Live data from Hacker News

IP address blocking banned after anti-piracy court order hit Cloudflare

torrentfreak.com

61–70 of 92 posts

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#61
post #5

IP address blocking may have been banned, but DPI to block domains based on SNI is alive and kickin'. I've seen people talk about encrypted SNI for a very long time now and it's still not working; someone must have dropped the ball pretty hard regarding that

The evolution of ESNI into ECH has been slow but basically encryption of just the SNI would not play nicely with the rest of the protocol. So more had to be encrypted but that meant a deeper interaction to analyze.

It's also dependent on a new kind of DNS record and the original design wasn't great for DNS load balancing. Some tweaking had to happen there too.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#62
post #46

Earlier quoted context omitted.

And despite not having net neutrality in the US not a single one of the fears came true. Which is what I said way back then: There's nothing wrong with net neutrality but it's simply not necessary.

but they could have. still could. and you might not even know. and the fact that one of our political teams has been fighting SO HARD against net neutrality is a big red flag. protections are important even if someone's not actively and noticeably abusing people right this minute.

There's been exactly zero problems in 20 years (the idea was introduced in 2003), yet somehow "still could. and you might not even know.".

No one is fighting "so hard" this is a dead topic.

T-Mobile offers to zero rate YouTube if you let them throttle it - it's your choice. Would that be legal under Net Nutrality? Would they have to get permission from YouTube?

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#63
post #27

> When the ISPs discovered that the IP addresses belonged to Cloudflare, arms were thrown up in despair. The level of desperation the ISP’s engineers have felt in front of such incompetence must have been through the roof. I am getting tired of our politics here in europe: tech literate people in governments are put to work on surveilance stuff, never for actual policymaking. The shit show continues.

Surely they should have contacted Cloudflare and asked them to sort out the issue with their network ... CF will probably retort {common carrier, we are American and you are not etc}. Austrian policy makers get upset and ... THIS NONSENSE IS STILL NOT SORTED. The internets are somewhat broken, quite badly. We all allow ourselves to end up in a series of virtual walled off silos - Facebook, Twitter etc, run by some pr…

> CF will probably retort {common carrier, we are American and you are not etc}.

Considering how quickly they reversed course on their grand statement about having principles, any such retort would probably be about as effective as they predicted in that statement.

.

> The internets are somewhat broken, quite badly. We all allow ourselves to end up in a series of virtual walled off silos

The problem with the Internet is that between nat and annoying rules and asymmetric connections, most home connections aren't suitable for serving things.

The big services being centralized isn't a problem with the Internet, which can be seen from how often non-Internet things consolidate the same way.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#64
post #50

Earlier quoted context omitted.

Layer 7 gear has been around for a long time. At an ISP level I’d be shocked if they weren’t running big F5s or something similar that can handle this properly. Actually do so is another matter entirely though, and I’m not even considering throughput.

Layer 7 gear has also been pretty irrelevant for a long time and not really something an ISP wants to waste money on when all it needs to do is deliver L3 fast and cheap. First payload encryption, then protocol encryption like the aforementioned ESNI or QUIC, and now DNS encryption. Even if you invest in it how much good is it going to do? Most ISPs have boxes that can handle volumetric attacks and the minimum requir…

Oh, I totally agree. Sorry, I just re-read my post and it does come across as “they should just use layer 7 gear to filter it”.

I certainly wouldn’t expect to see it in the real world, I was mostly just musing on ISPs deploying/leveraging their layer 7 gear if required.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#65

The association of IPs to individuals and particular services is the original sin of the Internet. At Cloudflare, we’re working to fix that sin. That doesn’t mean governments don’t have the right to regulate content on networks in their boarders: they absolutely do so long as they follow principles of Rule of Law. But blocking on an IP can never be transparent — and therefore violates the Rule of Law — and will alway…

> The association of IPs to individuals and particular services is the original sin of the Internet. At Cloudflare, we’re working to fix that sin.

... Being able to talk to someone without an intermediary is a problem?

> That doesn’t mean governments don’t have the right to regulate content on networks in their boarders: they absolutely do so long as they follow principles of Rule of Law.

Pretty sure governments have the right to do whatever they want regardless. It's that pesky "sovereignty" thing.

> But blocking on an IP can never be transparent

What do you mean by this?

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#66

The association of IPs to individuals and particular services is the original sin of the Internet. At Cloudflare, we’re working to fix that sin. That doesn’t mean governments don’t have the right to regulate content on networks in their boarders: they absolutely do so long as they follow principles of Rule of Law. But blocking on an IP can never be transparent — and therefore violates the Rule of Law — and will alway…

give me a break. blocking with collateral damage is the cloudflare modus operandi

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#67
post #11

I always assumed businesses such as Cloudfare or Google would have a good reason to be the main IPFS or tor node hosts, since that can help improve the backbone infrastructure for this side of of the internet, and can also help catch bad actors if there are any there (easily turn in all logs to three letter agencies if they knock, or they can simply offer it up for anon tips).

... They should host the big anonymous services for the purpose of being able to break that anonymity? Somehow I think that might not go over so well.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#68
post #46
post #7

> According to reviews conducted by local telecoms regulator TKK, the IP address blocking violated net neutrality regulations and will no longer be allowed. Thank god for net neutrality. We of course have that here in America right? Cus freedom!

And despite not having net neutrality in the US not a single one of the fears came true. Which is what I said way back then: There's nothing wrong with net neutrality but it's simply not necessary.

> And despite not having net neutrality in the US not a single one of the fears came true.

That same set of scoundrels[1] that CF backtracked on defending keeps having routing issues (on top of their ddos issues).

Supposedly they (or someone related?) recently complained to a state AG under a state-level net neutrality rule. Not sure if it's been long enough to know if anything'll come of it.

.

[1] https://www.goodreads.com/quotes/52416-the-trouble-with-figh...

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#69
post #39

Earlier quoted context omitted.

Courts don't work like computer programs, if the court order would have clearly unintended outcomes then you have some option to in good faith not comply with the order, have your lawyers raise it with the right politicians or courts, and not end up in legal trouble. The job if the engineer who notices this is to raise it to their boss and legal counsel and let them decide whether you should still execute the planned…

> The job if the engineer who notices this is to raise it to their boss and legal counsel... ...shouldn't the legal department be involved way before the issue reaches the engineer? Why should the engineer ever care about it in the first place? Chances are these orders do not come directly to their email.

> shouldn't the legal department be involved way before the issue reaches the engineer?

Possibly, but the legal department might not know what cloudflare is or the implications until the engineers explain it.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#70
post #34

Earlier quoted context omitted.

It's mostly navy run right now is my understanding, and used by journalists, so I don't see how it's that much of a downgrade.

It was started by the Navy way back in the '90s for secure communication online. Then the source was released like a year after being made public and development was funded by the EFF until the Tor Project itself was officially founded. They still do (or did?) get grants from a few federal agencies though. But they had no strings attached. This is probably what you're thinking of. Source: Hung out with a few Tor devs…

I think they meant it's believed that most/some exit nodes are run by US intelligence to spy on people. Not that development has anything to do with them now.
Post reply on HN