Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

111–120 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#111

Earlier quoted context omitted.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?

No. Nobody said that.

Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#112

Earlier quoted context omitted.

> You cannot host user content without being required to police it for at a minimum things like child porn. yes, child sexual abuse material is covered by law , i.e. they already have a lawful obligation for that thus do not require a separate lawful order. the issue is around arbitrary content-policing, where the decision is made by cloudflare rather than the legal apparatus. having a website that says you do ddos f…

Yeah, there's a huge big hole you're ignoring: That 18 USC 2 and 371 apply to the CFAA, too. What are those? Accomplice liability, which has been considered to include aiding and abetting. Hosting (and protecting, by virtue of your product) computer crime organizations could quite plausibly be rolled into accomplice liability.

cloudflare has no knowledge that is linked to and they have no way of gaining that knowledge unless presented with a lawful order stating such.

if what you were saying was at all a plausible legal interpretation, it would have been brought to light over the last 16 years of lawsuits cloudflare has been involved in. or it would have been brought up by their literal room full of (actual) on-staff lawyers.

aiding and abetting requires knowledge of the crime and intent to facilitate it. cloudflare has neither.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#113

Earlier quoted context omitted.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?

[deleted]

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#114

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

This is a flawed analogy. The "keyboard manufacturer" in this scenario is the "router manufacturer" who Cloudflare buys off of, not Cloudflare.

In your scenario Cloudflare is more like a newspaper aggregator which carries all sort filth along with it's normal commentary.

If this was a normal situation one could just decide not to read some filthy newspapers, while letting those who want to read it make that decision for themselves.

But in the Cloudflare scenario all the major relevant normal newspapers decided to publish all their content through Cloudflare and if something objectionable is published along with it, instead of taking your beef to the original publisher, you have to to take it up with Cloudflare who might just forward your details to some very unsavory people without you having a chance to know beforehand.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#115

The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief. Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or p…

There's a simpler explanation: Cloudflare (generally speaking, not 100%, as in the case of The Daily Stormer[1]) does not censor presumably-legal content traveling through their systems, and do not themselves opt to be arbiter of legality.

[1]: https://blog.cloudflare.com/why-we-terminated-daily-stormer/

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#116

Completly agree, cloudflare protects scammers on a huge scale and no one cares... All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down. None of them. For a company making billions, protecting people, they should take this stuff serious.

Would you prefer a huge organization that arbitrarily censors websites without a mechanism for appeal or legal process? The current state of affairs is way better.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#117
post #116

Completly agree, cloudflare protects scammers on a huge scale and no one cares... All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down. None of them. For a company making billions, protecting people, they should take this stuff serious.

Would you prefer a huge organization that arbitrarily censors websites without a mechanism for appeal or legal process? The current state of affairs is way better.

The current state of affairs is that cloudflare is that huge organization that arbitrarily censors websites without a mechanism for appeal or legal process.

Cloudflare actively removes your ability to decide for yourself which websites and systems you want to connect to by obscuring their sources.

Without Cloudflare I could decide for myself that I want to block certain networks to connect to my networks.

Cloudflare hiding the origin of these networks along with it's size in the market make Cloudflare exactly that huge organization.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#118

With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.

Not the same case. If you get a bomb on a ups package, that's not UPS' fault. But if you tell UPS someone is using them to send bombs to people, and they don't act on it in the least and even look like they are shielding bomb senders, then it starts being their fault a little bit, doesn't it?

What if there are one or two bomb senders out of the millions of people sending normal packages, and you have hundreds of thousands of false “tips” that are actually just harassment campaigns? Do you cut off service to the victims just in case? What if you can’t tell what half of the packages even are? Mystery mechanical parts and circuits?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#119

Earlier quoted context omitted.

how does anyone not know where the line is? An example that makes it more clear: "by that logic it's my fault that i was robbed for leaving the door to my house unlocked." No, it's the robber's fault you were robbed. The robbery is the illegal part. It is not illegal to leave a door unlocked. Back to your train wreck of an example: it is not illegal to sell keyboards, and it is not illegal to provide water to people.…

Cloudflare didn't say "give us money or we'll cause you harm"... so no extortion. Cloudflare infrastructure wasn't used for the attack, so no DoS attack. They sold services to two customers, one of whom did a crime independent of cloudflare. If a robber sees Bob buy a bunch of expensive electronics at WalMart, and then buys a crowbar and robs him, is WalMart somehow responsible for the robbery?

> If a robber sees Bob buy a bunch of expensive electronics at WalMart, and then buys a crowbar and robs him, is WalMart somehow responsible for the robbery

Yes, if Walmart somehow knew robber’s intentions, but sold anyway. That is the primary question actually. Was the intent or act known or not.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#120
post #31
post #23

Yes. I find a similar pattern to Meta's scammer ads. Huge publicly traded companies benefitting from the illegal actions of their clients, turning a blind eye, or conveniently delaying their takedowns. Big companies need to absorb the liability of small companies, otherwise you get this delegated Sybil Good bank/Bad bank attack

If they accept money to display malicious ads they should be prosecuted as accessories to the crime tbh

who would be they in that case? I don't think entities can be charged criminally.

A more basic middle ground would be making the company liable for the damages (civil court not criminal).

Post reply on HN