Live data from Hacker News

Cloudflare took down our website

robindev.substack.com

451–460 of 483 posts

Re: Cloudflare took down our website

#451

As far as I can tell, the issue with this is: OP runs a casino/gambling site. Gambling is a regulatory mess (I have spent far too long dealing with this as an RNG supplier), and so it's very hard to comply with every jurisdiction, and each one needs you to prove compliance to operate in that jurisdiction.* Gaming companies spend a lot on compliance and tracking, but since the internet is the internet, it's pretty har…

Ok, I have to ask: are you a Random Number Generator (RNG) supplier, or a Renewable Natural Gas (RNG) supplier, or some other kind of supplier??

Considering they mentioned working with gambling/casinos, I would assume random number generator. Which may seem somewhat trivial to build a business around, except if you’re in a highly regulated industry like gambling that regulates the implementation of randomness (and probably requires auditing and other complicated things like that). I would love to read a blog post on all the complexities at here.

Re: Cloudflare took down our website

#452
post #397

Earlier quoted context omitted.

I wrote what I wrote. He came here and in his only comment, criticised Google for not being quick enough. That is all I wrote and all I meant. https://news.ycombinator.com/item?id=13718752#13721644 I don't much care if words are being put in my mouth but I do point it out. But then again as Maya Angelou said: "When someone shows you who they are, believe them the first time."

For someone getting very aggressive for words "being put in your mouth", you're not really paraphrasing that Cloudflare CEO very fairly. He was specificity responding to someone complaining it's still in Google's cache, by stating that "The caches other than Google were quick to clear [..] I agree it's troubling that Google is taking so long.". By leaving out this context, and phrasing it a "strategy", is not a fair…

The context in which Cloudflare was saying it was that a team at Google was the one to discover the issue in the first place. That's why that particular comment was taken so uncharitably by many at the time.

Re: Cloudflare took down our website

#453
post #398

Earlier quoted context omitted.

Hmm. My take is the casino structured its business to comply, not to evade interest. Further, I don't see how Cloudflare benefits by taking on the risk to charge more to help a customer avoid scrutiny. More like: they know it's a humming business and want a piece.

> My take is the casino structured its business to comply, not to evade interest It's impossible to say what's going on since it's an anonymous post with no details. Maybe it's all 100% true. Maybe there are some key details being left out. Wouldn't be the first time I've seen one of those outrage posts that seriously misrepresented things. Whatever the case, obviously the author is not an unbiased party. These posts…

Thing is, this is also not the first time when Cloudflare T&S team has been disrupting their customers out of the blue. The post even has some links to other HN stories.

Re: Cloudflare took down our website

#454
post #46

Earlier quoted context omitted.

Taking a step back, why would they even care if their platform is supposedly neutral and not responsible for the content ? If they can indeed stop providing services to a casino, why cannot they shutdown a website spreading pro-war propaganda, or a website selling illegal services ? It means they are making editorial choices, instead of just being the technological provider and being a neutral "internet pipe". Not su…

> Taking a step back, why would they even care if their platform is supposedly neutral and not responsible for the content ? Because their main network all uses one big IP address pool and the blocks by various regions/countries against their site were probably not just DNS blocks but also IP address blocks. So they now have an account whose activity is getting their IPs banned in countries where they operate. So the…

This may indeed be the motivation but, at least in those emails that are presented in the linked post, there's no evidence that Cloudflare did at any point clearly communicate that this is indeed what the problem is.

Re: Cloudflare took down our website

#455

Earlier quoted context omitted.

I would be very happy to hear Cloudflare's actual side of this. (Or - it would have been great if they had given their side to us before getting into this mess). The only critical information from our side that I'm aware of is that we're a casino with multiple domains - which is why I put that right at the top. But most of the info should be relevant to any business interacting with CF. I do admit that I originally d…

My experience with Cloudflare is that anytime “Trust and Safety” are involved, no one will ever be told anything. Even if it’s a totally benign or even good situation. Even if they find a case in your favor or resolve an issue for you. Whoever runs that team really, really gets off on being withholding, as Buster Bluth would say.

This seems to be the rule in general with large companies.

They say it's because if such teams don't operate under secret protocols, the "bad guys" will discover the loopholes in them. But I rather suspect that this has more to do with evading legal liability.

Re: Cloudflare took down our website

#456

Earlier quoted context omitted.

I interviewed there once and they asked me what I would do if a service broke after a deployment. I said the first step was to revert to the last known good version and then investigate. Color me surprised when that was not the answer they expected.

That's strange. What was the "correct" answer?

They wanted me to roll out a fix first. Apparently rolling back first was not moving fast enough for the interviewer’s liking.

Re: Cloudflare took down our website

#457

Earlier quoted context omitted.

My guess for why this would be flagged: its a gambling website so people are unsympathetic. Definitely an abuse of the flagging system.

Maybe HN needs a flagging ring detector as well as its voting ring detector.

You can always email the mods if you believe you’re witnessing an attack on either a single article and/or the site; they have many more tools to reveal concerted group assaults than we do.

Re: Cloudflare took down our website

#458

Earlier quoted context omitted.

Flags below the [flagged] threshold are invisible but still act to downweight the post.

I've noticed that cloudflare complaint threads get flagged with surprising and unwarranted regularity.

They’re boring, repetitive, and uninteresting with surprising regularity. It’s no surprise that many of them get flagged as a result.

Re: Cloudflare took down our website

#459

Earlier quoted context omitted.

You would be surprised how big of a hammer ISPs will use when they are told to hit something. They live in a very different world than many modern web software companies - they are the plumbers for lots of things you take for granted, and look at the world the way a plumber does. Thanks to TLS, the plumbers can't see the HTTP headers to figure out what's actually flowing, so they sort of end up whacking all of it. Ge…

It will be interesting to see. Just for completeness, Fastly is not requiring us to BYOIP or anything unless it causes them actual problems, which so far it hasn't. I'm sure they also have other similar businesses to ours so they should have some experience. I guess I'll see in a while if this was also just a sales tactic from Cloudflare or not.

Yeah, I also assume that any sane CDN of this size has enough IPs that they can reserve a /16 or so for their "risky" customers (each deployment needs a /24, usually, so /16 gets you 255 regional sites). If Fastly has no problems or can otherwise quarantine you, there's no good reason for the BYOIP demand.

Re: Cloudflare took down our website

#460
post #94
post #34

Earlier quoted context omitted.

I'm not defending Cloudflare's exact actions in this scenario, but it seems reasonable that there are cases where yes, for $10k Cloudflare is okay. Risk can be mitigated, especially if you take care to know what the risk is, but risk mitigation and the salaries of the risk mitigation teams are not free. The answer of "no, we will not host you unless you pay us enough money to hire people to make sure we're not breaki…

And all of that is fine when communicated properly. Even if OP is an unreliably narrator are we to believe they also left out some of CF's emails? To me it looks like https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_pr... is entirely the wrong email to send in the situation and if you are as old as I am and come from where I come from, you will have flashbacks to "reading between the lines" of the party dail…

T&S departments generally exist for one reason: to manage reputational risk. This sometimes involves legal risk, but it usually just means preventing relentless hit pieces about your company enabling something portrayed as horrible. This can result in customers and even employees leaving if the media is relentless enough.

Companies take risks if the reward is considered good enough. In this case, that reward is income from the customer (who can still be dropped if the hit pieces start getting published).

Post reply on HN