I dislike CFs role in the modern Internet as much as the next person, but this is a bunch of speculation trying to connect dots with no basis other than that a Canonical cert renewal happened on the same day as a company transfer.
There might be somewhat of a tangential story, however, in that Njalla seems to have reorganized or changed ownership fairly recently[1], and that Njalla and immateriali.sm seem to be related entities[2]
> if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. You are ignorant of the law. You cannot host user content without being required to police it for at a minimum things like child porn. But this is also not a remotely ambiguous case. Any normal service would instantly terminate a client account if the client is blatan…
> You cannot host user content without being required to police it for at a minimum things like child porn. yes, child sexual abuse material is covered by law , i.e. they already have a lawful obligation for that thus do not require a separate lawful order. the issue is around arbitrary content-policing, where the decision is made by cloudflare rather than the legal apparatus. having a website that says you do ddos f…
cloudflare is not hosting the infrastructure doing the actual attacks. the attack is coming from residential proxy servers, not from the webpage being hosted by cloudflare, which is just a marketing page and a login portal. that clause is not really applicable. in any case, its not a question of whether cloudflare can remove a website. of course they can, for whatever reason they want. its a question of whether we wa…
Wait, the webpage hosted by cloudflare, as you say. So yes, they're not hosting the infrastructure doing the actual attacks, they're "just" hosting the infrastructure for the site advertising the attacks. "You may not use the services to attack our infrastructure. You may use the services to advertise and charge for attacking our infrastructure".
correct, you should be able to host any lawful website you want.
if a police investigation turns up that X DDoS is linked to Y advertising site, the police should then submit a lawful takedown request, which cloudflare will oblige.
people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…
>if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever They already pick and choose. They have not decided to sit outside of it. Any claim about them not getting involved should be read as tacit approval. Because we know they will drop users they sufficiently disapprove of.
They have done this one time and the CEO said he regretted it.
"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
I have no insight into this particular case/incident, but I do have to deal with a lot of http traffic management, and I've lately been seeing Cloudflare IPs show up a lot more often in my logs for probes and nuisances, and not because the traffic is being proxied (or at least, it doesn't have the CF-Connecting-Ip header). Used for these attacks, dunno, used for some attacks, yes. (But CF still remains a much less fr…
One of types of services Cloudflare provides goes by the name "Warp". Calling it a VPN is only wrong in ways that don't really matter — it has the effect of causing client traffic to appear to originate from a different IP address to the one they're notionally connected to the Internet via.
> if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. You are ignorant of the law. You cannot host user content without being required to police it for at a minimum things like child porn. But this is also not a remotely ambiguous case. Any normal service would instantly terminate a client account if the client is blatan…
> You cannot host user content without being required to police it for at a minimum things like child porn. yes, child sexual abuse material is covered by law , i.e. they already have a lawful obligation for that thus do not require a separate lawful order. the issue is around arbitrary content-policing, where the decision is made by cloudflare rather than the legal apparatus. having a website that says you do ddos f…
Yeah, there's a huge big hole you're ignoring:
That 18 USC 2 and 371 apply to the CFAA, too. What are those? Accomplice liability, which has been considered to include aiding and abetting. Hosting (and protecting, by virtue of your product) computer crime organizations could quite plausibly be rolled into accomplice liability.
Seems petty clear the intent of the post you are replying to isn't to hold random parents accountable for thousands and instead to hold app developers (add maybe too open app marketplaces) accountable for malicious app behavior
This road seems to lead to the exclusion of third party app stores and/or the ability to load apps that aren't signed by Google/Apple.
That’s what they want, it’s why you often see people popping up in discussions on HN supporting licensing for software developers.
Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…
The internet worked for so long because people responsible for each little island did what was for the most part in the best interests of the rest of the islands. If you didn't, other islands would shut off their links to you. Law enforcement was a last resort because 1. the courts don't move at the speed of the internet and 2. nobody wanted the internet getting top down governmental regulation because it was trans-n…
Yes, Cloudflare has always been really shitty and automated at responding to abuse reports, and because they are the front-end connection, it is impossible to pursue the report against the 'real' host unless Cloudflare is willing to provide you with information about where that host is: which they won't typically do, even if you are a fellow infrastructure provider. It's been several years, so maybe they have gotten better, but I would be surprised.
"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…
Seems like they could use Tor onion sites just as easily tbh.
I don’t think it should be a requirement to talk to cloudflare at all to host content on the internet. I certainly don’t.
How did you get that from the comment? It’s the other way around - if you report criminal or illegal sites hosted by cloudflare they will take it down. I’ve hosted content online for decades and never once talked to cloudflare.
Will they? Have you gone through that process with them? In my experience (admittedly somewhat stale) it was fairly hard to get through to them, much less to get the information required to actually report bad actors to their real hosting provider that Cloudflare is fronting.