Live data from Hacker News

I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

rasbora.dev

231–240 of 244 posts

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#231

The deplatforming logic is practical but pretty shaky as a long term strategy. Kiwifarms absolutely may have been a despicable place causing real harm to people. In that case, the police should initiate a request to take them down that Cloudflare or ISPs etc. are obligated to follow. The problem is the government is completely ineffective and regularly offloads their responsibility to platforms like Facebook, Cloudfl…

> police should initiate a request to take them down that Cloudflare

Police is executive, not legislative, they cant willy-nilly decide such things.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#232

Earlier quoted context omitted.

To steal a line of discussion I heard on a podcast some time ago—at what point along the chain does this stop being acceptable? In other words, which of the following scenarios are you okay with? • A data center refusing to host Kiwifarms. • An ISP refusing to provide internet to the data center that hosts Kiwifarms. • A power company refusing to provide electricity to the data center that hosts Kiwifarms. • An ISP r…

I am okay with 100% of these scenarios. If I am a Jewish Doctor and a card-carrying Nazi came in, I should have the right to say "he can sit over there and I will not treat you". And if that causes him to die, that is his fault not mine. If I am a Jewish contractor for a power company and I enter the home of a card-carrying Nazi, I should have the right to say "I will leave now, and you can sit in the dark until you…

> If I am a Jewish Doctor and a card-carrying Nazi came in, I should have the right to say "he can sit over there and I will not treat you". And if that causes him to die, that is his fault not mine.

Not exactly. I don't think medical ethics work that way in matters of life and death. For example:

https://www.timesofisrael.com/medics-told-to-treat-attackers...

Israeli medics told to treat terrorists the same as victims

"New rules from Israeli Medical Association require that the wounded be aided in order of severity of injury, even if that means helping assailants before victims"

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#233
post #164

Earlier quoted context omitted.

I just don't think its ever going to be realistic for a company to be held responsible for everything every customer puts up on the web, because there are millions/billions of them. The problem is any organized body of people can start a similar pressure campaign against Cloudflare or Facebook or Reddit. It is now their job to be a complete legal system - listen to each complaint, adjudicate who is right and who is w…

The problem with your argument is that CloudFlare didn’t act to benefit ordinary citizens, it acted to protect its shareholders from a material risk to the company. It’s always been the case that businesses have to choose who they do business with and that clients can take their business elsewhere if they don’t like how a company behaves, very much including demanding that other clients are dropped. Companies started…

Than lets go one level closer to the user.

Should ISPs proactively block certain websites to all clients under threat of leaving of a group of clients?

I think we want some companies to behave like utilities and be agnostic.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#234
post #152
post #142

Earlier quoted context omitted.

By the nature of how Cloudflare works, you have to provide them with your domain name and the content of your website. See if you could come up with a simple regular expression to deny services to these well known DDoS providers that are actively using Cloudflare: CryptoStresser.com Instant-Stresser.com FreeStresser.so StresserAI.com Booter.sx Flystress.net Bootyou.net

Say you go to a bank to get a loan, and you give the bank your details, including your address. The address you give is in a notorious crime-infested neighborhood. Does the bank have the moral obligation to deny you a loan, in order not to support criminal activity? I mean, they most likely will . However, most people instead like to attribute this behavior to banks being racist. Are you saying that this should inste…

If you were getting that loan to buy a house to use as a base of operations for harassing people in the neighborhood, the bank would rightfully deny your application.

You're strangely trying to tie this to someone simply living in a high-crime neighborhood. It's racist to deny a qualified person because the neighborhood is "high-crime" because often neighborhoods are high-crime because they're also over policed (which increases crime stats). In your analogy, the person isn't a known criminal, and isn't more likely to commit crime simply by living in an area that has a higher crime rate.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#235

Earlier quoted context omitted.

To steal a line of discussion I heard on a podcast some time ago—at what point along the chain does this stop being acceptable? In other words, which of the following scenarios are you okay with? • A data center refusing to host Kiwifarms. • An ISP refusing to provide internet to the data center that hosts Kiwifarms. • A power company refusing to provide electricity to the data center that hosts Kiwifarms. • An ISP r…

I am okay with 100% of these scenarios. If I am a Jewish Doctor and a card-carrying Nazi came in, I should have the right to say "he can sit over there and I will not treat you". And if that causes him to die, that is his fault not mine. If I am a Jewish contractor for a power company and I enter the home of a card-carrying Nazi, I should have the right to say "I will leave now, and you can sit in the dark until you…

"If I am a Jewish Doctor and a card-carrying Nazi came in, I should have the right to say "he can sit over there and I will not treat you". And if that causes him to die, that is his fault not mine."

Would you be okay with dying if a doctor refused to treat you based on this post on HN?

Suppose a doctor has strong convictions about free speech, detests cancel culture and is willing to let you die to make a point?

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#236
post #73

Earlier quoted context omitted.

I think that it's morally wrong to push the burden to end-users. If anyone should be accountable it must be the companies producing the devices and software.

End-users would likely end up in large class actions against the manufacturers in such a hypothetical situation. While turbulent for a brief moment it would be a strong market incentive for those who pump out insecure devices to change their ways.

That was not how the airlines was (very successfully) secured. It was by goverment regulations.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#237
post #54
post #32

Earlier quoted context omitted.

A simpler example: AWS hosts fakeLVbags.com. This site sells counterfeit luxury handbags, and says so clearly on the site. Now AWS does not realize this as they are large and have lots of operations. However, one day a journalist asks Amazon directly about this website, and there is an official press release by Amazon made about it. AWS has had this illegal activity brought to their attention, as well as the fact tha…

A DDoS Protection company doesn't know what the state of the market is? Really? Feigning ignorance on this matter is not very honest. Your aws story is completely irrelevant since AWS doesn't sell counterfeit luxury handbag insurance. Would you argue amazon webstore doesn't know about fake products in their marketplace?

to be clear I'm not trying to defend Cloudflare. The sort of generous interpretation is that even if CF understands this at a high level that doesn't necessarily lead to them knowing where these services are and which companies they are hosting that have this (though ... honestly, for B2B services like CF it feels pretty reasonable to at least do the vaguest sanity check)

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#238
post #152

Earlier quoted context omitted.

Say you go to a bank to get a loan, and you give the bank your details, including your address. The address you give is in a notorious crime-infested neighborhood. Does the bank have the moral obligation to deny you a loan, in order not to support criminal activity? I mean, they most likely will . However, most people instead like to attribute this behavior to banks being racist. Are you saying that this should inste…

If you were getting that loan to buy a house to use as a base of operations for harassing people in the neighborhood, the bank would rightfully deny your application. You're strangely trying to tie this to someone simply living in a high-crime neighborhood. It's racist to deny a qualified person because the neighborhood is "high-crime" because often neighborhoods are high-crime because they're also over policed (whic…

I’m using banks denying a loan to a high-crime neighborhood address as an analogy to explain why it’s also bad to deny hosting or service based on the domain name alone. It’s basically the Scunthorpe problem.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#239

Earlier quoted context omitted.

You’re confusing the First Amendment — a particular law about the government’s requirement to uphold the principle of freedom of speech — with the principle of freedom of speech more generally. In this context, the First Amendment is irrelevant - it doesn’t apply here; it says nothing about the actions of private companies. Instead, people are discussing the principle of freedom of speech, and in particular the exten…

I don't think it's confusion; the two are inherently connected. How can a law (and it's consequent enforcement) dictating some types of speech not play into freedom of speech more generally? Freedom of speech is rightly often characterized as a core American principle; it's emphasized in civic education, and most of the country will, if anything, overstate what is actually allowed by it. Generally though, I think it…

Another parallel to these tensions between free speech, commercial responsibilities and rights is a kind of tension between the ability to be anonymous on the internet (on social networks especially) and the inability to track down dangerous things on social networks and/or prevent them. But - it's not just about anonymity in lies or persuasiveness on the internet.

I love being able to be anonymous or pseudo-anonymous on the internet. At the same time, the ability of people to persuade others of dangerous, destructive lies on social networks is terrible for society. It's not just the us of course, there have been multiple other countries where people were persuaded to attack the 'other' minority group or religion or whatever because they were secretly attacking them.

I'm in the us and social media has destroyed the ability to have some basic agreement on what has happened in the world (such as the issues of the election in 2020). But it's not just social media. It's certain conservative news outlets that push these lies, persuasively!

And I don't know what to do about these problems. I honestly don't see how we as humans will develop a better ability to study what happens and get to a basic understanding of reality - even in the face of conflicting information. My own dad was an EE and a cfo of a billion dollar a year company and now he's fallen into the sway of a certain american network's lies and racial animus. Maybe he was always sympathetic to these views.

Re: I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped

#240
post #164

Earlier quoted context omitted.

The problem with your argument is that CloudFlare didn’t act to benefit ordinary citizens, it acted to protect its shareholders from a material risk to the company. It’s always been the case that businesses have to choose who they do business with and that clients can take their business elsewhere if they don’t like how a company behaves, very much including demanding that other clients are dropped. Companies started…

Than lets go one level closer to the user. Should ISPs proactively block certain websites to all clients under threat of leaving of a group of clients? I think we want some companies to behave like utilities and be agnostic.

Honestly, there’s quite a few firms that want to have their cake and eat it on this one. Not just internet firms, but credit card companies. And I’m 100% not onboard with that.
Post reply on HN