Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

151–160 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#151

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

In The Before Times, there were very few problematic DDOS operations because... they would all DDOS one another offline. Websites, control infrastructure, anything. DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups. Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services.…

Why didn't those companies use Telegram?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#152
post #132

Earlier quoted context omitted.

"... its really jarring to see the general sentiment on this submission ..." I am heartened to see a high default level of suspicion, bordering on contempt, for a global observer MITM'ing as much of the Internet as they can. I'm not sure if Cloudflare is a malicious actor but we should all behave as if they are .

you are heartened to see people advocate for cloudflare to start proactively and arbitrarily deciding who can host legal content, instead of being content-neutral? their size and the "man-in-the-middle"-ing is a huge problem. however, i dont think the solution is to encourage them to also start acting as content police. i dont trust cloudflare, which is exactly why i dont want them policing my legal content. you want…

I don't think it's proactive, most people are just saying they should respond to abuse reports more or should be treated based on their lack of response.

If I'm hosting anything I don't have to proactively police it. If someone alerts me that a certain domain I'm hosting points to something illegal, I then decide if I want to remove it or not (and don't decide this based on a shell script). Cloudflare is apparently just fine removing child porn when reported, so we know they are making an active decision in every case, and we can judge them based on their decisions.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#153
post #76

Earlier quoted context omitted.

> We already live a world where your service is terminated for illegal activity. Of course we want it, how is this even a question? you are misunderstanding me, but im not sure if you are doing it on purpose. if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. > The mental loops people in these comments are using to supp…

> if they receive a lawful order of course they should oblige. and without a lawful order they should not make content-based decisions on what to host. You are ignorant of the law. You cannot host user content without being required to police it for at a minimum things like child porn. But this is also not a remotely ambiguous case. Any normal service would instantly terminate a client account if the client is blatan…

You don't have to police content. You only have to take content reports and read them. (Assuming you don't live in a dictatorship)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#154

Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry. Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me. I don't think it should be a…

That's not a "weird belief". Cloudflare positions itself as "infrastructure". That means they think they are not responsible for the content that they carry. In a normal scenario, if you want to protect your systems from other "bad" systems on the internet, you can block them on the IP layer. But Cloudflare operates at the IP layer proxying data between you and good and bad (and everything in between) systems. In a n…

This is a good thing. You shouldn’t be able to get a Discord full of “activists” with personality disorders to spam someone’s host with false abuse reports and threaten them until the host boots them out of sheer annoyance.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#155

Earlier quoted context omitted.

But the Ubuntu update servers are necessary to serve the update. Taking them down prevents the users from downloading the update. I don't know whether the update servers were affected though.

They were affected, update service was intermittent for a couple days

It is apparently still intermittent as it no longer works when I'm on a VPN, but does work when I disconnect from the VPN.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#156

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

Yes, agreed these are very different things. Also I'm not really sure the argument holds, there are plenty of AWS Command and Control hosted servers and AWS victims, is AWS to blame or blackmailing? The answer is a large no.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#157
post #139
post #123

Earlier quoted context omitted.

How? Their sign-up flow would have to change dramatically. It might even become a process that is internally "expensive". There is likely one or more managers in charge of this decision and they don't want it. Additionally the current universe rewards the current situation (for them)

This is called KYC and is a standard part of operating a financial service. Seems to me like it should be part of internet infrastructure services as well. And, I thought, in some cases already is?

KYC is useless as a regular user. I hope it never infects industries outside the financial system.

Why care about them hosting an info page for anyone? Cyber criminals supposedly can host it a billion other ways so why care?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#158

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

Linux users and FUD. Name a more iconic duo

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#159

Earlier quoted context omitted.

>if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever They already pick and choose. They have not decided to sit outside of it. Any claim about them not getting involved should be read as tacit approval. Because we know they will drop users they sufficiently disapprove of.

They have done this one time and the CEO said he regretted it.

They have done it at least 3 times: The Daily Stormer, 8chan, and Kiwi Farms

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#160

Earlier quoted context omitted.

Cloudflare enables this because their stance is that they are a neutral carrier who is not responsible for the data they carry. If I send an abuse report to github for content on their system, there is a chance that I will be annoyed by how they handle it. Cloudflare's core thing OTOH is to hide who I could be sending an abuse report to, Possibly they will forward it ( more likely not) , but they will include my pers…

You can report abuse here anonymously - what am I missing? https://www.cloudflare.com/en-gb/trust-hub/reporting-abuse/

If you report most types of abuse, nothing will happen.
Post reply on HN