Live data from Hacker News

Cloudflare's abuse policies and approach

blog.cloudflare.com

171–180 of 1001 posts

Re: Cloudflare's abuse policies and approach

#171
post #87
post #75

Earlier quoted context omitted.

It's not actually commendable to host content for white supremacists and transphobes. Free speech may be deserving of protection, but white supremacists using the internet to coordinate real-world activities (such as terrorist attacks) doesn't actually qualify as "free speech" deserving protection against "authoritarians and individuals wanting to rip each other down".

"I support free speech except the things that I don't like"

I broadly support free speech, but not hate speech.

Re: Cloudflare's abuse policies and approach

#172
post #126

Earlier quoted context omitted.

I think one easy thing they could do, is stop hosting for forums dedicated to doxxing and harassing people, preferably before they inevitably bully their victims into suicide.

Guess what? They do. FTA: > Our decision to disable access to content in hosting products fundamentally results in that content being taken offline, at least until it is republished elsewhere. Hosting products are subject to our Acceptable Hosting Policy. Under that policy, for these products, we may remove or disable access to content that we believe: [...] Is otherwise illegal, harmful, or violates the rights of ot…

This policy seems to only apply to content that they host. It appears that they don't intend to apply this policy to websites that they are only providing DDoS mitigation to, such as KiwiFarms.

Whether Cloudflare is hosting the content or mitigating DDoS attacks against it, they bear some responsibility for the content being accessible. I see no good reason for them to have different policies between their hosting and DDoS mitigation services if they actually care about not propagating the content they refuse to host.

Re: Cloudflare's abuse policies and approach

#173
post #104

Earlier quoted context omitted.

Possibly, but as soon as it became a thing it would be raided by the police, as per what happened to the Black Panthers.

Police are also a reason the left need a strong gun culture (I mean we are talking about the same groups of people, police and right wing extremists, terrorist groups, white supremacist gangs etc). BP didn’t go far enough and were hamstrung by lack of support from the left due to racial division within working class and those in poverty

Good thing the left is so supportive of the working class now lol

Re: Cloudflare's abuse policies and approach

#174

If this is in response to Kiwi Farms, I would say this is very disappointing. Love CloudFlare, think they are amazingly innovative, huge amount of respect for the people who work there. I see where they're coming from, but I don't see how KF is defensible whilst 8chan et al aren't.

They dropped support for 8ch after successive terrorist attacks, one of which killed 50 innocent people. The CEO has stated that he regrets dropping them.

Re: Cloudflare's abuse policies and approach

#175

Earlier quoted context omitted.

It's a really tricky situation. On the one hand, websites like KF and the like are utterly reprehensible. On the other hand, Cloudflare taking it upon themselves to police the Internet is a nightmare in its own, given their bot-prevention services are effectively mandatory in order to even keep any sort of larger interactive website running. What is permitted to say is something for the courts, not for the whims of p…

Except that they don't respect court verdicts - e.g. in one case they lost against an Italian court "US-based Cloudflare disagreed. It countered that the Italian court didn’t have jurisdiction and that the e-Commerce directive didn’t apply to foreign companies, but those objections were rejected." How can you argue that a legal ruling is legally invalid (besides appealing it) and use this as a supposed justification…

Their point for not respecting verdicts is:

> Unfortunately, these cases are becoming more common where largely copyright holders are attempting to get a ruling in one jurisdiction and have it apply worldwide to terminate core Internet technology services and effectively wipe content offline. Again, we believe this is a dangerous precedent to set, placing the control of what content is allowed online in the hands of whatever jurisdiction is willing to be the most restrictive.

It is pretty hard to suggest that someone can sue Cloudflare in a random country with either a corrupt or weak judicial system (not saying that's the case here, but in general) then get it taken down globally. To add, taking things down in a single country might not be super effective with the way the internet works, and the court might see someone browsing from a VPN and claim that a geoip-based block is insufficient for compliance.

Although, I don't know the exact case you're referring to or if it's covered by this statement.

Re: Cloudflare's abuse policies and approach

#176
post #75

Earlier quoted context omitted.

It's not actually commendable to host content for white supremacists and transphobes. Free speech may be deserving of protection, but white supremacists using the internet to coordinate real-world activities (such as terrorist attacks) doesn't actually qualify as "free speech" deserving protection against "authoritarians and individuals wanting to rip each other down".

Stopping terrorist attacks is also how the NSA vindicates spying on every internet user. It's up there with "think of the kids!". It's an excuse though - and people will extend "terrorist attacks" to include non-violent protests when it suits them.

Except this isn't a "we should record everyone's interactions to stop terrorism" it's "we should stop hosting propaganda for terrorists, especially when that cessation doesn't harm others (dropping hosting for their website does't impair other people's liberties, whereas spying on everyone's messages would)"

Re: Cloudflare's abuse policies and approach

#177

Earlier quoted context omitted.

> They are exact type of customer who need DDOS protection the most. They (KiwiFarms, Daily Stormer) would be better not on the internet. > They've decided they want to be seen as a utility. This isn't how law works - just as you can't say "we don't have a banking license but we'd like to be seen as a bank and provide banking services" you can't say "we're not a utility but we'd like to be seen as one". Note that bei…

> They (KiwiFarms, Daily Stormer) would be better not on the internet. Who should decide that? Cloudflare? you?

Cloudflare. It's in the TOS. They're not a utility, so yes, they get to decide.

Re: Cloudflare's abuse policies and approach

#178

> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…

The negative value of a website being serviced by Cloudflare is usually significantly higher than the price they pay for the service.

How much do you think Cloudflare donated for the 3 suicides caused by Kiwi Farms in the recent years?

Re: Cloudflare's abuse policies and approach

#179

Earlier quoted context omitted.

DDoS is a product of an inherent weakness of the internet infrastructure, namely BGP. Cloudflare "solves" this by acting as a middleman, and charging for their service. I don't know if I would describe a DDoS attack as "digital terrorism", but it is annoying and hard to stop on an individual level because of the design of the internet.

> namely BGP DDoS attacks would still occur if we used a routing protocol other than BGP. It's not created by BGP, it's created by the fact that the Internet is end-to-end oversubscribed.

The weakness in the internet that allows for DDoS is that you can't tell your peers to filter incoming traffic on your behalf, so you need to discriminate on the edge. The attacker still gets to eat up your bandwidth and CPU time.

Re: Cloudflare's abuse policies and approach

#180
post #161

Earlier quoted context omitted.

They address this: > Giving everyone the ability to sign up for our services online also reflects our view that cyberattacks not only should not be used for silencing vulnerable groups, but are not the appropriate mechanism for addressing problematic content online. We believe cyberattacks, in any form, should be relegated to the dustbin of history.

My point is this: if there are certain types of content that they deem unacceptable to host, why do they deem it acceptable to protect? I disagree that the paragraph you quoted is relevant to that. But if it is, then it doesn't seem good that their goal of eradicating cyberattacks is more important to them than actual human lives.

No post body was provided.
Post reply on HN