Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

11–20 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#11
post #6

This is insanely dumb. Cloudflare is providing free hosting services, not materially supporting the attacker. You can argue that cloudflare needs to be better, or adopt different values towards, taking down sites they host, but this organization could absolutely just serve elsewhere (or just advertise their services over telegram or the like). Maybe there is a point to be made about monopoly power in hosting and ddos…

It's not dumb. There's a conflict of interest.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#13
It seems disingenuous to assume that CF offering some (unknown) amount of service to a malicious actor amounts to "blackmailing" someone that actor is attacking. CF could, and probably should, be better about not offering services to criminals but making a leap of logic certainly doesn't help anything.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#14
post #8

Earlier quoted context omitted.

>They protect (from legal consequence or even discovery) the attackers and host them on their infrastructure so they're untouchable Victims can't file a subpoena to get account details?

I've never tried a subpoena. I've tried reporting them to ICANN for whois abuse contact violations and never received a response (after I recieved a response from cloudflare saying, "Go away, we don't care, sign up for our services and pay us to care."). Perhaps I should set up a gofundme or something for the thousands of dollars needed to get justice via subpoena. If I were hosting illegal malicious actors doing thi…

>I've tried reporting them to ICANN and never received a response.

So ICANN is complicit too? After all, if we adopt your interpretation, in some way ICANN is also turning an blind eye, both to what cloudflare is supposedly doing and also to what the domain registrars are doing.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#15
"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks.

This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#16
The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief.

Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or profit sharing or anything like that, there is not a clear side that the DDos protector service is on?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#18
Completly agree, cloudflare protects scammers on a huge scale and no one cares...

All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down.

None of them.

For a company making billions, protecting people, they should take this stuff serious.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#20
post #14

Earlier quoted context omitted.

I've never tried a subpoena. I've tried reporting them to ICANN for whois abuse contact violations and never received a response (after I recieved a response from cloudflare saying, "Go away, we don't care, sign up for our services and pay us to care."). Perhaps I should set up a gofundme or something for the thousands of dollars needed to get justice via subpoena. If I were hosting illegal malicious actors doing thi…

>I've tried reporting them to ICANN and never received a response. So ICANN is complicit too? After all, if we adopt your interpretation, in some way ICANN is also turning an blind eye, both to what cloudflare is supposedly doing and also to what the domain registrars are doing.

ICANN doesn't get any kickbacks from Canonical needing to protect itself as far as I can tell. Cloudflare literally sells the protection.
Post reply on HN