Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

21–30 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#21

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence.

How can we do that, if we would like to preserve relative anonymity and global nature of the internet?

People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it. The required investment is rather high.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#22
post #11
post #6

This is insanely dumb. Cloudflare is providing free hosting services, not materially supporting the attacker. You can argue that cloudflare needs to be better, or adopt different values towards, taking down sites they host, but this organization could absolutely just serve elsewhere (or just advertise their services over telegram or the like). Maybe there is a point to be made about monopoly power in hosting and ddos…

It's not dumb. There's a conflict of interest.

Yeah, I demand all my hosting providers be 100% vulnerable to DDoS for this reason.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#23
Yes.

I find a similar pattern to Meta's scammer ads.

Huge publicly traded companies benefitting from the illegal actions of their clients, turning a blind eye, or conveniently delaying their takedowns.

Big companies need to absorb the liability of small companies, otherwise you get this delegated Sybil Good bank/Bad bank attack

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#24
post #17

I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail, so that hacking group could exploit as many targets during that time as possible

copy.fail patches can be applied with minimum downtime, and a VM reboots in 30 seconds, tops, regardless of size. I believe all the apex servers are configured as HA to keep the load distributed, so normal users won't feel anything when copy.fail is patched.

Our users didn't feel a thing when we rolled out the patches.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#26

Completly agree, cloudflare protects scammers on a huge scale and no one cares... All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down. None of them. For a company making billions, protecting people, they should take this stuff serious.

If you’re not using the legal system to seek action from Cloudflare, you’re unlikely to be heard by them. “I was injured for $20 and I seek as redress the customer payment details (issuing bank, account number) provided to Cloudflare so that I can identify and file a claim for financial redress against them” would be a lovely small claims lawsuit, for example. I haven’t heard of anyone trying that yet but I’d love to admire the results if someone does!

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#28
post #21

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expensive then so be it; that's the result of pricing in the externalities.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#30
post #8

Earlier quoted context omitted.

>They protect (from legal consequence or even discovery) the attackers and host them on their infrastructure so they're untouchable Victims can't file a subpoena to get account details?

I've never tried a subpoena. I've tried reporting them to ICANN for whois abuse contact violations and never received a response (after I recieved a response from cloudflare saying, "Go away, we don't care, sign up for our services and pay us to care."). Perhaps I should set up a gofundme or something for the thousands of dollars needed to get justice via subpoena. If I were hosting illegal malicious actors doing thi…

> If I were hosting illegal malicious actors doing this stuff on my home servers and refused to even say who was doing it I would 100% get my door kicked down by the FBI. But some persons, corporate persons, are more equal than others.

If you refused to tell some random person who asked? No, you wouldn’t. If you refused to respond to a legal authority—a court-issued subpoena, for example—then there would be consequences.

As far as cloudflare is concerned you’re just a random person asking. They have no legal obligation to provide you with information.

Post reply on HN