> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…
And let's be real. DDoS attacks are acts of digital terrorism. They're attacking infrastructure due to political motives. These people who want to revoke DDoS protection for groups they don't like are essentially promoting terrorism. Why else would they fight so hard to remove DDoS protection, if not because they simply want those attacks to succeed?
Cloudflare's abuse policies and approach
201–210 of 1001 posts
Re: Cloudflare's abuse policies and approach
#202It's rather disappointing that Cloudflare's policy is to not host content that is "illegal, harmful, or violates the rights of others, including content that discloses sensitive personal information, incites or exploits violence against people or animals, or seeks to defraud the public", but they do not apply that same policy to content that they provide DDoS mitigation services for. I don't see why their policies sh…
They address this: > Giving everyone the ability to sign up for our services online also reflects our view that cyberattacks not only should not be used for silencing vulnerable groups, but are not the appropriate mechanism for addressing problematic content online. We believe cyberattacks, in any form, should be relegated to the dustbin of history.
If Matt Prince were the head of the Inglorious Basterds, he’d evidently reform them to vote blue instead of scalping nazis
Re: Cloudflare's abuse policies and approach
#203Earlier quoted context omitted.
The weakness in the internet that allows for DDoS is that you can't tell your peers to filter incoming traffic on your behalf, so you need to discriminate on the edge. The attacker still gets to eat up your bandwidth and CPU time.
BGP absolutely does allow you to tell your peers to filter traffic before passing it to you. https://www.rfc-editor.org/rfc/rfc7999.html
What you need is something like a whitelist-by-public-key or hashcash or something.
Re: Cloudflare's abuse policies and approach
#204Earlier quoted context omitted.
Stopping terrorist attacks is also how the NSA vindicates spying on every internet user. It's up there with "think of the kids!". It's an excuse though - and people will extend "terrorist attacks" to include non-violent protests when it suits them.
Except this isn't a "we should record everyone's interactions to stop terrorism" it's "we should stop hosting propaganda for terrorists, especially when that cessation doesn't harm others (dropping hosting for their website does't impair other people's liberties, whereas spying on everyone's messages would)"
Re: Cloudflare's abuse policies and approach
#205Earlier quoted context omitted.
Quoted post unavailable.
The net interprets censorship as damage and routes around it. The push to platform everyone you don't like is accelerating radicalization. Instead of just existing as a small number of weirdos on mainstream platforms with millions of users, they are now building their own silos. Forced from internet infrastructure and payment networks, they are forced to build their own platforms and banks. This is happening now. The…
This is _not_ about that - these people are building their own siloes; Cloudflare are hosting them. If Cloudflare stop providing services to them it will reduce their ability to host their own siloes.
Re: Cloudflare's abuse policies and approach
#206Earlier quoted context omitted.
This policy seems to only apply to content that they host. It appears that they don't intend to apply this policy to websites that they are only providing DDoS mitigation to, such as KiwiFarms. Whether Cloudflare is hosting the content or mitigating DDoS attacks against it, they bear some responsibility for the content being accessible. I see no good reason for them to have different policies between their hosting an…
> I think one easy thing they could do, is stop hosting for forums dedicated to doxxing and harassing people > This policy seems to only apply to content that they host. Yes, which is exactly what the parent commenter was saying.
Re: Cloudflare's abuse policies and approach
#207Earlier quoted context omitted.
They've decided they want to be seen as a utility. You undermine your DDOS protection business if you drop controversial customers. They are exact type of customer who need DDOS protection the most.
> They are exact type of customer who need DDOS protection the most. They (KiwiFarms, Daily Stormer) would be better not on the internet. > They've decided they want to be seen as a utility. This isn't how law works - just as you can't say "we don't have a banking license but we'd like to be seen as a bank and provide banking services" you can't say "we're not a utility but we'd like to be seen as one". Note that bei…
> > They (KiwiFarms, Daily Stormer) would be better not on the internet.
DDOS protection only exists because some people are willing to illegally target websites they believe would be better not on the internet. It's the entire point. Folding to publish pressure for one customer weakens their case for protecting others.
Re: Cloudflare's abuse policies and approach
#208Re: Cloudflare's abuse policies and approach
#209It's rather disappointing that Cloudflare's policy is to not host content that is "illegal, harmful, or violates the rights of others, including content that discloses sensitive personal information, incites or exploits violence against people or animals, or seeks to defraud the public", but they do not apply that same policy to content that they provide DDoS mitigation services for. I don't see why their policies sh…
They address this: > Giving everyone the ability to sign up for our services online also reflects our view that cyberattacks not only should not be used for silencing vulnerable groups, but are not the appropriate mechanism for addressing problematic content online. We believe cyberattacks, in any form, should be relegated to the dustbin of history.
Re: Cloudflare's abuse policies and approach
#210>For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation service we worked with our Proudflare employee resource group to identify an organization that supported LGBTQ+ rights and donate 100 percent of the fees for our services to them.
I find this section peculiar. Why does the company have "values"? I though companies were supposed to be looking after the intrests of their shareholders, i.e., profit. Do the shareholders consent to the lost profit being donated to political motives? This broader trend of companies becoming political organizations is terrible, frankly.
But even with that said, I find their stance in the article to be hopeful, and sincerely wish that they stay true to their words in this paragraph.
>To be clear, just because we did it in a limited set of cases before doesn’t mean we were right when we did. Or that we will ever do it again.