Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

131–140 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#131
post #5
post #3

They didn’t.

Yeah, probably not - because they don't explicitly have to, as outlined in the post. The very architecture of CF's services essentially enables "blackmail as a service" in the sense that, CF protects the attacker and essentially creates a coercive environment in which the victim "has" to pay CF to protect them from... the very attacker that CF protects.

> and essentially creates a coercive environment

This is the part that's wrong. CF is not creating the fact that sites are vulnerable to DDoS, and these attacks would happen even if the sites were kicked off.

If some guys are going around slashing tires, would we demand that tire repair shops not sell to them? Would we say it's blackmail because the tire shop sells to anyone, and selling tires to them "creates a coercive environment"?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#132

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

"... its really jarring to see the general sentiment on this submission ..."

I am heartened to see a high default level of suspicion, bordering on contempt, for a global observer MITM'ing as much of the Internet as they can.

I'm not sure if Cloudflare is a malicious actor but we should all behave as if they are.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#133

Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…

Cloudflare & AWS wouldn't even INVESTIGATE a abuse report I sent because there weren't any "infringing URLs" or "specific resources".

I provided enough evidence for them to at least be able to kickstart a internal investigation or even CONTACT the abusive customer, which they did not do.

If it were a stresser, all they would see is a login panel. It's not like these sites are publicly advertising what they're doing...

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#134
post #6

This is insanely dumb. Cloudflare is providing free hosting services, not materially supporting the attacker. You can argue that cloudflare needs to be better, or adopt different values towards, taking down sites they host, but this organization could absolutely just serve elsewhere (or just advertise their services over telegram or the like). Maybe there is a point to be made about monopoly power in hosting and ddos…

Seems unavoidable if you're running DDoS protection services. Of course the people performing the attack also don't want to get attacked back.

Taking down their info site wouldn't have made the attack go away anyway.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#135

Earlier quoted context omitted.

How did you get that from the comment? It’s the other way around - if you report criminal or illegal sites hosted by cloudflare they will take it down. I’ve hosted content online for decades and never once talked to cloudflare.

Will they? Have you gone through that process with them? In my experience (admittedly somewhat stale) it was fairly hard to get through to them, much less to get the information required to actually report bad actors to their real hosting provider that Cloudflare is fronting.

I once came across a website hosting extremely inappropriate content while surfing the web. I discovered that this website was using Cloudflare for DDoS protection and other purposes. I had a bit of a look online and found out how to submit a complaint to Cloudflare. On that form, I was asked for my email address and no other personal details, if I remember correctly. On the very same day, I received an email confirming that my complaint had been accepted and was under review - presumably an automated response. It was already quite late, so I went to sleep.

And just a few hours later, I received a letter informing that the information about the website in question had been forwarded to the relevant authorities, as well as to the website’s hosting provider. To be honest, I didn’t read that second email until the next day (I was sleeping), and it seems the website's hosting provider acted quickly (or the site owners decided to cover their tracks), because when I went to that website to check how it is going, it was no longer active, no longer existed at all. It just was gone. That was about six months ago.

So... I won’t speak for others’ experiences, but in this particular case, they reacted quickly and quite effectively. Perhaps other people have had different experiences.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#136
post #35

Earlier quoted context omitted.

If a billboard company accepted an ad that included a threat on the president’s life or recruitment info for a known terror organization, are they complicit in the crime? Water is a basic utility so I don’t think that’s a fair comparison This is more like a firearms dealer selling a gun to someone after they put their intended usage as “robbing banks” in the ATF form

Nah this is more like a billboard service “selling” a billboard to someone (for free) and the billboard reads something like “wanna have a bank robbed for you? call me” — tbh not sure if that is illegal (probably depends on jurisdiction?)

Note in this example that the billboard seller is not told what messages will be placed on the billboard, and the billboard itself is a digital billboard that can change messages instantly on command and without permission required from the billboard seller.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#137
post #116

Completly agree, cloudflare protects scammers on a huge scale and no one cares... All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down. None of them. For a company making billions, protecting people, they should take this stuff serious.

Would you prefer a huge organization that arbitrarily censors websites without a mechanism for appeal or legal process? The current state of affairs is way better.

Can you seriously see no space between hosting people advertising DDoS-for-hire services and arbitrarily censoring the Internet? Is this what passes as civil discourse these days?

That's especially rich considering that Cloudflare is the actor perhaps best known for blocking access to the Internet for people who seek privacy. Have you tried using Tor during the past several years? Or just a lesser popular web browser?

Look, it's very simple. When any one of your customers is exactly the criminal you sell protection against, you drop them, otherwise you are aiding and abiding. Perhaps not exactly in the sense of the law, if you have expensive enough lawyers, but in practice.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#138
post #132

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

"... its really jarring to see the general sentiment on this submission ..." I am heartened to see a high default level of suspicion, bordering on contempt, for a global observer MITM'ing as much of the Internet as they can. I'm not sure if Cloudflare is a malicious actor but we should all behave as if they are .

>I'm not sure if Cloudflare is a malicious actor but we should all behave as if they are.

Theres sentiment and content. If you claim something without evidence, you become another malicious actor.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#139
post #123
post #111

Earlier quoted context omitted.

No. Nobody said that. Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.

How? Their sign-up flow would have to change dramatically. It might even become a process that is internally "expensive". There is likely one or more managers in charge of this decision and they don't want it. Additionally the current universe rewards the current situation (for them)

This is called KYC and is a standard part of operating a financial service. Seems to me like it should be part of internet infrastructure services as well. And, I thought, in some cases already is?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#140
post #132

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

"... its really jarring to see the general sentiment on this submission ..." I am heartened to see a high default level of suspicion, bordering on contempt, for a global observer MITM'ing as much of the Internet as they can. I'm not sure if Cloudflare is a malicious actor but we should all behave as if they are .

you are heartened to see people advocate for cloudflare to start proactively and arbitrarily deciding who can host legal content, instead of being content-neutral?

their size and the "man-in-the-middle"-ing is a huge problem. however, i dont think the solution is to encourage them to also start acting as content police.

i dont trust cloudflare, which is exactly why i dont want them policing my legal content. you want the "malicious actor" to exercise more control?

Post reply on HN