Earlier quoted context omitted.
It makes a very broad claim which makes it sound like an extortion racket but doesn't have anything to back it up. I would bet that if it included some evidence it would fare much better. For example, they have a ton of large organizations which are customers. The very first question the average reader is going to have is whether it's really the case that these sites are predominantly attacked by booter services whic…
The claim was discussed in this post: https://news.ycombinator.com/item?id=32709329 Basically DDOS booters use Cloudflare to protect their websites from competitors, since Cloudflare is one of the best. The same people Cloudflare is protecting (and claims to do so on an ethical neutrality basis) is furthering the need for Cloudflare to exist.
You don’t want to be on Cloudflare’s naughty list
231–240 of 354 posts
Re: You don’t want to be on Cloudflare’s naughty list
#232Earlier quoted context omitted.
I wonder if HN posters have ever held a job before. Can you explain why it's beneficial for Cloudflare to block legitimate users? Why is the simplest explanation "Cloudflare just hates this one user in particular?"
Well, apparently they scared this user into installing their browser extension, so it sounds like this incident was a win for them.
Re: You don’t want to be on Cloudflare’s naughty list
#233Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…
That wouldn't just be bad news, it would be disastrous news. It would immediately render the entirety of the web worthless to me.
Re: You don’t want to be on Cloudflare’s naughty list
#234Harsh blocking/limiting/challenging is way too valuable to sites that are actually trying to make money online. It's not going away short of legislation banning it. Losing 1/10,000 legitimate customers to cut fraud attempts, spam, exploit attempts, and so on, by 90% or more, is just too good a trade-off. I have bad news about the most-likely fix for it, longer term, so we can lay off the IP-based reputation stuff and…
An alternative that preserves some privacy also doesn't seem that hard to imagine... though it probably has its own can of worms*. Basically, the core problem is digital identities (accounts, IPs, phone #s etc.) are cheap to create (even considering captchas and all) so fraud is easy. The solution could be just to make it "costly" to create new digital identities. For example, you could get a "verified but anonymous"…
We already use this model in practice. It's why so many services require a phone number verification now - they are hard enough to get en-masse, especially if you block things like Google Voice. They even have a big advantage in that they are comparatively hard to hack, as the SIM card is effectively a weak form of physical security key.
I think the big problems this causes is discussed on HN quite often.
Re: You don’t want to be on Cloudflare’s naughty list
#235Re: You don’t want to be on Cloudflare’s naughty list
#236Earlier quoted context omitted.
I'm sorry. I have a colleague based out of Venezuela. We've had to work together to get tunnels and vpns configured so that he can get uncensored and secure internet access. But Tor is an enormous source of abusive traffic and if I don't filter it, then that's harmful to site owners. I'm being forced to choose between the needs of people that I know, work with, and depend on financially, and the needs of people in co…
There are probably more sophisticated options that would solve your problems than simply blocking it.
Re: You don’t want to be on Cloudflare’s naughty list
#237Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. A few months ago I got on Akamai's naughty list (with my other ISP) for some very light automated website downloading. That…
> Cloudflare is a regular problem for Starlink users. We're on CGNAT so users share IPv4 addresses. I see CAPTCHAs when using Starlink ten times as often as on my other ISP. I don't think it actually breaks things the way this article describes, it seems like a gentler behavior, but it's annoying. I've been noticing this too, and it's why Starlink remains my secondary ISP/bulk transfer connection. If I had to drop on…
Re: You don’t want to be on Cloudflare’s naughty list
#238I use a VPN, for perfectly legitimate reasons (I travel a lot, and most internet services assume that your IP address also indicates your nationality, citizenship, language, bank account country, etc. Being able to change IP source country is vital). Some VPN exit addresses have obviously been flagged as "bad" by Cloudflare and I get challenged with CAPTCHAs from some countries. It's an interesting experience, but lu…
Re: You don’t want to be on Cloudflare’s naughty list
#239Earlier quoted context omitted.
But how many of them: 1) refuse to take responsibility for content they host by claiming they don't host 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination 3) make the abuse reporting process intentionally difficult and time-consuming 4) want to aggregate all the DNS data they can by making a deal with Firefox to turn on DNS-over-https by default…
1) refuse to take responsibility for content they host by claiming they don't host >CDNs don't host content, they proxy it 2) discriminate against huge parts of the Internet with no publicly known rules, nor methods to change that discrimination >Not large parts of the internet, scammy and attacky parts of the internet. If the rules were public they wouldn't be effective. 3) make the abuse reporting process intention…
Hosting is providing services without which a presence on the Internet won't work. Hosting was around before the web, so how is it that you think you can magically come along and declare, "this is now the definition of hosting"? Only through bullshit.
If by "scammy and attacky parts of the internet" you mean whole countries, good for you for being an elitist.
I'm happy that you've "had an answer back within 24 hours", but that doesn't address the fact that it's time consuming and arduous. Notice that you didn't respond to that part at all. Their reporting site doesn't have an option for spam (because they don't care), the Javascript allows more text to be entered than the form will accept (so you have to know to go and delete some), and it doesn't allow nearly enough in the first place. For someone who wants to forward abuse to abuse@cloudflare, it's shitty and it's a way to discourage abuse reporting.
So tell me about how Google, Facebook and Amazon have never lied about what they're doing with data. Then go ahead and explain to me how it is that we're just supposed to trust Cloudflare. Audited by whom? When? How is there conclusive, testable proof that the data isn't analyzed or siphoned off somewhere else? Are you ignoring the fact that this is in part an attempt to become a monopoly, and in part an attempt to make it so that network-level filtering next to impossible? You didn't reply to any of this, which makes you seem all the more like a paid shill than someone who actually cares about an exchange of ideas.
But then you say, "every cdn centralizes the internet", which means you're either willfully ignoring the points brought up here, or you're really, really clueless and don't know how to respond to point brought up, so you talk about other things instead.
We don't need any more paid shills. If you really don't understand the points brought up about how Cloudflare is working tirelessly to become a monopoly in ways that are measurably different from regular CDNs, then ASK. If you don't understand how we (the Internet collectively) are going to assume that Cloudflare cares more about making money than about doing the right thing, then please look at all the privacy nightmares we've learned about Amazon, Google, Microsoft, Facebook, et cetera.
If you're just here to tell us how much you love Cloudflare, that's fine, too, but you don't do that by just randomly disputing points with irrelevant responses.
Re: You don’t want to be on Cloudflare’s naughty list
#240Earlier quoted context omitted.
I'm a noob, can you give me a pointer? What kind of abusive traffic is coming through Tor and why do they do it?
Mainly forms -- login forms, comment forms, signup forms. Bots use Tor pretty heavily because it's anonymous and hard to block them without blocking the entire network. Login form abuse is mildly irritating but not a huge deal if you have other measures in place. Comment spam is annoying but there are some options that deal with it pretty well. But the signup spam was a headache. I didn't want to just blackhole Tor t…
Solution: Require sign-ups by email, so the end account must actively send your mailserver a registration message. This also turns an open-loop control system into a closed loop control system, which is inherently easier to secure / keep safe.