Live data from Hacker News

I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

rasbora.dev

21–30 of 244 posts

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#21

Cloudflare is oddly political for an infrastructure provider. Every few months or so they seem to be forced to explain why they have decided to deplatform this or that website contrary to their no interference policy. You don’t see AWS or Microsoft having the same frequency of these sorts of reports. What am I missing?

Normal service providers normally remove violent/hate sites as a matter of course, which makes it not news. Cloudflare has set themselves up as a sort of refuge of last resort, for [redacted] reasons. Fill in the blank yourself.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#22

How do we prevent DDOS without centralized services like these? There has to be something. It would be nice if these attacks were blocked before they even get to a transit provider, but cheap server / VPN providers seem unmotivated to try to solve the problem (since they barely lose any money when they facilitate the DDOS, and/or the attacking devices are rogue IoT devices and booting them would mean booting legitima…

Pay per packet.

I remember maidsafe was working on this for many years without much success. Then they got into crypto for micropayments a decade later and it all got a bit messy. Not sure how the project is doing these days but it was a solid concept at heart.

https://maidsafe.net/

> legitimate customers who don't know the first thing about auditing their network for compromised devices

An IoT device not suddenly working is a good signal to endusers that it is compromised and being used illegally.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#23
post #18
post #9

I don't think the author's argument makes sense. Cloudflare's position is that they are neutral and will provide their services to anyone and everyone. They do not make those value judgements deciding who deserves their services or not. The fact that they thus provide their service to booters isn't a flaw in Cloudflare's argument, in fact it's consistent with their position. The author is implying that Cloudflare sho…

I would agree with you, however please take a look at a statement from CloudFlare earlier today: https://news.ycombinator.com/item?id=32707821 "Our decision today was that the risk created by the content could not be dealt with in a timely enough matter by the traditional rule of law systems." Booter services have been using CloudFlare for the better part of a decade, sure individual services come and go but the tren…

Ok, I honestly know nothing about this topic, I just read the article and my comment is merely a critique of the original article's internal logic and nothing more.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#24
post #16

Earlier quoted context omitted.

Ok then. Better to have lead with that if it's going to be a central topic in the article.

It's the second link in the article and part of the header abstract.

The second link in the article is the Cloudflare blog post and I'm not seeing a header abstract on my device, just a title and text.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#25

How do we prevent DDOS without centralized services like these? There has to be something. It would be nice if these attacks were blocked before they even get to a transit provider, but cheap server / VPN providers seem unmotivated to try to solve the problem (since they barely lose any money when they facilitate the DDOS, and/or the attacking devices are rogue IoT devices and booting them would mean booting legitima…

Thinking out loud: Maybe by decentralizing the things being attacked? AFAIK it's much harder to DDoS a torrent than a website. Of course, moving a p2p/decentralized websites would require solving a number of other problems.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#26

How do we prevent DDOS without centralized services like these? There has to be something. It would be nice if these attacks were blocked before they even get to a transit provider, but cheap server / VPN providers seem unmotivated to try to solve the problem (since they barely lose any money when they facilitate the DDOS, and/or the attacking devices are rogue IoT devices and booting them would mean booting legitima…

Pay per packet. I remember maidsafe was working on this for many years without much success. Then they got into crypto for micropayments a decade later and it all got a bit messy. Not sure how the project is doing these days but it was a solid concept at heart. https://maidsafe.net/ > legitimate customers who don't know the first thing about auditing their network for compromised devices An IoT device not suddenly wo…

So you want to put everyone on a metered internet connection?

And then hit them with massive bills if they have a device that gets hacked?

Seems unreasonable given the current state of security.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#28

Cloudflare is oddly political for an infrastructure provider. Every few months or so they seem to be forced to explain why they have decided to deplatform this or that website contrary to their no interference policy. You don’t see AWS or Microsoft having the same frequency of these sorts of reports. What am I missing?

It's the exact opposite. They try to be, and I believe are, the least political out of all networking infrastructure companies, so in the very rare cases where they do decide to deplatform (Daily Stormer, 8chan, and Kiwi Farms are the only three) it always makes huge press. AWS or Azure doing the same wouldn't make news because they would immediately drop a site like Kiwi Farms, and anything like it, after the first…

Thanks, that makes sense.

Still, I don’t understand why Cloudflare goes out of its way to be a white knight when its peers have far less mercy. What’s in it for them? Companies at this scale remove the “don’t be evil” slogans they adopted when they were smaller.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#29

Cloudflare is oddly political for an infrastructure provider. Every few months or so they seem to be forced to explain why they have decided to deplatform this or that website contrary to their no interference policy. You don’t see AWS or Microsoft having the same frequency of these sorts of reports. What am I missing?

You're missing that nobody makes a fuss about AWS removing things. Unsavory and/or illegal sites are removed from AWS every day for TOS violations - a somewhat recent and notable example was Parler, the extreme-right-wing Twitter clone that was used to plan the January 6th insurrection.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#30

How do we prevent DDOS without centralized services like these? There has to be something. It would be nice if these attacks were blocked before they even get to a transit provider, but cheap server / VPN providers seem unmotivated to try to solve the problem (since they barely lose any money when they facilitate the DDOS, and/or the attacking devices are rogue IoT devices and booting them would mean booting legitima…

Pay per packet. I remember maidsafe was working on this for many years without much success. Then they got into crypto for micropayments a decade later and it all got a bit messy. Not sure how the project is doing these days but it was a solid concept at heart. https://maidsafe.net/ > legitimate customers who don't know the first thing about auditing their network for compromised devices An IoT device not suddenly wo…

> An IoT device not suddenly working is a good signal to endusers that it is compromised and being used illegally.

Given the overall quality of cheap electronics, if I had a camera on the fritz, even knowing what I do, the last thing I’d suspect is that it’s been compromised.

Post reply on HN