Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…
The internet worked for so long because people responsible for each little island did what was for the most part in the best interests of the rest of the islands. If you didn't, other islands would shut off their links to you. Law enforcement was a last resort because 1. the courts don't move at the speed of the internet and 2. nobody wanted the internet getting top down governmental regulation because it was trans-n…
Can someone please explain whether Cloudflare blackmailed Canonical?
91–100 of 182 posts
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#92Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…
In a normal scenario, if you want to protect your systems from other "bad" systems on the internet, you can block them on the IP layer.
But Cloudflare operates at the IP layer proxying data between you and good and bad (and everything in between) systems.
In a normal situation you could block and report a site that is run by the the mob, by either blocking them at the IP level or by contacting the abuse@ of the organization that is hosting the content.
Cloudflare is making it so that you can't do either. And if you send an abuse report to Cloudflare, you cannot be sure that they will not just forward your contact information directly to the entity that you are complaining about. They have changed their stance over the years to appear more responsible, but the fact remains:
If I want to send an abuse@ report to a system that is hidden behind Cloudflare I can not be sure that they won't just forward it without me knowing who they are forwarding it to.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#93Earlier quoted context omitted.
copy.fail patches can be applied with minimum downtime, and a VM reboots in 30 seconds, tops, regardless of size. I believe all the apex servers are configured as HA to keep the load distributed, so normal users won't feel anything when copy.fail is patched. Our users didn't feel a thing when we rolled out the patches.
But the Ubuntu update servers are necessary to serve the update. Taking them down prevents the users from downloading the update. I don't know whether the update servers were affected though.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#94The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…
I do agree with your comment. But obviously Cloudflare didn't invent DDoS. If Cloudflare just magically disappears tomorrow, the AI crawlers won't stop. So what's the alternative? It's not a world you need to upload a government-issued ID to browse the internet, right? ...right?
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#95With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.
Not the same case. If you get a bomb on a ups package, that's not UPS' fault. But if you tell UPS someone is using them to send bombs to people, and they don't act on it in the least and even look like they are shielding bomb senders, then it starts being their fault a little bit, doesn't it?
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#96"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#97The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…
Ok, so what's the solution? I do agree with your comment. But obviously Cloudflare didn't invent DDoS. If Cloudflare just magically disappears tomorrow, the AI crawlers won't stop. So what's the alternative? It's not a world you need to upload a government-issued ID to browse the internet, right? ...right?
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#98Earlier quoted context omitted.
[flagged]
I think you may have missed the forest for the trees; the concern is about the slippery slope that may lead to a for-profit company (also the risk in case it's non-profit; see OpenAI shenanigans) controlling what content you can read, what operating systems you can download, etc... and the fear is about protection rackets leading us to being stuck with a monopoly or an oligopoly at best that enforce that censorship.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#99people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…
One of the few reasonable comments on this thread. I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters. Zero evidence that cloudflare actually enabled the attack itself from what I can tell.
Cloudflare's core thing OTOH is to hide who I could be sending an abuse report to,
Possibly they will forward it ( more likely not) , but they will include my personal information in a report to an entity that is unknown to me, who are likely criminals, exposing me to danger.
Re: Can someone please explain whether Cloudflare blackmailed Canonical?
#100Earlier quoted context omitted.
Most companies have TOS that include not damaging or attacking the company itself. The advertised service attacks Cloudflare explicitly. It seems very straightforward that this would violate any reasonable TOS. edit: and here it is straight from their TOS https://www.cloudflare.com/en-ca/website-terms/ "7. PROHIBITED USES As a condition of your use of the Websites and Online Services, you will not use the Websites or…
cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…
"You may not use the services to attack our infrastructure. You may use the services to advertise and charge for attacking our infrastructure".