Live data from Hacker News

Cloudflare's abuse policies and approach

blog.cloudflare.com

421–430 of 1001 posts

Re: Cloudflare's abuse policies and approach

#421
post #201

Earlier quoted context omitted.

The group they're trying to target here is a terrorist group. Not even in a metaphorical sense. It's people who try to harass random transgender people to the point of suicide or murder.

If they are a terrorist group (or otherwise doing something "wrong"), then the appropriate means to deal with that is courts and law enforcement, not a CDN.

pigs and domestic terrorists are the same group https://knock-la.com/tradition-of-violence-lasd-gang-history...

and they collude secretly with corporations to advance their powers mutually https://www.eff.org/deeplinks/2021/06/emails-show-amazon-rin...

I don’t ask someone to shoot their own foot to protect myself

Re: Cloudflare's abuse policies and approach

#422
Cloudflare showed themselves to be profit-driven and irresponsible years ago when they said they could not and would not take down blatantly illegal sites they host / facilitate (I don't buy in to their bullshit attempts to redefine "host") [1].

I get that you shouldn't be able to contact them, or any other entity, and just make a claim to get a site taken down (look at abuses of the DMCA), but when the illegality is unquestionable, it's just a sign that Cloudflare clearly doesn't want to set any kind of precedent about doing the right thing.

What's unquestionably illegal, you ask, because you're about to tell me how much of a grey area that is? Bank of America phishing sites are unambiguously illegal. Any reasonable human would say that anyone pretending to be Bank of America to try to steal credentials has no place doing so, and that there's no reason to not take direct action.

Sites hosting Adobe Flash "updaters" are also unambiguously illegal.

The fact that Cloudflare says they can't take down sites like these because they're protecting "First Amendment rights" shows that they don't want to be bothered with abuse complaints and they care more about profit than anything else [2].

It's disingenuous at best and purely evil at worst. It's saying, "I have the tiniest thread of a reason to continue facilitating illegal behavior because who really knows who BoA are?"

They said the same about Adobe Flash "updater" sites that provide Trojan / virus downloads.

If that's not bad enough, they refused for many, many months to answer a question directly, without diversions. I asked them:

"When I send abuse complaints to abuse@cloudflare.com, I get a form response that implies, but does not clearly state that action will NOT be taken unless I also visit Cloudflare's web site and fill out an abuse form there. Is it true that no action will take place unless I also fill out that form?"

They refused to answer directly, instead constantly telling me that filling out the form helps them improve abuse handling, et cetera. They would not answer yes or no, even when asked directly to answer yes or no. Who does that except assholes?

The form, by the way, has all sorts of issues which makes using it arduous and time consuming, which is, I suspect, exactly what they want.

When people have an opportunity to communicate unambiguously yet choose to double down on being vague, they show themselves to be assholes who want to manipulate others. They did, after many months, finally answer my question and acknowledge that they don't process abuse complaints if the web form is not filled out, but this was only after months of repeatedly asking.

I get that some people use their products and want to assume the best about Cloudflare because they like the products, but any shitty company with shitty, profit driven people running it can still have good products. I encourage those who think Cloudflare is good because their products are good to consider the end result should Cloudflare get their way.

Imagine this: a majority of the world hosts using Cloudflare's DDoS protection. They all have Cloudflare in their WHOIS. Much of the world also use DNS-over-https in their browsers. Cloudflare becomes a monopoly and gladly continues to ignore court orders and legal subpoenas. Network admins can no longer control their own networks - they can't block exposure to malicious sites using DNS or by blocking networks, can't stop CaC access, can't stop exfiltration of data because everything is going to and coming from Cloudflare, legitimate and malicious.

Not only have they re-centralized the Internet and have become a big, glaring, single point of failure, but they've weakened our networks and taken control of them away from us. They're privy to every DNS lookup we make and every web site we visit. As an entity based in the United States, all of this data is almost certainly available to the United States' surveillance apparatuses.

[1] "hosting" is providing material services without which certain things on the Internet wouldn't function. Consider the fact that Clouflare wants to redefine "hosting" to mean directly hosting a web site (not DNS, not email, not proxy services), but hosting existed before the web existed.

[2] It doesn't matter if scammers use Cloudflare's free services; the motivation for profit means they want everyone to use them, good and bad, so people can't easily block the bad without blocking the good. Protecting scammers sets precedents that discourage people from trying to blame Cloudflare for facilitating and hosting. Also, they want and intend to be a monopoly, so enticing people using free services is still profit-based, for those who can't think that far ahead.

Re: Cloudflare's abuse policies and approach

#423
This just reads like Cloudflare trying to dodge all culpability / wash their hands of the harm caused by those they knowingly provide services to by shifting the buck elsewhere.

Pretending courts are oracle machines that perfectly determine which sites should be permitted in countries and inferring selecting websites to provide security services to is a totally binary choice.

Re: Cloudflare's abuse policies and approach

#424

Earlier quoted context omitted.

An argument should be able to stand on its own regardless of which people believe in it or use it. As for the Twitter thread I've heard plenty of similar arguments before but I'm not a particularly big believer in them. Lots of people have very awful company (take for example Hollywood actors associating with predators) but that doesn't particularly mean that they are promoting or in agreement with the actions of the…

> * An argument should be able to stand on its own regardless of which people believe in it or use it.* Which is why I continued on with addressing the argument. > Lots of people have very awful company (take for example Hollywood actors associating with predators) False equivalency I'd say. Yes, the entertainment industry as a whole SUCKS. But if you think about it for even a second, you'll realize there is a differ…

You didn't give me an argument you gave me a twitter thread. The argument I interpreted from the thread was if you let your bar be associated with a Nazi (because you served them) then down the road they will invite their other Nazi friends and eventually your bar will become a Nazi bar. In the context of this HN thread I take this argument to mean, well Null is associating with people who harassed this woman to death, therefore Null supports it. Which is why I gave the response I did.

Re: Cloudflare's abuse policies and approach

#425
post #201

Earlier quoted context omitted.

And let's be real. DDoS attacks are acts of digital terrorism. They're attacking infrastructure due to political motives. These people who want to revoke DDoS protection for groups they don't like are essentially promoting terrorism. Why else would they fight so hard to remove DDoS protection, if not because they simply want those attacks to succeed?

The group they're trying to target here is a terrorist group. Not even in a metaphorical sense. It's people who try to harass random transgender people to the point of suicide or murder.

Is Homeland Security actively following and prosecuting that group you mentioned? I mean, on account of them being allegedly "terrorists".

Re: Cloudflare's abuse policies and approach

#426

> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…

No post body was provided.

Re: Cloudflare's abuse policies and approach

#427

> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…

And let's be real. DDoS attacks are acts of digital terrorism. They're attacking infrastructure due to political motives. These people who want to revoke DDoS protection for groups they don't like are essentially promoting terrorism. Why else would they fight so hard to remove DDoS protection, if not because they simply want those attacks to succeed?

Wow. So de-platforming Nazis is terrorism now?

Re: Cloudflare's abuse policies and approach

#428

Earlier quoted context omitted.

If they are a terrorist group (or otherwise doing something "wrong"), then the appropriate means to deal with that is courts and law enforcement, not a CDN.

This assumes that law enforcement is both effective and fair. It is neither. "Police exist, therefore nobody except the police is allowed to do anything about anyone's bad behavior" is a terrible argument.

It is the best argument we can have in a liberal regime. Anything else would lead us directly to tyranny, and not the metaphorical one.

Re: Cloudflare's abuse policies and approach

#429

Earlier quoted context omitted.

And let's be real. DDoS attacks are acts of digital terrorism. They're attacking infrastructure due to political motives. These people who want to revoke DDoS protection for groups they don't like are essentially promoting terrorism. Why else would they fight so hard to remove DDoS protection, if not because they simply want those attacks to succeed?

> They're attacking infrastructure due to political motives. They're attacking KiwiFarms for their agenda of trying to drive people to commit suicide.

No post body was provided.

Re: Cloudflare's abuse policies and approach

#430

The problem isn't that certain customers are bigots, but that they actively seek to allow harm to be done by their own end users like Kiwi Farms. The fact they have an exhaustive wikipedia for one person (Chris Chan) should have been the "nope" moment for them. Like if I was a host or a provider of a service and Josh Moon came to me with his site I'd just turn him away because he's like nuclear waste dangerous. It's…

The CWCki is not operated by KF, and at any rate is critical of Chris but not at all wishing death or violence on him. (And it is a wiki, not "a Wikipedia." Wikipedia is itself a wiki.)

And what does Josh's mother have to do with anything?

Post reply on HN