Live data from Hacker News

Cloudflare's abuse policies and approach

blog.cloudflare.com

491–500 of 1001 posts

Re: Cloudflare's abuse policies and approach

#491

> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…

Cloudflare is not a public service, the comparison with firefighters is not apt. I’ve been seeing this confusion more and more recently, probably because of the size and omnipresence of corporations. I don’t know if this confusion is deliberate to justify certain acts or simply ignorance, but the distinction has to be emphasized. Corporations and public services are completely different beasts, with different legisla…

The point here is that Cloudflare's core product, despite being run by a private for-profit company, is as close to an essential service as it gets in the digital world. This is not the same as saying "posting on Twitter is a civil right"

Re: Cloudflare's abuse policies and approach

#493
post #458

Earlier quoted context omitted.

> Large corporations policing free speech Let me stop you right there. This is not a free speech issue. Please be precise with your terminology.

And let me get you out the way so gp doesn't get sidetracked. Nobody needs pedantry when the subject under discussion is existentially important, and every normal person already knows what the problem is.

Firstly, this is not existentially important aside for the people whose lives are ruined (and will continue to be ruined) by Kiwi Farms. Secondly, "every normal person already knows..." doesn't mean anything, because (a) you don't get to declare what normal is, and (b) you don't know that.

Re: Cloudflare's abuse policies and approach

#494

Earlier quoted context omitted.

They do have an agenda for sure. That wasn't the question, tho. The question was whether they condone or even encourage their users to target people with the goal of driving those people into suicide? This might be well the case. I am not one of their users nor am I educated in this matter, so I'd like to know too. When somebody makes this claim, as has been made multiple times in the threads here, with demands to th…

Josh Moon (founder) gloating on stream about getting Chloe Segal to kill herself after KF harassed her for 5 years https://twitter.com/keffals/status/1564490554754433025

For context, because I didn't know and I'd think others might not either: Apparently Chloe Segal killed herself by going to a public park and lighting herself on fire, telling witnesses in a spoken suicide note her reasons were homelessness and mental health issues.

Josh Moon then playing "Fire" ("I am the God of hellfire and I bring you fire") is in extremely bad taste and outright vile. I can very well see this as gloating.

And yet, it does not prove kiwifarms direct involvement. It's a short extract from a stream he did. Playing devil's advocate for a second, it for example might very well have been a response to media at the time already claiming he/kiwifarms was to blame for the suicide and therefore a rather misguided attempt to poke fun at what he might have considered unfair reporting.

Re: Cloudflare's abuse policies and approach

#495

Earlier quoted context omitted.

Is Cloudflare a government service? Do local fire departments remove copyright infringers' sheds?

First of, not all fire departments are government services. Sometimes they are private associations of volunteers that receive marginal if any taxpayer support. Other times, they are for-profit corporations. This is particularly true when another company needs specialized firefighting services because they are remote or handle materials and situations the local government-supported firefighters aren't equipped to han…

Cloudflare is not a private association of volunteers. Private fire fighting services are not called fire departments commonly, are plural, and are not local frequently. My response is still the analogy is bad. We can understand the situation better without trying to imagine what fire would be like if it didn't spread.

Re: Cloudflare's abuse policies and approach

#497

> Some argue that we should terminate these services to content we find reprehensible so that others can launch attacks to knock it offline. That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character. > For instance, when a site that opposed LGBTQ+ rights signed up for a paid version of DDoS mitigation…

> We don't and won't talk about these efforts publicly because we don't do them for marketing purposes

in a post that further goes out of its way to say, "look at these morally good things we're doing (Galileo and Athenian) that aren't themselves part of the abuse process, and then has their logos as two of the three images in the article body? Okay, sure, this may not strictly be marketing material insofar as it's not an ad the marketing team purchased, but c'mon, did ya'll put those in place to help explain the abuse process or because they're nice "but look, we also do good things!" window dressing on an article you think otherwise may not have the best reception?

Re: Cloudflare's abuse policies and approach

#498
post #394

Earlier quoted context omitted.

When I checked last week, their origin IP was trivially available. I found it by typing “kiwifarms” into search.censys.io

Right now their server can simply block all IPs and all certs not from Cloudflare. Firewalls resists DDoS better than web servers and DBs

If they allowlist Cloudflare IP addresses, they should be careful that list only includes the IPs of the caching servers, and not of the exit nodes for the free WARP VPN service.

These both share the same AS number, I think. I’m not sure if Cloudflare segregates WARP traffic or publishes a list of WARP exit IP addresses.

Aside: It’s not that simple of a problem, is it? Because there’s also CF workers, which execute on caching servers and can therefore send outbound requests with the IP of the caching server. (That said, I don’t know the details of this routing config, although I’m now curious to test it.)

Anyway, I think an IP allowlist is probably the most crude starting point - I’m pretty sure CF has some products that are better suited for it (mTLS maybe, and that server side WARP VPN product they had at some point - I’m not up to date on this).

Re: Cloudflare's abuse policies and approach

#499

Earlier quoted context omitted.

> Large corporations policing free speech Let me stop you right there. This is not a free speech issue. Please be precise with your terminology.

It's an American company hosting content for an American. The laws of America apply.

Precisely, they do! Which is why this isn't a free speech issue. Cloudflare is not a utility, nor are they a government entity.

Re: Cloudflare's abuse policies and approach

#500

Earlier quoted context omitted.

> Large corporations policing free speech Let me stop you right there. This is not a free speech issue. Please be precise with your terminology.

> This is not a free speech issue. Please be precise with your terminology. Let me take a stab in the dark: you think "free speech" refers only to the United States' First Amendment, and not a universal principle, which: * according to Wikipedia, is "a principle that supports the freedom of an individual or a community to articulate their opinions and ideas without fear of retaliation, censorship, or legal sanction"…

You're shifting goalposts.
Post reply on HN