Live data from Hacker News

Thoughts on Cloudflare

xn--gckvb8fzb.com

71–80 of 88 posts

Re: Thoughts on Cloudflare

#71

I dislike how Cloudflare wants to do everything the Cloudflare way. A lot of their services are legit good and insanely cheap though, and containers have the potential to be a game changer that takes them from occasionally useful to the backbone of your cloud.

Help me understand your point better. How do you want the services to work? Is there some standard you are advocating for, or for them to mimic existing services, or what?

Re: Thoughts on Cloudflare

#72
post #54

Load of bull. Every article linked in this is either wrong or mischaracterized. Cloudflare does not facilitate phising - it just made proxying and tunneling easier. The breaches and bypasses mentioned are anything but - they are linking to a successful mitigation of an attack as if the attacker got away with something of value. This entire article reeks of trying to fit the evidence to an agenda. Considering they cou…

I've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.

Not my experience at all. We've reported hundreds if not thousands of sites and with few exceptions they have taken them down swiftly. Definitely one of the best cloud operators when it comes to this.

Re: Thoughts on Cloudflare

#73
post #54

Earlier quoted context omitted.

I've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.

Not my experience at all. We've reported hundreds if not thousands of sites and with few exceptions they have taken them down swiftly. Definitely one of the best cloud operators when it comes to this.

As recently as August 8th, I reported a phishing site targeting seniors into installing a pre-configured Atera client (who _also_ failed to respond in a reasonable time) by pretending to be an event invite. It was blatant and obvious phishing. This was the response:

---

Hello,

Cloudflare received your Phishing report regarding: ----

We are unable to process your report for the following reason(s):

We were unable to confirm phishing at the URL(s) provided.

Please be aware Cloudflare offers network service solutions including pass-through security services, a content distribution network (CDN) and registrar services. Due to the pass-through nature of our services, our IP addresses appear in WHOIS and DNS records for websites using Cloudflare. Cloudflare cannot remove material from the Internet that is hosted by others.

Please reply to this message, keeping the report identification number in the subject line intact, with the required information.

To respond to this issue, please reply to abusereply@cloudflare.com.

Thanks, The Cloudflare Team.

---

This is the typical response for me from Cloudflare - it took 2 more weeks before it was finally taken down. If I had to hazard a guess, your high volume of reports gets you into a very different support bucket than the occasional reporter.

Re: Thoughts on Cloudflare

#74
post #54

Earlier quoted context omitted.

I've reported blatant phishing attacks targeting seniors dozens of times to cloudflare (and so far it's always been cloudflare) and never once have they replied with anything except "we could not determine this was phishi g". They absolutely facilitate phishing through inaction.

Not my experience at all. We've reported hundreds if not thousands of sites and with few exceptions they have taken them down swiftly. Definitely one of the best cloud operators when it comes to this.

My most recent experience was terrible for two reasons:

1. They didn't take down an obvious banking scam site that was hiding behind their service

2. They forwarded my "report phishing content" submission, including contact information, to the scammer, resulting in a roughly 100x increase in the amount of spam I receive and ensuring that I won't ever use their reporting function again

Re: Thoughts on Cloudflare

#75
post #71

I dislike how Cloudflare wants to do everything the Cloudflare way. A lot of their services are legit good and insanely cheap though, and containers have the potential to be a game changer that takes them from occasionally useful to the backbone of your cloud.

Help me understand your point better. How do you want the services to work? Is there some standard you are advocating for, or for them to mimic existing services, or what?

By not harshly penalizing those who legitimately use VPN's, proxies?

I'm using FreeBSD - This is on the hit list

I'm using Waterfox - This is on the hit list

I'm using my colocated server for a VPN from a reputable provider - This is on the hit list

I eliminate the last two and suffer with my ADSL. My ADSL isn't a standard domestic provider so I'm hit with that too for using an alternative provider. I am still being penalized for using FreeBSD.

Every page I encounter that uses Cloudflare ends up with a captcha. Why isn't there a way to verify myself that I am an actual legit person? I've clicked the captcha enough times, why does it have to be every single time?

Why can't I whitelist my IP?

If this is truly the only way to restrict bad actors, then it's pathetic. Am I'm going to be hit for using Xorg and not Wayland in the future? Their "bot" protection technology is years out of date.

I don't like that Cloudflare has total control on how I can see the internet. I don't need any of their services, I don't want any of their services and others may praise them but to me not required.

This may of worked five years ago, but like cookie banners, it doesn't work now. Yet they wish to spin up new modern services and neglect the old that actually made Cloudflare and not some power-hungry MiTM service. That's what it feels like but not that they will listen. I hate the fact that any point they can just go full anal and force you to X.

The internet is suppose to have some sort of freedom, it's less than freedom. Using the internet now is like an animal in a cage. Heck, I would even register an account with Cloudflare if it allowed me to verify legitimacy.

Re: Thoughts on Cloudflare

#76
post #67
post #53

Earlier quoted context omitted.

>Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba. Source? AFAIK their China product is entirely separate and you need to specifically sign up for it. AWS/Azure have similar arrangements in China but you wouldn't say the Cloudfront users are getting MITMed by the CCP.

I noticed this years ago while in China. I saw someone at a bar with a laptop out using my web site. I went and chatted him up, and I noticed a different TLS certificate, I don't recall if he moused over the lock icon or if his browser, or back then when browsers showed the issuer in the address bar. Freaked me out. Apparently it's JD Cloud now. Or maybe it was the, and I don't recall correctly. It was a Chinese comp…

Are you sure they weren't using a corporate machine with some sort of MITM proxy? That seems far more plausible than what you're suggesting. Moreover it's unclear why they'd even bother minting a new certificate for the China side, rather than copying the certificate like they do for all their other POPs.

Re: Thoughts on Cloudflare

#77
Any infrastructure can be abused, but that doesn't negate its legitimate uses.In fact, it is precisely because of the popularity of free services such as CloudFlare that the threshold for network security has been significantly lowered.

Re: Thoughts on Cloudflare

#78
post #53
post #27

Earlier quoted context omitted.

They already do this for Chinese traffic. They send traffic from China to Alibaba controlled infrastructure. Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba. And I would not be surprised if they were abusing their middlebox position to do all kinds of surveillance based on secret "warrants" in other places.

>Think about the consequences of that. Anyone who connects to your site from China is MITM by Alibaba. Source? AFAIK their China product is entirely separate and you need to specifically sign up for it. AWS/Azure have similar arrangements in China but you wouldn't say the Cloudfront users are getting MITMed by the CCP.

Yes, I havent done CDN work in a few years, but AFAIK that applies to all of the cloud "partners" in PRC as well. The customer needs to sign up with the PRC entity, provide ICP & local contacts, etc.

I would say that any MIIT approved infrastructure provider _is_ co-opted by the CCP. Its the entire point of requiring ICPs, tying the ICPs to network addresses/endpoints, and infra providers to be local entities; the MIIT gets their MITM equipment and RTBH routes directly in to the providers local DC.

Re: Thoughts on Cloudflare

#79
post #76
post #67

Earlier quoted context omitted.

I noticed this years ago while in China. I saw someone at a bar with a laptop out using my web site. I went and chatted him up, and I noticed a different TLS certificate, I don't recall if he moused over the lock icon or if his browser, or back then when browsers showed the issuer in the address bar. Freaked me out. Apparently it's JD Cloud now. Or maybe it was the, and I don't recall correctly. It was a Chinese comp…

Are you sure they weren't using a corporate machine with some sort of MITM proxy? That seems far more plausible than what you're suggesting. Moreover it's unclear why they'd even bother minting a new certificate for the China side, rather than copying the certificate like they do for all their other POPs.

Yeah, I'm sure it wasn't a corporate MITM. I turned off my VPN and saw the same on my own machine.

I guess Cloudflare isn't doing this any more by default.

They probably didn't share the other cert because they'd have to give the private keys to these Chinese partner.

Re: Thoughts on Cloudflare

#80

Earlier quoted context omitted.

“complying with local laws” isn’t always a good thing. Here’s some behaviours that you need to report in some countries in order to comply with local laws: * someone is a homosexual * someone had sex out of wedlock * someone is a communist * someone is right-wing * someone is a Muslim * someone is _not_ a Muslim * someone spoke ill of the current ruler * someone hosted a messaging service, and didn’t ask users for a…

In which countries do you have to report someone for any of that? Genuinely curious. Can't think of a single country where any of these criteria would be a reportable offense.

I can certainly think of a few where some of these things are illegal or forbidden enough to result in death if someone found out.
Post reply on HN