Live data from Hacker News

IP address blocking banned after anti-piracy court order hit Cloudflare

torrentfreak.com

21–30 of 92 posts

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#21
Plenty of corporate web filtering solutions block on IPs, and the adoption of ESNI will only make it worse. If you manage an important website, moving out of a bad neighborhood (Cloudflare) before you end up the victim of blocking is probably a good idea.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#23
post #19
post #6

Earlier quoted context omitted.

>The level of desperation the ISP’s engineers have felt in front of such incompetence must have been through the roof. If I was an engineer there I would block the addresses and call it a day. What do I care? After all it's customer service who will deal with the angry calls.

Obviously your boss or boss's boss would care.

It would be my boss or boss' boss ordering me to block the addresses, wouldn't it?

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#24
post #22

I noticed earlier today that thepiratebay.org seems to be down for the first time in a while. It's just a cloudflare error page at the moment. Really curious what's going on there.

That's just the usual shit show that is thepiratebay.org.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#25

Looks like my job. The best way to change stupid procedures is following them to the letter and watch the world burn.

This is one of the useful tactics that unions will use when they aren’t legally allowed to strike for one reason or another, they will engage in large scale “work to rule”, which is pretty much what it sounds like, you do your work following the rules to the letter and no further, stubbornly by the book no matter how inconvenient or unproductive or disruptive the rules are when you suddenly start following them exactly.

It’s particularly effective if the rules are a large part of their collective grievances with management, as it highlights to all involved that the current rules need changing, and can sometimes result in fairly quick and positive changes since it demonstrates to management that the current “rules as written” are not the most fiscally effective set of rules for running the business.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#27

> When the ISPs discovered that the IP addresses belonged to Cloudflare, arms were thrown up in despair. The level of desperation the ISP’s engineers have felt in front of such incompetence must have been through the roof. I am getting tired of our politics here in europe: tech literate people in governments are put to work on surveilance stuff, never for actual policymaking. The shit show continues.

Surely they should have contacted Cloudflare and asked them to sort out the issue with their network ...

CF will probably retort {common carrier, we are American and you are not etc}. Austrian policy makers get upset and ... THIS NONSENSE IS STILL NOT SORTED.

The internets are somewhat broken, quite badly. We all allow ourselves to end up in a series of virtual walled off silos - Facebook, Twitter etc, run by some pretty worrying monster commercial companies, whilst living within quite disparate physical societies. I think that the fediverse is a possible contender for the way forwards. I dumped Reddit for Lemmy and that seems to be working so far. I know a lot of 'X'iles are finding a home with Mastodon.

I worry about quite a few networks. One of the tools in the box is the IP block list. With the rise of the hyper-scalers, the IP blocklist is becoming increasingly useless. Same with SMTP filtering for spam. You can't block M365 or Gmail en-masse (tempting for my home setup, though!)

I recently gave CrowdSec a run at work (I will stick with it but with care). Great idea for the 2010s but not so much now. I got it to watch HA Proxy logs (proxies on site Exchange) and it pretty soon decided that my real users should be banned because of how Outlook works, or rather how the auth that Outlook uses works. Outlook doesn't just use Kerberos, it also uses EWS for the Addressbook and the good Lord knows what else. So you get a connection to a endpoint from Outlook without auth creds which generates a 401 (failed auth) error, then Outlook tries again, this time with creds and it works OK (200). To a CrowdSec agent those repeated 401s look like bots pissing around.

That is one reason why we cannot have nice things.

I'm a Brit (yes we Brexited) but I am still very much a European and so is my little country, like it or not - I have seen shed loads of number plates from across the EU trundling along the large A30/A37 crossroads/roundabout called Yeovil in Somerset. Mostly lorries and quite a few cars and campervans.

So I am from country X (GB in my case, not that X!) but I engage with (w,x,y,z) societies on line. Now whose laws apply? In general it seems we muddle along effectively but should there be a formal internationally accepted agreement?

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#28
post #23
post #19

Earlier quoted context omitted.

Obviously your boss or boss's boss would care.

It would be my boss or boss' boss ordering me to block the addresses, wouldn't it?

Yes, who would also yell at you when customers can't access their cat pictures.

Of course it could be an accident, and you didn't know. But if it was clearly malicious compliance, personally and I think I speak for many, I wouldn't continue to have on the team somebody with these kinds of traits.

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#29
post #28
post #23

Earlier quoted context omitted.

It would be my boss or boss' boss ordering me to block the addresses, wouldn't it?

Yes, who would also yell at you when customers can't access their cat pictures. Of course it could be an accident, and you didn't know. But if it was clearly malicious compliance, personally and I think I speak for many, I wouldn't continue to have on the team somebody with these kinds of traits.

I don't think I understand. A court orders you to block certain IP addresses: you have no options. If that block disallows access to unrelated pages there's nothing either the engineer or the boss can do. Should the engineer lose any sleep over this? Am I missing something?

Re: IP address blocking banned after anti-piracy court order hit Cloudflare

#30
post #11

I always assumed businesses such as Cloudfare or Google would have a good reason to be the main IPFS or tor node hosts, since that can help improve the backbone infrastructure for this side of of the internet, and can also help catch bad actors if there are any there (easily turn in all logs to three letter agencies if they knock, or they can simply offer it up for anon tips).

Google should run Tor? Yeah, that's an interesting idea, if you want to get rid of that annoying build in anonymity in tor which is its main purpose?
Post reply on HN