Live data from Hacker News

Can someone please explain whether Cloudflare blackmailed Canonical?

flyingpenguin.com

171–180 of 182 posts

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#171
post #145
post #139

Earlier quoted context omitted.

This is called KYC and is a standard part of operating a financial service. Seems to me like it should be part of internet infrastructure services as well. And, I thought, in some cases already is?

... and financial services companies huge and small still go out of their way to help their clients move money around in a myriad of ways, because it's very lucrative and there are so many loopholes and ways to obscure things. Offloading the responsibilities of law enforcement and regulatory bodies to private companies makes things worse for everybody. Providing non-crime services to criminals should not be a crime a…

No fintech within reach of the US government is going to give money to terrorists under sanctions on the SDN without facing severe fines/consequences. That various groups have faced consequences for giving money to terrorists is a sign of the system working, not that it doesn't work. No system is going to be 100% perfect, but the US is pretty serious about having no one they have control over sending money to eg North Korea.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#172
post #146

Earlier quoted context omitted.

> the webpage being hosted by cloudflare, which is just a marketing page and a login portal thus being used for illegal and harmful activities right? > Cloudflare retains the right (but not the obligation) to block content from its Distributed Web Gateway that Cloudflare determines (in its sole discretion) to be illegal, harmful Not that I have any hope for TOS violation claims. I've learned early on in life that peo…

> thus being used for illegal and harmful activities right? neither the login portal page nor the marketing page are illegal. > Cloudflare so far hasn't acted like a party that has the good of the web in its interest for a lot of reasons, i generally agree with this statement. however, for this specific reason (maintaining a content-neutral approach, instead of playing content-police), i could not disagree more. clou…

What's inside the login portal? I honestly don't know and am genuinely asking but the article didn't seem to go into it, but if the login portal leads to a page with a btc/other crypto address and a text box where the attacker enters ubuntu.com and a submit button labeled DDoS, should that bit be legal?

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#173
post #156

"Renting attack capacity from [cloudflare]" is inaccurate as I understand things. That group hosts their site behind cloudflare but I have not seen anyone claim that cloudflare's infra is used for the attacks. This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.

Yes, agreed these are very different things. Also I'm not really sure the argument holds, there are plenty of AWS Command and Control hosted servers and AWS victims, is AWS to blame or blackmailing? The answer is a large no.

AWS does have an abuse department though, and if you're in that space, you can send them abuse reports and they'll do something about that.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#174

Earlier quoted context omitted.

They have done it at least 3 times: The Daily Stormer, 8chan, and Kiwi Farms

Thanks for the correction, I didn’t know they had done it again. Unfortunate that they allowed themselves to be bullied into deplatforming again. DDoS protection should be content-neutral, like electricity service.

Which, the FBI can get the electricity shut off in a hostage situation.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#175

people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received. if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some…

One of the few reasonable comments on this thread. I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters. Zero evidence that cloudflare actually enabled the attack itself from what I can tell.

Do you think people in that space aren't going to go after the "million other" static site hosts for hosting their content though? Yeah it's a game a whack a mole but there are some motivated whackers out there because they really don't like DDoS for hire services.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#176

Earlier quoted context omitted.

Should Walmart be responsible for performing background checks on people buying crowbars to ensure they don’t intend to do harm? What about lighter fluid? Rat poison? Baseball bats?

you keep missing the point. is it intentional?

I believe I simply disagree with you.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#177

Earlier quoted context omitted.

Thanks for the correction, I didn’t know they had done it again. Unfortunate that they allowed themselves to be bullied into deplatforming again. DDoS protection should be content-neutral, like electricity service.

Which, the FBI can get the electricity shut off in a hostage situation.

We’re not talking about a hostage situation, we’re talking about extralegal deplatforming.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#178

Earlier quoted context omitted.

Seems like they could use Tor onion sites just as easily tbh.

Why don't they?

Good question—they should?

Or maybe not, I’d rather have more Tor sites that aren’t questionable content. It’s a great tool for hosting even personal sites if you appreciate privacy and resilient infrastructure.

(The great thing, though, is nobody can prevent you, or anyone, from hosting your site there.)

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#179

Earlier quoted context omitted.

I've never tried a subpoena. I've tried reporting them to ICANN for whois abuse contact violations and never received a response (after I recieved a response from cloudflare saying, "Go away, we don't care, sign up for our services and pay us to care."). Perhaps I should set up a gofundme or something for the thousands of dollars needed to get justice via subpoena. If I were hosting illegal malicious actors doing thi…

> If I were hosting illegal malicious actors doing this stuff on my home servers and refused to even say who was doing it I would 100% get my door kicked down by the FBI. But some persons, corporate persons, are more equal than others. If you refused to tell some random person who asked? No, you wouldn’t. If you refused to respond to a legal authority—a court-issued subpoena, for example—then there would be consequen…

They have a legal obligation to provide a working abuse contact address. I guess you're saying that it is working when they say, "go away." and yeah, I can see that point of view.

But it also means that any domain fronted by cloudflare won't actually have contact information for the owner of the domain required by their legal contact with ICANN as a registrar.

Re: Can someone please explain whether Cloudflare blackmailed Canonical?

#180
post #145

Earlier quoted context omitted.

... and financial services companies huge and small still go out of their way to help their clients move money around in a myriad of ways, because it's very lucrative and there are so many loopholes and ways to obscure things. Offloading the responsibilities of law enforcement and regulatory bodies to private companies makes things worse for everybody. Providing non-crime services to criminals should not be a crime a…

No fintech within reach of the US government is going to give money to terrorists under sanctions on the SDN without facing severe fines/consequences. That various groups have faced consequences for giving money to terrorists is a sign of the system working, not that it doesn't work. No system is going to be 100% perfect, but the US is pretty serious about having no one they have control over sending money to eg Nort…

Ok, terrorists and countries we've been at war with for 70 years. What about drug dealers, mafias, hitmen, corrupt politicians, white collar criminals, scammers, etc? Criminals that actually threaten Americans? Nobody cares about whether terrorists or whatever tinpot dictator can get funding through US banks, because the CIA is bringing pallets of cash to them anyway.
Post reply on HN