Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

51–60 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#51
people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received.

if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some sort of nebulous set of criteria, people will get (justifiably) big mad about it, guaranteed.

the "renting attack capacity [from cloudflare]" should have some evidence behind it, because as far as i am aware, the attackers are not using cloudflare infrastructure for the actual attack.

(its really jarring to see the general sentiment on this submission vs. the general sentiment on google submissions)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#52

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything.

DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups.

Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services. Preventing them from DDOSing one another offline really let the DDOS industry take flight.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#53
post #21

Earlier quoted context omitted.

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expe…

Same with ISPs.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#54
post #40

Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity." Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't. In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap.…

> Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against. I don't think that argument holds water. There's a world of difference between knocking a site offline with a DDoS and making a legal request which results in a hosting provider shutting it down.

Sure. Any evidence such a legal request has been made in this case? If not, why the whining?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#55

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS.

edit: and here it is straight from their TOS

https://www.cloudflare.com/en-ca/website-terms/

"7. PROHIBITED USES

As a condition of your use of the Websites and Online Services, you will not use the Websites or Online Services for any purpose that is unlawful or prohibited by these Terms. You may not use the Websites or Online Services in any manner that could damage, disable, overburden, disrupt or impair any Cloudflare servers or APIs, or any networks connected to any Cloudflare server or APIs, or that could interfere with any other party's use and enjoyment of any Websites or Online Services. You may not transmit any viruses, worms, defects, Trojan horses, or any items of a destructive nature through your use of Websites or Online Services. You may not exceed or circumvent, or try to exceed or circumvent, limitations on the Websites or Online Services, including on any API calls, or otherwise use the Websites or Online Services in a manner that violates any Cloudflare documentation or user manuals. You may not attempt to gain unauthorized access to any Websites or Online Services, other accounts, computer systems, or networks connected to any Cloudflare server or to any of the Websites or Online Services through hacking, password mining, or any other means. You may not obtain or attempt to obtain any materials or information through any means not intentionally made available through the Websites or Online Services. You may not to use the Websites or Online Services in any way that violates any applicable federal, state, local, or international law or regulation (including, without limitation, any laws regarding the export of data or software to and from the US or other countries).

Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful, or in violation of these Terms. For these purposes, illegal or harmful content includes but is not limited to: (a) content containing, promoting, or facilitating child sexual exploitation and abuse or human trafficking; (b) content that infringes on another person’s intellectual property rights or is otherwise unlawful; (c) content that discloses sensitive personal information, incites or exploits violence, or is intended to defraud the public; and (d) content that seeks to distribute malware, facilitate phishing, or otherwise constitutes technical abuse."

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#56
post #21

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

Then there is going to have to be geographic separation. Someone completely out of your jurisdiction or control can bring essential services down, leadership only has one option, to put up a Great Firewall. Or the wider public internet will be abandoned naturally as AI slop infests it.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#57
post #55

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS. edit: and here it is straight from their TOS https://www.cloudflare.com/en-ca/website-terms/ "7. PROHIBITED USES As a condition of your use of the Websites and Online Services, you will not use the Websites or…

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable.

in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want.

its a question of whether we want to be in a world where cloudflare starts making content-based decisions on website hosting. most people probably dont want that.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#58
post #21

Earlier quoted context omitted.

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expe…

So if your kid downloaded a shady app, and it turned out that app had some residential VPN SDK, are you on the hook too? Does it stop at DDoS attacks? If it turned out they were scraping linkedin, can they sue you for a thousands of dollars of "harm" that you enabled?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#59

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Not the same case. If you get a bomb on a ups package, that's not UPS' fault.

But if you tell UPS someone is using them to send bombs to people, and they don't act on it in the least and even look like they are shielding bomb senders, then it starts being their fault a little bit, doesn't it?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#60
post #55

Earlier quoted context omitted.

Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS. edit: and here it is straight from their TOS https://www.cloudflare.com/en-ca/website-terms/ "7. PROHIBITED USES As a condition of your use of the Websites and Online Services, you will not use the Websites or…

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

[flagged]
Post reply on HN