Live data from Hacker News

I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

rasbora.dev

131–140 of 244 posts

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#131

Everyone wants to bully and pick on Cloudflare now because it’s the cool thing to do I guess. The issue is not Cloudflare — it’s just the sad reality of the Internet in 2022. Imagine a criminal pumps a full tank of gas into his vehicle and then uses that vehicle to commit crimes. Nobody goes out and blames the gas station or holds them accountable. The owner of the vehicle should and would be held accountable in real…

> Nobody goes out and blames the gas station or holds them accountable.

If the gas station operator knows the criminal's identity and hides it, I'm pretty sure everyone would go after the gas station.

DDOS-protection is one of Cloudflare's services. The other one is hiding where you host your stuff, so people cannot contact your host to have them shut down the illegal operation.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#132
post #94

We simultaneusly act annoyed that Visa/Mastercard act as gatekeepers, and demand Cloudflare should become the new moral police

My side getting our way is good. Their side getting their way is bad.

It seems rational for any partisan to think this way, no? People standing on opposite sides of the battlefield, shooting at each other with the same sort of weapons, both believing in the goodness of their cause.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#133
post #102

Earlier quoted context omitted.

> And why isn't law enforcement stepping in? Because 1) they have limited resources and must prioritise and 2) America law enforcement seems to have a distinct lean towards the transphobic / homophobic / white supremacist / right-wing, etc. Just because something is not being actively policed does not mean it's not an actual crime (cf motorists running red lights for an easy example.)

Traffic violations are actually policed pretty closely because it's a source of revenue. High tech is employed to identify drivers, and even some shady tricks like shortening the yellow light. So it's not a good example. Regardless, it's a public forum(?), there should be tons of evidence if they routinely instigate swattings.

Traffic enforcement varies widely. Larger jurisdictions here in the Pacific Northwest seem to not enforce anything outside of parking rules in paid areas.

Meanwhile some neighboring suburban jurisdictions come down harshly on passerbys, even when the stop was unjustified and no crime occured.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#134
post #76

Earlier quoted context omitted.

These defenses of Cloudflare's behavior are getting very silly. Is there anything that Cloudflare could protect that you wouldn't be OK with? Because a DDoS-for-hire service is illegal, unethical, and contradictory of Cloudflare's stance that "cyberattacks, in any form, should be relegated to the dustbin of history."[1] Most importantly, it should be obvious to anyone that a company that has a purported goal of prote…

I don't really give two hoots about Cloudflare, I just don't like false statements, like when "Cloudflare helped me run a DDoS network" actually means "Cloudflare kept my website from being DDoSed", with the addendum "and I'm bad, therefore, not protecting KiwiFarms is hypocritical." It's just dumb.

It is like renting a storefront in a mall and selling goods stolen from other shops in the mall. What the storefront is doing is illegal, and offering them free rent hurts the other legitimate shop owners in the mall.

To extend the analogy, the mall also refuses to tell the other store owners who owns the shop so they can take legal action. (Cloudflare quite famously will just forward your complaints about hosting illegal services to the service themselves)

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#135
post #96

I strongly believe abuse claims should be handled by the actual hosting providers behind CloudFlare.

... which are unknown because CloudFlare's service includes "hide your backend".

If CloudFlare provided a way to find out the host of a website they run, and gave said host a way to find out what servers specifically are hosting it, they'd have a much better argument, because they'd make it easy for anyone to use the legal system to go after offenders.

I don't know how easy it is for US citizens or law enforcement to get that information from CF, but from what I've heard, it's very, very hard to do so from Europe, and will basically only be used for major crimes, but not for a common "scam a granny" operation. CF is essentially providing cover for these.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#136
post #130

Earlier quoted context omitted.

I feel like that's assuming a lot about Cloudflare - what evidence is there of such Machiavellian maneuovres on their behalf? Would it be impossible to run DDoS as a service for profit without Cloudflare? People were doing fine at just that before Cloudflare ever existed.

> Would it be impossible to run DDoS as a service for profit without Cloudflare? Quite frankly, yes. Before CloudFlare won the race to the bottom, you'd have to front thousands of dollars per month for bulletproof DDoS shielded hosting to get started. There is a finite amount of DDoS-for-hire business that used to keep itself in check because they were constantly throwing attacks at each other raising everyone's "cos…

Cheers :) Happy accident makes a lot more sense than "deliberate policy".

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#137
post #102

Earlier quoted context omitted.

> And why isn't law enforcement stepping in? Because 1) they have limited resources and must prioritise and 2) America law enforcement seems to have a distinct lean towards the transphobic / homophobic / white supremacist / right-wing, etc. Just because something is not being actively policed does not mean it's not an actual crime (cf motorists running red lights for an easy example.)

Traffic violations are actually policed pretty closely because it's a source of revenue. High tech is employed to identify drivers, and even some shady tricks like shortening the yellow light. So it's not a good example. Regardless, it's a public forum(?), there should be tons of evidence if they routinely instigate swattings.

> Traffic violations are actually policed pretty closely

I can stand on the main road where I live in London and see 100+ violations an hour with no enforcement.

> So it's not a good example.

Perfect example if you're in London, though.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#138
post #102

Earlier quoted context omitted.

Traffic violations are actually policed pretty closely because it's a source of revenue. High tech is employed to identify drivers, and even some shady tricks like shortening the yellow light. So it's not a good example. Regardless, it's a public forum(?), there should be tons of evidence if they routinely instigate swattings.

> Traffic violations are actually policed pretty closely I can stand on the main road where I live in London and see 100+ violations an hour with no enforcement. > So it's not a good example. Perfect example if you're in London, though.

Can you also skim Kiwi Farms and find at least a few of these supposed swattings?

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#139

The deplatforming logic is practical but pretty shaky as a long term strategy. Kiwifarms absolutely may have been a despicable place causing real harm to people. In that case, the police should initiate a request to take them down that Cloudflare or ISPs etc. are obligated to follow. The problem is the government is completely ineffective and regularly offloads their responsibility to platforms like Facebook, Cloudfl…

> A private company should not be making decisions on essentially freedom of speech.

This comes up a lot and makes me think I’ve misunderstood US free speech dynamics. I thought the USA traditionally limited the government’s ability to regulate free speech, leaving it to private / social regulation. In other words, it was up to individuals, communities, companies and so on to decide what was acceptable.

But perhaps that’s a misunderstanding. Can anyone recommend books or papers to better understand the history of free speech in the USA? I guess The Federalist Papers are often a good place to start?

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#140

What's at the heart of the entire Cloudflare situation is this discussion around the platform's alleged neutrality. I do not understand this at all. If I run a business, and I see that unambiguously bad actors namely abusers, criminals, stalkers, harassers or whatever use my services to facilitate their actions I have a very clear ethical obligation to step in. I don't go "well the law isn't here, it's not my problem…

It really depends on the business you run. If you run the local electric company, and you read in the paper that some guy in your service area has been doing terrible things, do you turn off his power? Cloudflare sees their anti-DDoS services as a similar infrastructure-level service, and while you might not agree with that (I'm not sure I do either), it's not immediately unreasonable.

Is CF a utility in that way? I think you can argue that their DDOS-mitigation might be.

But that comes with the additional benefit of hiding the origin. This resembles a post-forwarder service or a bank that knows the customer's real identity, but provides a way for them to conduct business without exposing it. Is there a good-faith argument that this service is a public utility and should be provided even if the customer is using it for criminal activity?

If someone used FedEx to run a fake pharmacy and deliver fake medication to people while staying out of reach for law enforcement and regulators by using a FedEx-provided return address, would you say that FedEx should enforce their T&C and shut that customer down?

Post reply on HN