Live data from Hacker News

Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

infosec.exchange

21–30 of 46 posts

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#21
How do they know that behind the scenes Cloudflare has not handed over whatever IP and financial information they have on the attackers to the feds? AFAIK such things would not be disclosed until the attackers are locked up and the case is closed assuming such details are ever disclosed at all.

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#23
post #21

How do they know that behind the scenes Cloudflare has not handed over whatever IP and financial information they have on the attackers to the feds? AFAIK such things would not be disclosed until the attackers are locked up and the case is closed assuming such details are ever disclosed at all.

because unless they are remarkably stupid they didn't pay with their own credit card. That doesn't mean that the information is necessarily useless but I'd not expect them to kick a door down any time soon.

(Moreover since cloudflare has a free tier you could use their service while handing over only a single email)

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#24

This is the dumbest post I’ve read. The attackers have a site seemingly hosted by/orange clouded by Cloudflare. They aren’t providing botnet or DDOS capabilities. Cloudflare tries to act as a third party that follows the law when the law gets involved. They don’t want to actively police the internet in the same way they don’t actively abolish piracy (see Anna’s Archive). There are exceptions to this of course, but on…

> They don’t want to actively police the internet

They do and they've done so in the past. They are just more okay with some illegal stuff than others.

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#25
post #21

How do they know that behind the scenes Cloudflare has not handed over whatever IP and financial information they have on the attackers to the feds? AFAIK such things would not be disclosed until the attackers are locked up and the case is closed assuming such details are ever disclosed at all.

because unless they are remarkably stupid they didn't pay with their own credit card. That doesn't mean that the information is necessarily useless but I'd not expect them to kick a door down any time soon. (Moreover since cloudflare has a free tier you could use their service while handing over only a single email)

All true points though I have met some incredibly dumb, brazen and cavalier criminals. We will not know until the dust settles.

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#26
I recall this post[0] from cloudflare's CEO about when they terminated daily stormer back in 2017, and particularly this quote:

> Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network.

This is overall a very reasonable take and one I support from a player the size of Cloudflare: They should aim to remain as neutral as possible instead of enforcing arbitrary blocks on sites they disagree with.

Now, this post is from nearly 10 years go and I'm sure there have been many more cases that happened since then, their methodology likely did evolve, but I don't mind them protecting any site, regardless of their opinion towards its content.

[0] https://blog.cloudflare.com/why-we-terminated-daily-stormer/

[1] https://news.ycombinator.com/item?id=15031922

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#27

I recall this post[0] from cloudflare's CEO about when they terminated daily stormer back in 2017, and particularly this quote: > Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network. This is overall a very reasonable take and one I support from a player the size of Cloudflare: They should aim to remain as neutral as poss…

Kiwifarms back in 2022: https://news.ycombinator.com/item?id=32706673

"Our decision today was that the risk created by the content could not be dealt with in a timely enough matter by the traditional rule of law systems."

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#28

I recall this post[0] from cloudflare's CEO about when they terminated daily stormer back in 2017, and particularly this quote: > Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network. This is overall a very reasonable take and one I support from a player the size of Cloudflare: They should aim to remain as neutral as poss…

Kiwifarms back in 2022: https://news.ycombinator.com/item?id=32706673 "Our decision today was that the risk created by the content could not be dealt with in a timely enough matter by the traditional rule of law systems."

Bad example, that was clearly them yielding to a lynch mob in the performance of its duties, as the saying goes. They clearly would've been content neutral in that case too, if the mob hadn't turned against them too.

Re: Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

#30
> A part of the internet considered "Critical infrastructure" is being attacked with impunity, and those who could stop it are doing nothing.

i don't understand how ceasing to proxy their storefront would stop a ddos attack? it's not like CF infrastructure is being used for the DDOS, or is that actually the claim made?

i can get saying something like "they shouldn't be providing this service to them" but this isn't a critical service to their operation?

Post reply on HN