Earlier quoted context omitted.
Same here. .tk was the only one back then that allowed you to have your own domain name without subdomains. My memory is that: 1. freeserver.com/~userna 2. username.freeserver.com 3. username.fs.com 4. username.tk Then we grew up a bit and started paying domains :')
de.vu was popular in Germany for subdomains, I had a few of those. Also a .tk one later.
Cloudflare loses 22% of its domains in Freenom .tk shutdown
81–90 of 236 posts
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#82Earlier quoted context omitted.
> You can’t win with these people This is the classic fallacy of assuming that because you see comments of type A and comments of type B on the same forum that means they're the same people. They're usually not. A more accurate way to phrase this is "you can't win with ... people". Whatever you do will end up ticking off some subset of the population.
“These people” is presumably a set of people quick to find fault in anything a corporation does, which could be a superset of those two groups. Not sure what kind of fallacy that’s supposed to be.
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#83Earlier quoted context omitted.
The problem is that "free for kids" is also "free for scammers" and it's hard to square that circle.
Another way of looking at this is that scammers can probably afford to spend $5-10 on a TLD since it's just a cost of doing "business" to them, but many kids can't. I was very happy about free TLDs back in the day as a teenager, since I could just try things out before having to convince my parents to let me use their credit card to register a proper domain name.
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#84Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#85Another prominent .tk domain is for the Tcl programming language (tcl.tk) and I just checked, that is one of the paid .tk domains that are still up.
Why do orgs feel the need to use these whacky TLDs I’m still of the fence with rust using .rs in important places which is fundamentally in control of the Serbian government. You’re going to have to trust the Serbian government with signing .rs DNSSSEC at minimum and I don’t.
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#86Earlier quoted context omitted.
> That surprises me, given the time and effort they spend mitigating fraud and abuse What time? What mitigations? Cloudflare will proxy anything and then tell you "we're just a proxy, so we wont do anything lol" when you report anything other than cf pages. Doesn't matter if it's terror groups, animal torture, piracy, doxing, far right groups, etc. I have personally submitted abuse reports and seen that absolutely no…
> the amount of abuse I see from people using Cloudflare Warp is also very high. More so than from "traditional" VPNs (i.e. the ones claiming to keep "no logs and never selling your data")? That's quite surprising, since Cloudflare makes no such promises and markets Warp as a security/performance improvement tool, not an anonymity-providing one. I think at least for a while, Cloudflare-hosted sites would even bypass…
Yes, because it is a free service, an easy and free way to just hide your ip address. You don't even need an account.
> I think at least for a while, Cloudflare-hosted sites would even bypass it entirely and they'd get the real underlying client IP.
Correct, this used to be the case, but no longer is as far as I can tell. But even with that, it was an issue for non-Cloudflare websites and services that are being attacked that aren't HTTP(S) (e.g. SSH)
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#87Unrelated to the article but seeing .tk brings back many memories. As a kid without a bank account let's alone an international credit card (VISA/Mastercard), dot.tk is the only way to put a website online with your name. I created countless of websites with .tk for classmates, school and families.
In italy we had 3000.it https://web.archive.org/web/20010331143129/http://www.kliman... SPOILER: I didn’t become a webdesigner
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#88Unrelated to the article but seeing .tk brings back many memories. As a kid without a bank account let's alone an international credit card (VISA/Mastercard), dot.tk is the only way to put a website online with your name. I created countless of websites with .tk for classmates, school and families.
Same here. .tk was the only one back then that allowed you to have your own domain name without subdomains. My memory is that: 1. freeserver.com/~userna 2. username.freeserver.com 3. username.fs.com 4. username.tk Then we grew up a bit and started paying domains :')
Re: Cloudflare loses 22% of its domains in Freenom .tk shutdown
#89Thank god, .tk caused so many headaches for us, truly a cesspit of a tld. The rate of fraud and abuse on our platform was staggeringly high from it, it was close 99%.
It would follow that Cloudflare is tacitly admitting they have been / are hosting a large number of domains used for fraud and abuse. That surprises me, given the time and effort they spend mitigating fraud and abuse. Anyone care to explain what I'm missing?
Cloudflare will happily take money from and host (yes, host - they host, in spite of their rather stupid and completely disingenuous assertions that they don't) spammers and scammers. They do all the time, and they have no intention of changing that any time soon.
If you forward phishing spam to abuse@cloudflare.com, guess what? Nothing happens. You get an automated response, but they do nothing about it. They expect you to visit a web page that has all sorts of intentional problems (intentional because they've been pointed out to Cloudflare and Cloudflare hasn't addressed them for years) that make the process arduous and time consuming. For one, they don't have "spam" as an abuse type. For another, even though they now literally host web content, and even though they're a domain registrar, if you don't paste in a URL pointing to a site hosted by their proxying product, then you can't submit your form. This means there's literally no way to complain to Cloudflare about domains for which Cloudflare is in WHOIS and SOA records, and for whom Cloudflare hosts DNS. The fields are limited to some particular size (2,000 characters? I forget exactly), and have issues where if you paste more than a certain amount of content but less than the hard limit, you can't submit the form. If you try to use the form more than once a minute or two, IT'S RATE LIMITED and you can't submit the form. Imagine that - they need to protect themselves from human-speed abuse reporting.
In other words, it's REALLY hard to use their site to report abuse to them, and they know this, and it's intentional, unless we want to believe that they just suck at understanding how to make a web page that works.
If they get enough complaints about a given phishing domain, they eventually take action, but it'd be after several days, which is more than the lifetime of a typical phishing campaign. In essence Cloudflare is one of the most popular phishing and spam-promoted hosting platforms because of Cloudflare's intentional foot dragging and claims to want to "protect free speech".
They got on my shit list years ago when they told me - not kidding - that they couldn't just take down a Bank of America phishing site when it was pointed out to them because of "free speech". In other words, they don't want to set a precedent where they can apply the tiniest modicum of common sense and take down phishing sites which any reasonable human on the planet can unambiguously recognize as fraud.
Bottom line: Cloudflare tells the world that there's SO much bad stuff out there, and you'll get in trouble if you don't use their products, and that's mostly true if you want to run phishing and spam-promoted web sites, so scammers and spammers use Cloudflare and are protected from those of us who would report those spammers and scammers.
For all the companies and individuals who use Cloudflare, many are fooled in to thinking they need Cloudflare when they don't and are just making their sites problematic for much of the non-western world while helping a wanna-be monopoly re-centralize the Internet around a for-profit company that has a history of profiting from scammers and spammers.
If anyone thinks Cloudflare legitimately protects the Internet by mitigating fraud and abuse, I'd be very interested to see evidence that doesn't come from Cloudflare that shows this.