Earlier quoted context omitted.
>kid >2017 fucking hell
I know right! I feel so young. there are people on this site that were born in the previous millennium! :O
(reference: https://cdn.vox-cdn.com/thumbor/mO8UICqmeSd97l09w_FgSP1TDPQ=...)
161–170 of 236 posts
Earlier quoted context omitted.
>kid >2017 fucking hell
I know right! I feel so young. there are people on this site that were born in the previous millennium! :O
(reference: https://cdn.vox-cdn.com/thumbor/mO8UICqmeSd97l09w_FgSP1TDPQ=...)
Unrelated to the article but seeing .tk brings back many memories. As a kid without a bank account let's alone an international credit card (VISA/Mastercard), dot.tk is the only way to put a website online with your name. I created countless of websites with .tk for classmates, school and families.
I used .co.nr alongside .tk for a while, before moving to .co.cc, and then finally managing a way to buy my domain.
Thank god, .tk caused so many headaches for us, truly a cesspit of a tld. The rate of fraud and abuse on our platform was staggeringly high from it, it was close 99%.
I'd rather ICANN finally introduce .free, give a few years to alert everyone, and those developing spam filters can treat it how they want.
Earlier quoted context omitted.
Cloudflare is a US company. If they provide hosting (or reverse proxying; I don't think there's a material legal difference) services for anything illegal under US law, shouldn't it be possible to compel them to stop doing that through the legal system? And if this is about not-illegal-but-objectionable content, I'm actually glad that as an infrastructure company, they're choosing to not get into the business of cont…
> if this is about not-illegal-but-objectionable content, I'm actually glad that as an infrastructure company, they're choosing to not get into the business of content moderation. Agreed. There's one other subset you didn't mention: "Clearly illegal but not yet handled in the court of law". Cloudflare again has a pretty hardline stance that "the courts need to come to us and force us to take it down"
"Hardline"? To me it seems like quite reasonable approach as opposed to "we will just take down anything someone on Twitter didn't like".
Earlier quoted context omitted.
This seems like such a weird problem to me. If they're criminals, just send the cops? If you can't send the cops, then they aren't criminals? How do you end up in this limbo where you need critical infrastructure to play judge?
Who you going to send to an online pharmacy hosted say in Egypt?
Earlier quoted context omitted.
If you try to find evidence that Cloudflare mitigates fraud and abuse, you'll mostly find anecdotal evidence (sites that have been attacked and moved to Cloudflare, mostly) plus information and claims provided by Cloudflare, which is unverifiable. The problem is that nobody protects us, the Internet, from Cloudflare. Cloudflare will happily take money from and host (yes, host - they host, in spite of their rather stu…
What are some other viable options?
2) use literally any other registrar / DNS service / hosting platform. You then won't need to worry about whether people all over the world will be getting CAPTCHAs on ever visit because of where they live or what browser they choose to use.
Earlier quoted context omitted.
It would follow that Cloudflare is tacitly admitting they have been / are hosting a large number of domains used for fraud and abuse. That surprises me, given the time and effort they spend mitigating fraud and abuse. Anyone care to explain what I'm missing?
It seems at least plausible to me that either there would be even more fraud and abuse than there already is without the time and effort to mitigate it, or that maybe their mitigation is not as effective as they'd like. This isn't meant to contradict the other theories being posted here; I don't really have any experience specific to this area, so it's possible I'm just being naive.
As they say, extraordinary claims require extraordinary evidence…
Earlier quoted context omitted.
>kid >2017 fucking hell
I know right! I feel so young. there are people on this site that were born in the previous millennium! :O
Earlier quoted context omitted.
What are some other viable options?
1) not using DoS / DDoS protection, or using any number of hosting services that have this built in, or using a service that doesn't marginalize large parts of the world in the name of "security". DoS / DDoS attacks are not as common as Cloudflare would want you to believe. 2) use literally any other registrar / DNS service / hosting platform. You then won't need to worry about whether people all over the world will…
I know this because I manage a WordPress site fronted by a different WAF, and I can see in the logs that malicious bots are trying to pwn the site basically 24/7.
(and before you say ‘patches’ – yes, but defense in depth is a thing, and you don’t always have the luxury of vendors with good security practices.)
Earlier quoted context omitted.
Why do orgs feel the need to use these whacky TLDs I’m still of the fence with rust using .rs in important places which is fundamentally in control of the Serbian government. You’re going to have to trust the Serbian government with signing .rs DNSSSEC at minimum and I don’t.
Because all .com are already taken and available only after you pay ransom money.