Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

41–50 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#42
post #27

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Or water companies for selling water for them. Where is the line?

how does anyone not know where the line is?

An example that makes it more clear: "by that logic it's my fault that i was robbed for leaving the door to my house unlocked."

No, it's the robber's fault you were robbed. The robbery is the illegal part. It is not illegal to leave a door unlocked. Back to your train wreck of an example: it is not illegal to sell keyboards, and it is not illegal to provide water to people. Extortion is illegal. Denial of Service attacks are illegal.

That's where the line is. It is the border between legal and illegal.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#43
post #20
post #14

Earlier quoted context omitted.

>I've tried reporting them to ICANN and never received a response. So ICANN is complicit too? After all, if we adopt your interpretation, in some way ICANN is also turning an blind eye, both to what cloudflare is supposedly doing and also to what the domain registrars are doing.

ICANN doesn't get any kickbacks from Canonical needing to protect itself as far as I can tell. Cloudflare literally sells the protection.

So ICANN is alright because they're protecting them for free, but Cloudflare is bad because they're protecting them for money?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#44
post #27

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Or water companies for selling water for them. Where is the line?

Obviously we need to go after supermarkets and corner stores since criminals eat, so somewhere past that.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#45
post #40

Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity." Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't. In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap.…

> Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against.

I don't think that argument holds water. There's a world of difference between knocking a site offline with a DDoS and making a legal request which results in a hosting provider shutting it down.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#46
post #32
post #21

Earlier quoted context omitted.

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

> People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. This is a fascinating idea. Is this something anyone is working on?

In a sense, one can argue IPFS can do it, provided the content is syndicated widely enough. It is not, though.

Similarly, BitTorrent does roughly the same once the peer relationships are established.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#47
post #40

Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity." Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't. In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap.…

What you are saying is that Canonical should have first updated the DNS to point at the attacker's web site IP (hosted by Cloudflare) for a few hours to let Cloudflare eat 3.5Tbps for a bit? :)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#48
post #17

I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail, so that hacking group could exploit as many targets during that time as possible

> I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail

On Ubuntu copy.fail could be mitigated against with some modprobe(8) config tweaks:

    # echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
    # rmmod algif_aead
There may be some processes that use this functionality ("lsof | grep AF_ALG"), but it is not that widespread AIUI, and so disabling it should not be an issue for the vast majority of systems.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#49
post #43
post #20

Earlier quoted context omitted.

ICANN doesn't get any kickbacks from Canonical needing to protect itself as far as I can tell. Cloudflare literally sells the protection.

So ICANN is alright because they're protecting them for free, but Cloudflare is bad because they're protecting them for money?

In a way, yes, that makes it more okay. You can't have a conflict of interest if you have no interest. Cloudflare has clear interest in hosting the malicious actors and it's in clear conflict with providing services to their other users.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#50
post #35
post #27

Earlier quoted context omitted.

Or water companies for selling water for them. Where is the line?

If a billboard company accepted an ad that included a threat on the president’s life or recruitment info for a known terror organization, are they complicit in the crime? Water is a basic utility so I don’t think that’s a fair comparison This is more like a firearms dealer selling a gun to someone after they put their intended usage as “robbing banks” in the ATF form

> If a billboard company accepted an ad that included a threat on the president’s life or recruitment info for a known terror organization, are they complicit in the crime? Water is a basic utility so I don’t think that’s a fair comparison

Yet Meta and Twitter are doing fine, while this has happened.

Water was kinda intentional extreme end. Is there a line? Where is the line? Giving food for someone before they make a murder can give you much bigger jailtime than not giving it, and then just ignoring the knowledge that they are going to make a murder. It is not what you do but the act itself.

Post reply on HN