Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

81–90 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#81

Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…

I don’t think it should be a requirement to talk to cloudflare at all to host content on the internet. I certainly don’t.

How did you get that from the comment? It’s the other way around - if you report criminal or illegal sites hosted by cloudflare they will take it down.

I’ve hosted content online for decades and never once talked to cloudflare.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#82
post #60

Earlier quoted context omitted.

[flagged]

No. You want it because you are shortsighted. Others don't want that. If it is illegal, go and sue.

They have been suing and winning. Yet Cloudflare continues. I'm not a fan of overzealous companies, like La Liga, cutting out massive portions of the internet in Spain during football matches, but Cloudflare isn't the good guy here either.

La Liga sued Cloudflare in Spanish court and won. Cloudflare now starts taking down content that directly violates La Ligas copyright, but mainly only in Spain. It looks like Cloudflare will happily still serve the exact same content outside of Spain.

In response to these court rulings, the got the US government involved and now there is talk of this being a digital trade barrier.

https://www.courthousenews.com/spanish-soccer-league-battles...

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#83

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

I have no insight into this particular case/incident, but I do have to deal with a lot of http traffic management, and I've lately been seeing Cloudflare IPs show up a lot more often in my logs for probes and nuisances, and not because the traffic is being proxied (or at least, it doesn't have the CF-Connecting-Ip header).

Used for these attacks, dunno, used for some attacks, yes. (But CF still remains a much less frequent nuisance than pretty much any other infrastructure provider.)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#84
post #76

Earlier quoted context omitted.

> We already live a world where your service is terminated for illegal activity. Of course we want it, how is this even a question? you are misunderstanding me, but im not sure if you are doing it on purpose. if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. > The mental loops people in these comments are using to supp…

> if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. You are ignorant of the law. You cannot host user content without being required to police it for at a minimum things like child porn. But this is also not a remotely ambiguous case. Any normal service would instantly terminate a client account if the client is blatan…

>You cannot host user content without being required to police it for at a minimum things like child porn.

yes, child sexual abuse material is covered by law, i.e. they already have a lawful obligation for that thus do not require a separate lawful order.

the issue is around arbitrary content-policing, where the decision is made by cloudflare rather than the legal apparatus.

having a website that says you do ddos for hire is not illegal. (doing the ddos is the illegal part. but that was not done with cloudflare infrastructure = cloudflare should not be involved unless they receive a lawful order).

i am going to choose to ignore your additional mischaracterizations and insults. it would super cool of you to stop calling me ignorant, an astroturfer for ddos, etc. over a simple disagreement.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#85

Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…

I don’t think it should be a requirement to talk to cloudflare at all to host content on the internet. I certainly don’t.

Oh absolutely agreed. Cloudflare becoming a giant internet chokepoint is certainly a real problem. It would be a much better world where ddos protection would not be a needed service or where we it was provided as a public service, rather than by private companies. However, that's not the world we live in.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#86

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Not the same case. If you get a bomb on a ups package, that's not UPS' fault. But if you tell UPS someone is using them to send bombs to people, and they don't act on it in the least and even look like they are shielding bomb senders, then it starts being their fault a little bit, doesn't it?

How are they “shielding bomb senders” though? Because their marketing static page was hosted through cloudflare? Taking that down wouldn’t have changed anything here either.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#87

Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…

The internet worked for so long because people responsible for each little island did what was for the most part in the best interests of the rest of the islands. If you didn't, other islands would shut off their links to you. Law enforcement was a last resort because 1. the courts don't move at the speed of the internet and 2. nobody wanted the internet getting top down governmental regulation because it was trans-national.

Cloudflare spent a bunch of venture capital to give away expensive things for free and buy market share. If you convince all the grocery stores to move to your island, you can operate a den of criminal activity with no fear of everyone else shunning you.

Talk to anyone who fights botnets, malware, or online scams. Once you hit the Cloudflare dead end you just have to give up. Law enforcement isn't going to take up a case where only 7,000 peoples computers are infected, and Cloudflare isn't going to investigate and take action themselves.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#88
post #35
post #27

Earlier quoted context omitted.

Or water companies for selling water for them. Where is the line?

If a billboard company accepted an ad that included a threat on the president’s life or recruitment info for a known terror organization, are they complicit in the crime? Water is a basic utility so I don’t think that’s a fair comparison This is more like a firearms dealer selling a gun to someone after they put their intended usage as “robbing banks” in the ATF form

Nah this is more like a billboard service “selling” a billboard to someone (for free) and the billboard reads something like “wanna have a bank robbed for you? call me” — tbh not sure if that is illegal (probably depends on jurisdiction?)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#89

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

[deleted]

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#90
post #27

Earlier quoted context omitted.

Or water companies for selling water for them. Where is the line?

how does anyone not know where the line is? An example that makes it more clear: "by that logic it's my fault that i was robbed for leaving the door to my house unlocked." No, it's the robber's fault you were robbed. The robbery is the illegal part. It is not illegal to leave a door unlocked. Back to your train wreck of an example: it is not illegal to sell keyboards, and it is not illegal to provide water to people.…

Cloudflare didn't say "give us money or we'll cause you harm"... so no extortion. Cloudflare infrastructure wasn't used for the attack, so no DoS attack.

They sold services to two customers, one of whom did a crime independent of cloudflare.

If a robber sees Bob buy a bunch of expensive electronics at WalMart, and then buys a crowbar and robs him, is WalMart somehow responsible for the robbery?

Post reply on HN