Live data from Hacker News

Cloudflare's abuse policies and approach

blog.cloudflare.com

861–870 of 1001 posts

Re: Cloudflare's abuse policies and approach

#861
post #820
post #224

Earlier quoted context omitted.

Wikipedia has information on 3 suicides related to KiwiFarms: https://en.wikipedia.org/wiki/Kiwi_Farms#Suicides_of_harassm...

Joshua Moon, the owner of Kiwifarms was on Rekieta Law[1] and provided his view that kiwi farms did not cause these suicides [1] https://www.youtube.com/watch?v=gP92u3ld1-w

I can see no reason why the owner of kiwi farms would want to believe that kiwi farms wasn't directly responsible for suicides (and terrorism via swatting). /s

Of course kiwi farms caused those suicides.

Re: Cloudflare's abuse policies and approach

#862

Earlier quoted context omitted.

You are pretty much saying "but it's okay when we do it." If doxing and criticizing people for their beliefs and practices is not okay for the right to do, then it's not okay for the left to do either.

So you're fine if I post your SSN on this site? And let's assume the mods also co-sign that decision in this hypothetical, so you're okay with your PII being out there for anyone (and I mean anyone) to see and use? You wouldn't even try to subpoena Y Combinator for my information on file such as my IP logs and email address (necessary for registration) to serve me notice? I seriously doubt that. I'm sure you would la…

> But it seems you're fine with Kiwi Farms literally posting SSNs, bank balances, passwords to accounts, and much more.

Small correction, this doesn't happen on Kiwi Farms. Kiwi Farms is focused on discussing much more mundane, public drama. Just interactions between people, mostly on public social media like Twitter, Youtube and others. Things like hacking, private financial information, DDoSing, swatting, are all heavily policed on Kiwi Farms. Additionally, directly interacting with the subject of a thread on Kiwi Farms is also bannable.

Their ethos is watching monkeys in the zoo, not going out and poking them themselves.

There's actual shady forums out there that do those illegal things, generally hosted in foreign countries or behind Tor.

Re: Cloudflare's abuse policies and approach

#863

Earlier quoted context omitted.

> They're going to find a new, harder to harass vendor for CDN. This is a good thing. It raises the barrier of entry to do what they want to do. They will likely provide a worse service as well.

> It raises the barrier of entry to do what they want to do. How so?

Any other CDN that will host then will not be as smooth and as capable and as well advertised as Cloudflare.

It will be harder to get protection, so fewer sites will be able to succeed.

Re: Cloudflare's abuse policies and approach

#864
post #646

Earlier quoted context omitted.

You seem to be pretty active in comments for this post and you have made several arguments around the ideas that: * CF is not a utility and is not bound by the First Amendment (although you keep saying free speech) * CF is somehow immoral because they are otherwise compelled to remove content/service protections for stuff you disagree with (however correct you may be that the content is morally reprehensible). The fi…

It's precisely that their leadership (rank-and-file employees I know have different feelings) are taking an absolutist approach. That's pretty evident when their stance is that banning nazi sites was a mistake. My position is this. That is not a good stance to take. And people should now use their wallet to influence Cloudflare's leadership to reconsider their extreme position. The small part I can play in that today…

You're being intentionally dishonest. Their stance is not as simple as "banning the nazis was wrong. We need to bring back the nazis to our platform." They are pretty explicit in saying no company should be exercising the power that they did - if someone is willing to pay for DDoS protection on their site, they should take a neutral stance on the content of their site. Anything that is blatantly illegal is for the government to act on.

Do you think people should vote with their wallet in regards to the ACLU? What about the idea of public defenders generally? Should society not be footing the bill to be provide legal defense to hate crime offenders/rapists/etc?

Your characterization that their position is extreme is also dishonest. It's been the MO for American citizens/corporations/institutions and ingrained in 20th/21st century American jurisprudence to take a neutral stance when it comes to providing a service or defending rights. It's, frankly, one of the last few admirable things about our society.

You can promote an activist mindset if you'd like, but you should also consider that your opinion is only shared by a vocal minority and the fracturing of commerce into parallel economies won't benefit you or the communities you care about the way you think it will. I'm not sure what I need from CF, but after reading your comments/opinions on the issue, I'm inclined to just order shit from them now.

Re: Cloudflare's abuse policies and approach

#865

Earlier quoted context omitted.

I'm not sure hosting something and ensuring it's accessible are different really. But the Cloudflare CEO is. And they don't host Kiwi Farms. Or do they? The CEO said CDN isn't hosting. But it fits the common definition.

I see. So maybe we should go after the ISPs transmitting the information too?

There's a discussion that could be had about whether it's appropriate for ISPs to block sites that are strongly associated with terrorism.

I don't think that discussion can reasonably happen on this forum, but I think there are interesting philosophical positions that are valid that we should put against one another.

Re: Cloudflare's abuse policies and approach

#866

Earlier quoted context omitted.

Absolutely, but, Canadian law would absolutely allow illegally-collected evidence. The trial against the officer invading the defendant's privacy is a separate matter; the goal of a trial is to determine the truth of matters, after all, and if the defendant did kill someone, all evidence to support (or refute) that is generally admissible.

Nitpicking the details of the example isn't really a reputation of the more general point, though.

The details are the entire thing! The principles that we should have fair trials due process are followed, but, you end up with wildly different conclusions.

Re: Cloudflare's abuse policies and approach

#867
post #62

I don't understand why Cloudflare believes it is their responsibility to protect content that they admit to finding morally reprehensible when they are under no moral or legal obligation to do so. It seems that Cloudflare believes that they are the only ones who can protect the websites hosting this content from being DDoS'd out of existence, and thus they are protecting their right to freedom of speech. But the owne…

I feel like you missed the core points of this post. - Precedent from decisions on The Daily Stormer and 8chan was used to pressure Cloudflare to deplatform human rights organizations by authoritarian governments. Refusing to deplatform isn't about protecting Kiwifarms, but protecting other groups in a global environment where they face legal and social pressure on differing and conflicting views. A hands-off policy…

So wait, they don't get paid, meaning they are happy to provide protection to these sites at their expense? You see how that's worse, right?

Re: Cloudflare's abuse policies and approach

#868
post #756
post #27

Earlier quoted context omitted.

8chan users radicalize each other and encourage each other to commit mass shootings. KiwiFarms users post the personal information of people and encourage each other to harass them to the point of suicide. I don't see how they aren't comparable.

What is the distinction you are drawing between a death from a swatting and pulling the trigger yourself? Is this some "I didn't kill you, I just tied you up and left you on the tracks at 11:55 for the noon train" distinction? And just because the attacks aren't explicitly coordinated on the site doesn't mean there's not culpability there... if an 8chan user is radicalized by 8chan and attacks a target suggested by 8…

I think the post you were replying to was agreeing with you. "I don't see how they aren't comparable", i.e. they are comparable.

Re: Cloudflare's abuse policies and approach

#869

Earlier quoted context omitted.

They've decided they want to be seen as a utility. You undermine your DDOS protection business if you drop controversial customers. They are exact type of customer who need DDOS protection the most.

Utilities are heavily regulated and mandated. If they're asking for the cake, they should have it whole.

The entire reason they are mostly focusing on getting DDoS protection services to drop KF, is it's seen as the most promising approach to kick the website offline. Most other things you need to be on the Internet are either already utilities, or are reasonably possible to maintain yourself or find one provider among thousands. DDoS protection is not like that, you need an unreasonable amount of equipment and money to do it.

If CloudFlare folds, either the website will get knocked to DDoS, or it will find another of the few remaining DDoS protection services, which will be also invariably pressured to drop them, and as smaller players they will have an even greater incentive to fold to avoid a PR disaster. Repeat until they run out of DDoS protection services willing to protect them.

But, as far as I can tell both the owner of KF and its associated companies are located in the US and what they do is technically legal (they've not been convicted as far as I know). So, if they are unable to get on the Internet, that'd make a fantastic argument for regulation of DDoS protection services, which I guess is what CloudFlare is trying to avoid here.

Re: Cloudflare's abuse policies and approach

#870

Earlier quoted context omitted.

And let's be real. DDoS attacks are acts of digital terrorism. They're attacking infrastructure due to political motives. These people who want to revoke DDoS protection for groups they don't like are essentially promoting terrorism. Why else would they fight so hard to remove DDoS protection, if not because they simply want those attacks to succeed?

DDoS is a product of an inherent weakness of the internet infrastructure, namely BGP. Cloudflare "solves" this by acting as a middleman, and charging for their service. I don't know if I would describe a DDoS attack as "digital terrorism", but it is annoying and hard to stop on an individual level because of the design of the internet.

It's a problem that stop on an corporate level is also hard. Ultimately CDN is the only mitigation.
Post reply on HN