically: for the near future there will be no legislative restriction in the US on ha…

This is a crazy take on responsibility. It isn't Europe's responsibility when people decide to take unsafe passage on the sea and drown. Could they do more? Yes, I'm sure they could, but are they directly responsible for drownings? No, this is too far.

I'd argue the same for Kiwi Farms. If people are cyber-bullying (ie, reaching out to people and harassing them) then those people should be addressed. Arguing that any speech you or someone else deems "hurtful" or "hateful" should be banned is nuts, since no one has to go and read those words, its an opt-in process. AND, if people can disagree about whether something is really "hateful" then its even more difficult to justify taking action simply for communication of ideas that we find offensive.

CloudFlare is in a tough spot that they put themselves in. If they'd like to avoid legislation then they've got to be the pipe, not the moderator. Once they switch to moderator they are responsible for all moderation. They can't pick and choose. Imo they'd be better served by acting as a utility and staying out of the moderation game. We've already seen a ton of attacks on free speech by powerful Internet companies, in the US at least the 1st amendment (freedom of speech) needs a defender like CF to help.

Re: Cloudflare's abuse policies and approach

#35
Never thought I'd see the Left trying to weaponize corporations to suppress speech they dislike. Reminds me a LOT of Evangelicals in the 2000s - I know that comparison has been made frequently but that's the last group that made a serious censorship push.

I wonder how all of this will end? I support CloudFlare here - they should act as a utility, not as an arbiter of content. This ends poorly and one day will bite the people that are pushing for this.

Re: Cloudflare's abuse policies and approach

#36

> While we believe we have an obligation to restrict the content that we host ourselves, we do not believe we have the political legitimacy to determine generally what is and is not online by restricting security or core Internet services. If that content is harmful, the right place to restrict it is legislatively. Agreed, but realistically: for the near future there will be no legislative restriction in the US on ha…

Why does it have to be a US legislative solution? Any country CloudFlare serves could come up with a harmful-content policy for issuing takedown orders; and CloudFlare would likely have to obey that takedown order globally (not just to that country’s view) in order to be in compliance, such that their only other option would be to remove their POPs from that country and block all clients from that country.

Re: Cloudflare's abuse policies and approach

#37

Earlier quoted context omitted.

8chan had the whole mass shooter thing. Comparing the two websites is very hyperbolic.

What did the neo-Nazi site have that the others didn't? "Nazis" isn't the answer because I can find Nazis on a lot of websites out in the open.

If kiwifarms becomes the original public manifesto posting spot for national mediafest mass shooters, their views may change.

Re: Cloudflare's abuse policies and approach

#38

Earlier quoted context omitted.

You bet they'd get attacked if they ever stopped using a proxy.

When I checked last week, their origin IP was trivially available. I found it by typing “kiwifarms” into search.censys.io

As shown here, it wouldn't just be denial of service attacks. It'd be legal attacks on their DNS provider, their registrar, their hosting, their hosting's upstream providers, etc, etc.

Re: Cloudflare's abuse policies and approach

#39

If this is in response to Kiwi Farms, I would say this is very disappointing. Love CloudFlare, think they are amazingly innovative, huge amount of respect for the people who work there. I see where they're coming from, but I don't see how KF is defensible whilst 8chan et al aren't.

It's a really tricky situation. On the one hand, websites like KF and the like are utterly reprehensible. On the other hand, Cloudflare taking it upon themselves to police the Internet is a nightmare in its own, given their bot-prevention services are effectively mandatory in order to even keep any sort of larger interactive website running. What is permitted to say is something for the courts, not for the whims of p…

> On the other hand, Cloudflare taking it upon themselves to police the Internet is a nightmare in its own, given their bot-prevention services are effectively mandatory in order to even keep any sort of larger interactive website running.

Maybe we should additionally also focus on that problem as well. It should not be the case that you need to pay a protection racket just to be able to survive on the Internet.

We definitely need more, also international, efforts to establish:

- baseline requirements on IT security (to reduce the impact of stuff like hacked IoT devices)

- quick and fast cooperation between governments to identify and contact owners of hacked equipment to get them off the Internet and patched. Maybe something similar in operation to firefighters - you don't have to pay for their assistance unless you actually created the fire or were grossly negligent?

- procedures to get nation states that are a clear and consistent threat to everyone else off the Internet either because they actively attack others or because they are shielding hacker groups, and judging by where a lot of attacks originate, that is Russia, China, North Korea and Iran.

Particularly regarding the last point, I'd also advocate to take factual declarations of war as what they are and strike back.

Re: Cloudflare's abuse policies and approach

#40
post #14

Cloudflare services are really only useful when a site is under attack - otherwise it's just a CDN to reduce hosting costs. If "kicking someone off cloudflare" makes them unavailable, it means they're undergoing ongoing attacks of some sort.

I mean, sometimes you need a CDN because your hosting costs would be untenable otherwise, and CloudFlare’s the only one that’s free / a flat $20 for as much traffic as people can throw at it. So losing CloudFlare can mean that your only other option is to pay egress-bandwidth bills / other CDN service bills you can’t pay; and so you just don’t bother to put your site back up at that point.
Post reply on HN