Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

31–40 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#31
post #23

Yes. I find a similar pattern to Meta's scammer ads. Huge publicly traded companies benefitting from the illegal actions of their clients, turning a blind eye, or conveniently delaying their takedowns. Big companies need to absorb the liability of small companies, otherwise you get this delegated Sybil Good bank/Bad bank attack

If they accept money to display malicious ads they should be prosecuted as accessories to the crime tbh

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#32
post #21

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

> People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity.

This is a fascinating idea. Is this something anyone is working on?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#33

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

It's a protection racket born of fundamental weaknesses in the Internet's bedrock protocols.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#34
post #17

I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail, so that hacking group could exploit as many targets during that time as possible

copy.fail patches can be applied with minimum downtime, and a VM reboots in 30 seconds, tops, regardless of size. I believe all the apex servers are configured as HA to keep the load distributed, so normal users won't feel anything when copy.fail is patched. Our users didn't feel a thing when we rolled out the patches.

But the Ubuntu update servers are necessary to serve the update. Taking them down prevents the users from downloading the update. I don't know whether the update servers were affected though.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#35
post #27

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Or water companies for selling water for them. Where is the line?

If a billboard company accepted an ad that included a threat on the president’s life or recruitment info for a known terror organization, are they complicit in the crime? Water is a basic utility so I don’t think that’s a fair comparison

This is more like a firearms dealer selling a gun to someone after they put their intended usage as “robbing banks” in the ATF form

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#36
I'm not sure how correct this is but when you upgrade your tier on Cloudflare aren't the costs basically up to Cloudflare?

With the horror stories heard over the years I think a real issue is no hard pricing cap with forced shutdown.

Unless that's changed? I booted them a year ago..

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#38
post #21

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

You can’t have both ‘sockpuppet-grade anonymity’ and ‘held liable for their actions’ in the same society, whether Internet or otherwise. Both in reality and online, those that create sockpuppet corporations-slash-identities are unmasked only when their web of sockpuppetry is pierced by e.g. ‘reused a mailbox’, ‘used a neighbor’s identity’, ‘used a family member’s identity’, and so on. Until such investigations, sockpuppets get away with billions of dollars-slash-gigabits of crimes every year, and barring the ever-incompetence of most criminals, the Internet is a vast improvement over shell corporations in that regard. Still. It is technically possible to be able to ban the controlling human of an online sockpuppet without violating their anonymity, but we lack the societal infrastructure to do so — and since our own techno-utopian societies have invested no effort in doing so, it seems like the core utopian ideal could be ‘freedom from consequences’, rather than ‘freedom of anonymity’. If that’s a valid interpretation, then the core issue is not ‘preserve relative anonymity’, it is ‘preserve relative non-liability’, which may offer new avenues for much cheaper investment than pseudoanonymity would cost.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#39
post #8

Earlier quoted context omitted.

>They protect (from legal consequence or even discovery) the attackers and host them on their infrastructure so they're untouchable Victims can't file a subpoena to get account details?

I've never tried a subpoena. I've tried reporting them to ICANN for whois abuse contact violations and never received a response (after I recieved a response from cloudflare saying, "Go away, we don't care, sign up for our services and pay us to care."). Perhaps I should set up a gofundme or something for the thousands of dollars needed to get justice via subpoena. If I were hosting illegal malicious actors doing thi…

No you wouldn't. Unless you failed to comply with subpoenas/warrants/etc for it.

That assumes of course that like Cloudflare you were hosting a web page and not the actual illegal activity, and were following the laws around hosting things.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#40
Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity."

Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't.

In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap. And then if you really need them, you have every reason to start paying.

Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against. They wouldn't have a business if they made that a viable target!

But the result of these business decisions, made for their main customer acquisition flow, makes them a tempting place to host malicious content, as well as good. Black hats make a sport out of taking each other out. And so have every reason to use Cloudflare.

Still doesn't indicate a relationship between Cloudflare and the bad actors who are taking advantage of the setup.

Post reply on HN