Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

61–70 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#61

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

This is a service, not a device sale. Continuing to provide a service to an organization that is using it to support criminal activity is very different and terminating clients for illegal activity is not controversial.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#62
Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry.

Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me.

I don't think it should be a requirement to provide your credit card, phone number and a copy of your ID in order to host content on the internet...

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#63
post #60

Earlier quoted context omitted.

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

[flagged]

>We already live a world where your service is terminated for illegal activity. Of course we want it, how is this even a question?

you are misunderstanding me, but im not sure if you are doing it on purpose.

if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host.

>The mental loops people in these comments are using to support criminals is truly mind blowing.

this is a complete mischaracterization of what i am saying. and implying that i am... astroturfing for ddos? plain offensive.

i just dont want cloudflare ai-scanning my blog, seeing the word "DDoS" because i am in networking, and proactively removing my site from the internet.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#64

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#65
post #58

Earlier quoted context omitted.

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expe…

So if your kid downloaded a shady app, and it turned out that app had some residential VPN SDK, are you on the hook too? Does it stop at DDoS attacks? If it turned out they were scraping linkedin, can they sue you for a thousands of dollars of "harm" that you enabled?

[deleted]

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#66
post #60

Earlier quoted context omitted.

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

[flagged]

The split is on who decides when the account should be terminated as criminal for legal reasons, not whether we should support criminals regardless.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#67
post #27

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Or water companies for selling water for them. Where is the line?

Firearms companies for wrongful death, keyboards for hacking, 3d printers for suicide drones. Shovels for holes.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#68
post #60

Earlier quoted context omitted.

cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…

[flagged]

No. You want it because you are shortsighted. Others don't want that. If it is illegal, go and sue.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#69
post #40

Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity." Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't. In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap.…

> Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against. I don't think that argument holds water. There's a world of difference between knocking a site offline with a DDoS and making a legal request which results in a hosting provider shutting it down.

They are both denial of services. While there indeed differences between them, they don't seem relevant here.

If a third party takedown system is poorly implemented (and it's pretty hard to create a balanced takedown system at scale), it may become more effective to abuse it instead of using DDoS.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#70
post #58

Earlier quoted context omitted.

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expe…

So if your kid downloaded a shady app, and it turned out that app had some residential VPN SDK, are you on the hook too? Does it stop at DDoS attacks? If it turned out they were scraping linkedin, can they sue you for a thousands of dollars of "harm" that you enabled?

Seems petty clear the intent of the post you are replying to isn't to hold random parents accountable for thousands and instead to hold app developers (add maybe too open app marketplaces) accountable for malicious app behavior
Post reply on HN