Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

121–130 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#121

Earlier quoted context omitted.

>if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever They already pick and choose. They have not decided to sit outside of it. Any claim about them not getting involved should be read as tacit approval. Because we know they will drop users they sufficiently disapprove of.

They have done this one time and the CEO said he regretted it.

For reference on that: https://www.propublica.org/article/how-cloudflare-helps-serv...

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#122
post #97

Earlier quoted context omitted.

Ok, so what's the solution? I do agree with your comment. But obviously Cloudflare didn't invent DDoS. If Cloudflare just magically disappears tomorrow, the AI crawlers won't stop. So what's the alternative? It's not a world you need to upload a government-issued ID to browse the internet, right? ...right?

Don’t offer service to DDoS rings?

That doesn't get rid of the important perverse incentives. They still "want" DDoS all over from a monetary perspective. Kicking off the web page of the attackers will have a slight impact but not a whole lot.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#123
post #111

Earlier quoted context omitted.

So "big companies only, absolutely no anonymous sign-ups" should be the only ones able to put stuff on the internet without fearing that a random teenager can take your site offline for days just because they're bored?

No. Nobody said that. Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.

How? Their sign-up flow would have to change dramatically. It might even become a process that is internally "expensive". There is likely one or more managers in charge of this decision and they don't want it. Additionally the current universe rewards the current situation (for them)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#124
post #116

Earlier quoted context omitted.

Would you prefer a huge organization that arbitrarily censors websites without a mechanism for appeal or legal process? The current state of affairs is way better.

The current state of affairs is that cloudflare is that huge organization that arbitrarily censors websites without a mechanism for appeal or legal process. Cloudflare actively removes your ability to decide for yourself which websites and systems you want to connect to by obscuring their sources. Without Cloudflare I could decide for myself that I want to block certain networks to connect to my networks. Cloudflare…

> The current state of affairs is that cloudflare is that huge organization that arbitrarily censors websites without a mechanism for appeal or legal process.

Where are they censoring? You're talking about more than a single digit number of sites ever, right?

> Cloudflare actively removes your ability to decide for yourself which websites and systems you want to connect to by obscuring their sources.

What, you look up the ASN of sites before you decide if you want to connect to them? That ability is very unimportant at best. And any CDN or cloud host does the same kind of source-obscuring for servers.

> Without Cloudflare I could decide for myself that I want to block certain networks to connect to my networks.

How are they stopping you from filtering incoming connections? By running a VPN? I'm pro-VPN.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#125
post #21

Earlier quoted context omitted.

The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence. How can we do that, if we would like to preserve relative anonymity and global nature of the internet? People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it.…

This seems like one of those cases where you need to assign responsibilities and obligations to those enabling the damage, even if their offerings also enable a lot of good. If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables. You don't get to offload that burden on to the victims. If that makes your VPS offerings more expe…

> If you have the capacity to offer cheap/free VPS, then you also need to cover the cost of protecting against the DDoS attacks that service enables.

Which would drive the cost back up. What you are saying is that it should be impossible to run cheap services, and therefore hobbyists and shoestring startups are not allowed anymore.

And as the sibling comment points out, where does this stop? Should ISPs be liable? DNS providers? Banks (already becoming an issue btw)? Why not just cut off anyone who looks suspicious from society, just in case?

We have a legal system for a reason. It may be slow and imperfect, but it’s better than the alternative. Rule by law beats rule by man any day of the week.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#126

Earlier quoted context omitted.

How did you get that from the comment? It’s the other way around - if you report criminal or illegal sites hosted by cloudflare they will take it down. I’ve hosted content online for decades and never once talked to cloudflare.

Will they? Have you gone through that process with them? In my experience (admittedly somewhat stale) it was fairly hard to get through to them, much less to get the information required to actually report bad actors to their real hosting provider that Cloudflare is fronting.

I haven’t but it seems you have gone through it successfully with some friction (which is probably good?)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#127
post #119

Earlier quoted context omitted.

Cloudflare didn't say "give us money or we'll cause you harm"... so no extortion. Cloudflare infrastructure wasn't used for the attack, so no DoS attack. They sold services to two customers, one of whom did a crime independent of cloudflare. If a robber sees Bob buy a bunch of expensive electronics at WalMart, and then buys a crowbar and robs him, is WalMart somehow responsible for the robbery?

> If a robber sees Bob buy a bunch of expensive electronics at WalMart, and then buys a crowbar and robs him, is WalMart somehow responsible for the robbery Yes, if Walmart somehow knew robber’s intentions, but sold anyway. That is the primary question actually. Was the intent or act known or not.

Should Walmart be responsible for performing background checks on people buying crowbars to ensure they don’t intend to do harm? What about lighter fluid? Rat poison? Baseball bats?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#128

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

It's been a well known story around Cloudflare from the beginning that they protect booters and other cybercrime actors just like any other (paying or non-paying) customer.

If you report the DDoS-for-hire actors that offer their services on forums where such things are offered openly, they reply with a template that freely interpreted say something along the lines that they can do nothing and who is a crimininal is .. like, just your opinion, man (checks notes) they say here they are a legit load tester operation, so nothing really we can do.

You can say they entered the scene because DDoS exploded in popularity, but you could just as easily make the argument it was the other way around. Make of that what you will but they sure made a lot of money from the same booters they protect their customers from.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#129

Earlier quoted context omitted.

One of the few reasonable comments on this thread. I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters. Zero evidence that cloudflare actually enabled the attack itself from what I can tell.

Cloudflare enables this because their stance is that they are a neutral carrier who is not responsible for the data they carry. If I send an abuse report to github for content on their system, there is a chance that I will be annoyed by how they handle it. Cloudflare's core thing OTOH is to hide who I could be sending an abuse report to, Possibly they will forward it ( more likely not) , but they will include my pers…

You can report abuse here anonymously - what am I missing? https://www.cloudflare.com/en-gb/trust-hub/reporting-abuse/

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#130

Earlier quoted context omitted.

Wait, the webpage hosted by cloudflare, as you say. So yes, they're not hosting the infrastructure doing the actual attacks, they're "just" hosting the infrastructure for the site advertising the attacks. "You may not use the services to attack our infrastructure. You may use the services to advertise and charge for attacking our infrastructure".

correct, you should be able to host any lawful website you want. if a police investigation turns up that X DDoS is linked to Y advertising site, the police should then submit a lawful takedown request, which cloudflare will oblige.

[deleted]
Post reply on HN