Live data from Hacker News

I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

rasbora.dev

121–130 of 244 posts

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#121
post #76

Earlier quoted context omitted.

These defenses of Cloudflare's behavior are getting very silly. Is there anything that Cloudflare could protect that you wouldn't be OK with? Because a DDoS-for-hire service is illegal, unethical, and contradictory of Cloudflare's stance that "cyberattacks, in any form, should be relegated to the dustbin of history."[1] Most importantly, it should be obvious to anyone that a company that has a purported goal of prote…

I don't really give two hoots about Cloudflare, I just don't like false statements, like when "Cloudflare helped me run a DDoS network" actually means "Cloudflare kept my website from being DDoSed", with the addendum "and I'm bad, therefore, not protecting KiwiFarms is hypocritical." It's just dumb.

You have admitted in your earlier comment that "Cloudflare was helping keep his website up." You are saying that "Cloudflare helped keep his website up" does not logically imply "Cloudflare helped me run a DDoS network".

Even if you genuinely believe that, how are you confident enough that people generally share your interpretation of what constitutes help to call the statement in question "false"?

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#122

If SWATing is the weapon of choice for harassment mobs, then fix that first. Note that this particular SWATing wasn't in the US, it was in Canada -- so it's not necessarily even a uniquely American problem.

> If SWATing is the weapon of choice for harassment mobs, then fix that first.

How do you counter this weapon? Obviously you have to break the kill chain, but which part?

1. A target is geolocated; this is impossible to prevent if the target shares this information about themself freely.

2. The attacker makes a phone-call to emergency services, likely but not necessarily using a method they believe will anonymize them. Is it technologically feasible to close anonymity holes in the phone system? Should 911 calls from anonymous numbers be null-routed?

3. The attacker needs to persuade the emergency operator that an armed police response is necessary. This is theoretically possible in any country that believes armed police responses are sometimes needed, even those in which police normally patrol without weapons.

4. The armed police response will probably fail to kill the target. This seems to be the weakest part of the kill chain, where most murder-by-swatting attempts fail. Training police for this scenario could reduce the risk even more, but the possibility of an accident will always be non-zero if you have armed police responding to what might be some sort of murder in progress.

I think SWATings would probably continue to happen even if you completely resolved that third or fourth stages, eliminating the possibility of an accident completely. The anonymous troll probably still gets his rocks off at waking up the victim in the middle of the night by unarmed conflict resolution social workers banging on his door looking to resolve the [probable] misunderstanding. Breaking the kill chain at the second stage seems more promising for this reason, but I am not sure eliminating anonymous 911 calls is practical or ethical.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#123

The deplatforming logic is practical but pretty shaky as a long term strategy. Kiwifarms absolutely may have been a despicable place causing real harm to people. In that case, the police should initiate a request to take them down that Cloudflare or ISPs etc. are obligated to follow. The problem is the government is completely ineffective and regularly offloads their responsibility to platforms like Facebook, Cloudfl…

The trouble of course is that you have a technology enhanced libertarian movement convincing everyone that government shouldn’t be regulating anything except property rights

EDIT: shout out to all the techno libertarian hacker news bros downvoting my critique of techno libertarianism

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#124

Earlier quoted context omitted.

Sure, but what about the company that they rented the car from? Or the company they bought car insurance from? In the eyes of the law, the intent of the person is often (not always) extremely relevant.

> Sure, but what about the company that they rented the car from? Or the company they bought car insurance from? I expect if they said "I want to rent a car to use as a getaway vehicle for a bank robbery" whilst standing next to a TV showing a picture of them committing a bank robbery, yes, the rental company would have some culpability.

Did cloudfares customer tell them they wanted their services for DDOS?

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#125
post #26

Earlier quoted context omitted.

Pay per packet. I remember maidsafe was working on this for many years without much success. Then they got into crypto for micropayments a decade later and it all got a bit messy. Not sure how the project is doing these days but it was a solid concept at heart. https://maidsafe.net/ > legitimate customers who don't know the first thing about auditing their network for compromised devices An IoT device not suddenly wo…

So you want to put everyone on a metered internet connection? And then hit them with massive bills if they have a device that gets hacked? Seems unreasonable given the current state of security.

Was referring to a separate network if you briefly care to check the link I posted. DDOS'ing becomes a very costly endeavour, site owners don't need third parties to step in.

> And then hit them with massive bills if they have a device that gets hacked?

A ddos botnoet uses very little bandwidth in total for the individual, but yes someone should pay and there's certainly far worse things that can happen if they weren't made aware of a compromised device.

At some point global society has to decide whether we just employ more body scrapers to clean up the mess or stop letting people drive as drunk as they want on the roads. Cloudflare is the former.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#126

Exactly as expected. The more websites CloudFlare bans, the more its reputation will sink, the more enraged and demanding the pro-censorship mob will become. I note this one more time: almost no posts talking in favor of banning stuff here specify any objective limiting principle of where it should stop. It's like an exercise of deliberately creating a slippery slope.

But Brain virus, the slippery slope isn't real. It's a fallacy /s

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#127
post #73
post #63

Earlier quoted context omitted.

If you don't hold people accountable for their devices, what reason do they have to care about that security?

I think that it's morally wrong to push the burden to end-users. If anyone should be accountable it must be the companies producing the devices and software.

End-users would likely end up in large class actions against the manufacturers in such a hypothetical situation.

While turbulent for a brief moment it would be a strong market incentive for those who pump out insecure devices to change their ways.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#128
post #58
post #51

Earlier quoted context omitted.

There's something very wrong with the game community. I've learned enough during stupid internet fights I have had on reddit to never continue a conversation with an avid gamer, no matter the subject. Stories like this one you linked to on merkur.de (read via Google Translate, but I think they got it right) confirm to me that that was the correct call.

Why game community? It's more like all of the world enjoy games, including these sociopaths. You are chasing a red herring.

> Why game community?

At some point you have to blame the community itself, that example OP linked to is not an isolated incident, unfortunately.

Later edit: This [1] is a very sick and not ok community, a very sick one. Harassing a person in his own village, in his own house, on the streets of his own physical community, it's not ok. I didn't know who that Drachenlord person was until seeing OP's link, I'm left wondering how come all of that is legally possible, how come those persons that physically harass him are not in prison by now.

[1] https://youtu.be/-__r5B84Ymg?t=488

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#129
post #118
post #111

Earlier quoted context omitted.

> I also don't want Twitter mobs and DDoS-ers to have a say in what I can and can't read. This is honestly what I find the most disturbing about the entire story. This "keffals" person -- an individual! -- managed to organise enough attention to make all of this happen. From what I understand the argument is based on a threat towards this person, but considering the (public) information they were gathering on them (F…

> most of what was being posted was perhaps vulgar and certainly impolite, but practically harmless It was this mild but cloudflare took it down?

Here is an overview of some of the terror that was organized from kiwifarms:

https://twitter.com/oneunderscore__/status/15657972205318144...

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#130
post #80

Earlier quoted context omitted.

> No, it means Cloudflare was helping keep his website up, in a neutral manner. I think it's more subtle than that. It was keeping his website up to make a profit. It benefits Cloudflare to have powerful, well run bot networks out there ready take out any site which do not have Cloudflare's protection. Yeah, it's a neutral manner on one level, but at a higher level it's bit more nuanced.

I feel like that's assuming a lot about Cloudflare - what evidence is there of such Machiavellian maneuovres on their behalf? Would it be impossible to run DDoS as a service for profit without Cloudflare? People were doing fine at just that before Cloudflare ever existed.

> Would it be impossible to run DDoS as a service for profit without Cloudflare?

Quite frankly, yes. Before CloudFlare won the race to the bottom, you'd have to front thousands of dollars per month for bulletproof DDoS shielded hosting to get started.

There is a finite amount of DDoS-for-hire business that used to keep itself in check because they were constantly throwing attacks at each other raising everyone's "cost of goods sold" so to speak. By protecting these providers shops and ignoring abuse complaints CloudFlare helps more of them stay in business increasing the frequency and size of attacks needing to be mitigated.

I do not believe CloudFlare really thought this out. I believe it was a happy accident.

Post reply on HN