9 ms·
I ran the worlds largest DDoS-for-Hire empire and Cloudflare helped
- amq 4y agoI strongly believe abuse claims should be handled by the actual hosting providers behind CloudFlare.
- luckylion 4y ago... which are unknown because CloudFlare's service includes "hide your backend". If CloudFlare provided a way to find out the host of a website they run, and gave said host a way to find out what servers specifically are hosting it, they'd have a much better argument, because they'd make it easy for anyone to use the legal system to go after offenders. I don't know how easy it is for US citizens or law enforcement to get that information from CF, but from what I've heard, it's very, very hard to do so from Europe, and will basically only be used for major crimes, but not for a common "scam a granny" operation. CF is essentially providing cover for these.
- MichaelCollins 4y ago> If CloudFlare provided a way to find out the host of a website they run Surely they respond to subpoenas and warrants.
- luckylion 4y agoIf you're in the US, probably. If you're outside the US, from what I understand, they require you to file in the US (or have US law enforcement work on your behalf). For all intents and purposes, that means they don't for anyone outside the US, except for very high profile cases. For everything else, they're providing a legal shield.
- amq 4y agoCloudFlare forwards all abuse claims to the providers, so filling an abuse with CloudFlare is practically equal to filling it with the providers. The only difference is that you don't know who the providers are.
- luckylion 4y agoIt's not. They do forward it, but the provider can simply chose to ignore it, since it's not addressed to them and there's no legal implication - it's purely informational for them, letting them know that CF has received a complaint.
- breakingcups 4y agoCan I ask you. For all intents and purposes, what is the difference between Cloudflare and a regular host except an expiry time on the content they host? Cloudflare: - Makes a website available through their IP addresses - Resolves a site's DNS - Stores the content of the website on their servers, to serve to clients. The fact that there's an expiration on that content is of no consequence. The fact that the final source-of-truth lies offsite makes no difference. If I rent a regular, run of the mill server and have it proxy all requests to a different server, does that suddenly make the first host bulletproof to any and all scrutiny? Cloudflare likes to pretend they are a neutral entity, impartial, just like regular Internet Providers but they are decidedly not. They are being paid by their customers to store and serve their content from their servers and to perform traffic filtering.
- superchroma 4y ago
- robotmlg 4y agoHe was sentenced to 13 months in prison, followed by 3 years of probation, plus forfeiting $500k of proceeds https://www.justice.gov/opa/pr/former-operator-illegal-booter-services-sentenced-conspiracy-commit-computer-damage-and-abuse https://www.justice.gov/opa/pr/former-operator-illegal-boote...
- superchroma 4y agoOk then. Better to have lead with that if it's going to be a central topic in the article.
- alar44 4y agoWrite your own article then.
- defrost 4y agoIt's the second link in the article and part of the header abstract.
- superchroma 4y agoThe second link in the article is the Cloudflare blog post and I'm not seeing a header abstract on my device, just a title and text.
- defrost 4y agoThird link, (my bad) with the abstract | header | opening being that part above the first sub heading. Point being, it's there in the lead.
- BLKNSLVR 4y agoIt's a rare "inside" viewpoint, so it's really not a bad option for initiating the conversation. Let's also leave 'the law' to determining whether Rasbora should be paying fines. As well functioning, or otherwise, 'the law' is...
- bobsmooth 4y agoCan we just skip to the end where the internet breaks into fiefdoms? AOL almost did it in the 90s.
- everyone 4y agoIt already is imo, there's very different internets for different languages.
- judge2020 4y agoHow do we prevent DDOS without centralized services like these? There has to be something. It would be nice if these attacks were blocked before they even get to a transit provider, but cheap server / VPN providers seem unmotivated to try to solve the problem (since they barely lose any money when they facilitate the DDOS, and/or the attacking devices are rogue IoT devices and booting them would mean booting legitimate customers who don't know the first thing about auditing their network for compromised devices).
- dogecoinbase 4y agoWe dismantle the service providers that provide cover for the forums in which DDoS attacks are advertised and purchased, like Cloudflare themselves.
- BrainVirus 4y agoTransfer away from HTTP and DNS. Use something like global NATS clusters for content delivery. Make sure there are many providers. Problem is, this is not what Big Tech actually wants.
- Grimburger 4y agoPay per packet. I remember maidsafe was working on this for many years without much success. Then they got into crypto for micropayments a decade later and it all got a bit messy. Not sure how the project is doing these days but it was a solid concept at heart. https://maidsafe.net/ https://maidsafe.net/ > legitimate customers who don't know the first thing about auditing their network for compromised devices An IoT device not suddenly working is a good signal to endusers that it is compromised and being used illegally.
- msh 4y agoSo you want to put everyone on a metered internet connection? And then hit them with massive bills if they have a device that gets hacked? Seems unreasonable given the current state of security.
- 4y ago
- everyone 4y agoI don't think the author's argument makes sense. Cloudflare's position is that they are neutral and will provide their services to anyone and everyone. They do not make those value judgements deciding who deserves their services or not. The fact that they thus provide their service to booters isn't a flaw in Cloudflare's argument, in fact it's consistent with their position. The author is implying that Cloudflare should independantly make that value judgement against a booter, rescind their services from the booter, thus allowing other booters to take that booter down? That's ridiculous. All the booters should be dealt with by some legal authority. EDIT: So according to some comments cloudflare sometimes does decide independantly to rescind their services from some users? That would make them inconsistent in that case. The authors argument, that the solution to booting is more booting, still doesnt make sense tho imo. It's like the solution to too many guns is more guns.
- ALittleLight 4y agoCloudflare is neutral... Unless you are 8chan, Stormfront, or KiwiFarms. It's an odd definition of neutrality that allows one to take decisive values positions.
- oivey 4y agoCloudflare’s line seems to be where bodily harm comes into play (e.g. Kiwifarms people enabling SWATing via doxxing, stalking by mobs, etc) which is above and beyond just normal criminal activity. The situations really are not very similar.
- tjpnz 4y agoAnd yet they continue to work with innumerable other services causing bodily harm. This was all about countering the negative publicity.
- deleted 4y ago[deleted]
- 4y ago
- politician 4y agoCloudflare is oddly political for an infrastructure provider. Every few months or so they seem to be forced to explain why they have decided to deplatform this or that website contrary to their no interference policy. You don’t see AWS or Microsoft having the same frequency of these sorts of reports. What am I missing?
- GeneralMayhem 4y agoYou're missing that nobody makes a fuss about AWS removing things. Unsavory and/or illegal sites are removed from AWS every day for TOS violations - a somewhat recent and notable example was Parler, the extreme-right-wing Twitter clone that was used to plan the January 6th insurrection.
- stsffap 4y agoSorry to hijack this discussion thread. I've come across your comments on https://news.ycombinator.com/item?id=28425379 https://news.ycombinator.com/item?id=28425379 and I think you have brought up some really good points what modern DBs should support. Especially, the queue support for atomic state changes and message sending can be a powerful primitive. I am currently looking into this area and would love to have a chat with you if you like. You can reach me via my twitter @stsffap.
- superchroma 4y agoI recall some anger when Microsoft closed some GitHub repos. I think the diversification of these companies helps silo the scale of scandals.
- meowface 4y agoIt's the exact opposite. They try to be, and I believe are, the least political out of all networking infrastructure companies, so in the very rare cases where they do decide to deplatform (Daily Stormer, 8chan, and Kiwi Farms are the only three) it always makes huge press. AWS or Azure doing the same wouldn't make news because they would immediately drop a site like Kiwi Farms, and anything like it, after the first report or two. If you're routinely kicking people out, people don't scrutinize you when you do it. To bastardize Stalin's quote: three deplatformings is a tragedy, thousands is a statistic.
- judge2020 4y ago> they are actively lighting these fires and making money by putting them out! A bit of an odd take - it's like the fire department putting out the fire at the known arsonist-for-hire's house, and the police chief happens to run the fire department while doing nothing about the suspiciously wealthy arsonist. The difference is that Cloudflare isn't an actual public service and has no obligation to DDOS protect anyone.
- rtpg 4y agoA simpler example: AWS hosts fakeLVbags.com. This site sells counterfeit luxury handbags, and says so clearly on the site. Now AWS does not realize this as they are large and have lots of operations. However, one day a journalist asks Amazon directly about this website, and there is an official press release by Amazon made about it. AWS has had this illegal activity brought to their attention, as well as the fact that they are facilitating this activity. They openly acknowledge the site existing. Legally this is very different from not knowing about what is going on! Not only does Amazon in this hypothetical know, they have admitted publicly that they know! So… now to Cloudflare. Did Cloudflare, experts in this domain, not know about these DDOS vendors? And did not realize they were offering protection to those? Maybe not! But maybe. And knowing makes things a lot worse for them. Especially if Cloudflare connected the dots internally about the usage for illegal activity. But! CF simply might not have known, or had a complete picture. Or anything in between.
- xfer 4y agoA DDoS Protection company doesn't know what the state of the market is? Really? Feigning ignorance on this matter is not very honest. Your aws story is completely irrelevant since AWS doesn't sell counterfeit luxury handbag insurance. Would you argue amazon webstore doesn't know about fake products in their marketplace?
- rtpg 4y agoto be clear I'm not trying to defend Cloudflare. The sort of generous interpretation is that even if CF understands this at a high level that doesn't necessarily lead to them knowing where these services are and which companies they are hosting that have this (though ... honestly, for B2B services like CF it feels pretty reasonable to at least do the vaguest sanity check)
- renewiltord 4y agoWhat a nonsense storm in a teacup.
- mlyle 4y agoIt's not complete crap: Cloudflare facilitates the operation of "load testing" (DDoS) services by overwhelmingly providing the front end. Cloudflare claims to not care about content and provides security services to all, but perhaps Cloudflare is incentivized to do this by the fact that they make money on the DDoS they facilitate. Cloudflare isn't a protection racket, but doesn't have completely clean hands, either.
- oivey 4y agoThis article seems to have been posted to make a false equivalence with the current Kiwifarms situation. There’s a pretty clear difference in urgency between taking down DDOSers and deplatforming a forum that is a gathering point for a mob engaging in mass harassment, stalking, and SWATing. One is a nonviolent crime. The other is a crime targeting an individual that had already escalated to the point of a high risk of violence, with no sign of slowing down.
- hn2017 4y agoPrecisely, once human lives are in extreme danger, it's a different situation
- sourthyme 4y agoDDOSs can have more impact than you think. Such as taking down hospitals and the war in Ukraine. Not really sure which one can be worse though... https://www.radware.com/security/ddos-experts-insider/ert-case-studies/boston-childrens-hospital-ddos-mitigation-case-study/ https://www.radware.com/security/ddos-experts-insider/ert-ca...
- ThrowawayTestr 4y agoDDOSing is illegal, any illegal content on KF is quickly removed.
- dapids 4y ago
- mccorrinall 4y agoCloudflare still protects all those forums which harm people. Kiwifarms is the only one which was sensationized by the twitter crowd. Look at crime.to. They still send bomb threats [1], exchange stolen credit card data [2], harass people to the point where they lose their houses [3] (SWATing, breaking in into their house and much more included), and probably more on a daily basis. Still protected by cloudflare. Pretty hypocritical if you ask me. [1] https://archive.ph/mOBGB https://archive.ph/mOBGB [2] just browse the forum [3] https://www.merkur.de/bayern/nuernberg/drachenlord-youtube-winkler-obdachlos-hater-leid-rainer-tiktok-onlyfans-emskirchen-91760296.html https://www.merkur.de/bayern/nuernberg/drachenlord-youtube-w...
- roenxi 4y agoThis article is not very articulate on the point, but goes to the real touchy point with the Kiwifarms decision. Based on what I know it seems Cloudflare made a good decision, but: 1. The internet is vast. 2. Figuring out what someone is doing on the internet even if you did somehow have full transparency over the data they send/receive is hard. 3. Any policy of intervention is going to leave behind a stream of poorly prioritised actions that are highly questionable. 4. Just because we see something doesn't mean it is there. It is usual for the first impressions to be wrong. Often even after researching an issue thoroughly. I don't think there is a free speech issue here, but I do question whether Cloudflare has the motivation or capability to actually execute a policy of policing the internet fairly. All the pressure is going to be to police the internet for specific political goals.
- 8note 4y agoIt's a great argument against the scale that cloudformation has, and regulation would help. If you can't figure out that one of your clients is doing this bad things, you shouldn't have so many clients
- robryk 4y ago> It's a great argument against the scale that cloudformation has, and regulation would help. Agreed. It's very annoying that such services like ddos protection have an ever-growing scaling advantage (because the sizes of ddos attacks grow). > If you can't figure out that one of your clients is doing this bad things, you shouldn't have so many clients What kinds of entities would you extend this to? I would guess you wouldn't day the same thing about hardware stores (which sell dangerous tools).
- staticassertion 4y ago(2) doesn't seem important. This problem is easy - take down kiwifarms. No one is asking for Cloudflare to take down 100% of every single site that may or may not be classified as "bad" - they're asking for this one site to be taken down. Maybe even some others, too. There's a huge grey area of "bad", but there are also plenty of sites that very clearly fall to one side or the other. Solving "grey" is hard, solving kiwifarms is not.
- Barrin92 4y agoWhat's at the heart of the entire Cloudflare situation is this discussion around the platform's alleged neutrality. I do not understand this at all. If I run a business, and I see that unambiguously bad actors namely abusers, criminals, stalkers, harassers or whatever use my services to facilitate their actions I have a very clear ethical obligation to step in. I don't go "well the law isn't here, it's not my problem". Making money of unsavory individuals, metaphorically selling both shields and guns at the same time is unethical. Dodging that responsibility is moral cowardice. The law isn't in every place, it's slow as hell and dysfunctional anyhow in some jurisdictions in particular but that's no excuse for inaction when it is within ones power to prevent harm. It should be that simple.
- SpicyLemonZest 4y agoIt really depends on the business you run. If you run the local electric company, and you read in the paper that some guy in your service area has been doing terrible things, do you turn off his power? Cloudflare sees their anti-DDoS services as a similar infrastructure-level service, and while you might not agree with that (I'm not sure I do either), it's not immediately unreasonable.
- luckylion 4y agoIs CF a utility in that way? I think you can argue that their DDOS-mitigation might be. But that comes with the additional benefit of hiding the origin. This resembles a post-forwarder service or a bank that knows the customer's real identity, but provides a way for them to conduct business without exposing it. Is there a good-faith argument that this service is a public utility and should be provided even if the customer is using it for criminal activity? If someone used FedEx to run a fake pharmacy and deliver fake medication to people while staying out of reach for law enforcement and regulators by using a FedEx-provided return address, would you say that FedEx should enforce their T&C and shut that customer down?
- SpicyLemonZest 4y agoIn that hypothetical I'd grant that the answer is clearly yes, but it's not obvious to me how DDOS mitigation would help a company stay out of reach of law enforcement or regulators, unless Cloudflare is refusing to comply with subpoenas for customer information.
- barbarbar 4y agoYou should not drag others into your criminal actions. You decided to do it on your own and for your own benefit. You did it and must now live with it. But done blame others and drag them in and say they "helped". This is on you alone.
- longrod 4y agoI think this is becoming increasingly common for Cloudflar e which sets a bad precedent. They can scream however much they want that they don't want to make these decisions nor do they like to be put on the spot but it doesn't save them from the backlash of being a "curator of the internet". Moderators get the worst backlash everywhere in the world. The only difference is that Cloudflare continues to refuse the fact that they have quite a lot of power over whose traffic they let through. When you, basically, govern 20% of internet traffic you must take the responsibility for it as well. This article is a nonsensical shout in the air. Cloudflare, like Google, is not looking over every single request that goes through them. They take these actions after enough noise is raised to highlight the issue. The problem is that Cloudflare will become prone to bullying. What I mean is that if I have a good number of fanatic followers, I can raise noise against a rival platform and get Cloudflare to, at least, scrutinize it and, at worst, deplatform it. Cloudflare will need to set in place some policies to protect themselves from this. If Cloudflare does this kind of thing enough times, they will unintentionally become a policing force. That's really not a good place to be in for a business.
- fareesh 4y agoPolitical neutrality is important for the tech industry. I appreciate Cloudflare trying its best to be neutral. When harm is done, the fault lies at the feet of the perpetrator. Blaming their utility company, hosting provider, DNS registrar, grocer, butcher, barber, etc. is lunacy.
- 8note 4y agoIn the US at least, the getaway driver is to blame even if all they did was drive a car and receive payment for their driving
- yardstick 4y agoSure, but what about the company that they rented the car from? Or the company they bought car insurance from? In the eyes of the law, the intent of the person is often (not always) extremely relevant.
- zimpenfish 4y ago> Sure, but what about the company that they rented the car from? Or the company they bought car insurance from? I expect if they said "I want to rent a car to use as a getaway vehicle for a bank robbery" whilst standing next to a TV showing a picture of them committing a bank robbery, yes, the rental company would have some culpability.
- yardstick 4y agoDid cloudfares customer tell them they wanted their services for DDOS?
- mike_d 4y agoBy the nature of how Cloudflare works, you have to provide them with your domain name and the content of your website. See if you could come up with a simple regular expression to deny services to these well known DDoS providers that are actively using Cloudflare: CryptoStresser.com Instant-Stresser.com FreeStresser.so StresserAI.com Booter.sx Flystress.net Bootyou.net
- tcmb 4y agoMaybe a better analogy is an energy provider: You don't expect them to turn off somebody's power because they are listening to the wrong kind of music. Energy companies are publicly traded companies as well, I don't see what difference this fact makes in the analogy and the argument. Policing is the police's job, not that of infrastructure and utility companies, precicely because that would bring a lot of hairy questions that the author raises as well.
- zimpenfish 4y ago> You don't expect them to turn off somebody's power because they are listening to the wrong kind of music. But you would expect them to turn off somebody's power if they were, e.g., using that power for a marijuana farm or torturing kittens with electrical shocks and standing outside their house shouting "I'M USING THIS ELECTRICITY FOR CRIMINAL MEANS, YOU KNOW".
- Beltalowda 4y agoI would expect the police to step in if the power was used for a marijuana farm (assuming it's illegal in your jurisdiction of course, skipping the discussion whether it should be illegal). A corporation deciding to cut off my power without due process because they think there may be a marijuana farm – which may or may not be true – does not sound like something that's desirable. Either way, I don't think analogies like this are very helpful, because the situations are too different, and the analogy doesn't really help clarify anything IMO.
- BrainVirus 4y agoExactly as expected. The more websites CloudFlare bans, the more its reputation will sink, the more enraged and demanding the pro-censorship mob will become. I note this one more time: almost no posts talking in favor of banning stuff here specify any objective limiting principle of where it should stop. It's like an exercise of deliberately creating a slippery slope.
- Ygg2 4y agoBut Brain virus, the slippery slope isn't real. It's a fallacy /s
- dmatech 4y agoTwitter seems to be the social lubricant that makes all slopes it touches slippery. It massively accelerates social change and was basically the only place the KF story ever gained any traction at all. It's hard to overstate just how powerful that site is in the USA.
- danShumway 4y agoThe slippery slope is banning DDoS-for-hire sites? This is like complaining, "if Apple removes hate speech from its app store, then next people will ask it to remove malware."
- EdwardDiego 4y agoSo he ran a DDoS network that wasn't behind Cloudflare, but used Cloudflare to stop his website being DDoSed by competitors, and this means Cloudflare was helping him DDoS others? No, it means Cloudflare was helping keep his website up, in a neutral manner. In other words, exactly what Cloudflare have stated their policy is. Now if Cloudflare allowed him to run DDoS code on its Workers, then yes, that's Cloudflare helping him. Very false equivalence.
- Borgz 4y agoThese defenses of Cloudflare's behavior are getting very silly. Is there anything that Cloudflare could protect that you wouldn't be OK with? Because a DDoS-for-hire service is illegal, unethical, and contradictory of Cloudflare's stance that "cyberattacks, in any form, should be relegated to the dustbin of history."[1] Most importantly, it should be obvious to anyone that a company that has a purported goal of protecting its customers from some harm should not also be attempting to facilitate that same harm. [1] https://blog.cloudflare.com/cloudflares-abuse-policies-and-approach/ https://blog.cloudflare.com/cloudflares-abuse-policies-and-a...
- EdwardDiego 4y agoI don't really give two hoots about Cloudflare, I just don't like false statements, like when "Cloudflare helped me run a DDoS network" actually means "Cloudflare kept my website from being DDoSed", with the addendum "and I'm bad, therefore, not protecting KiwiFarms is hypocritical." It's just dumb.
- Borgz 4y agoYou have admitted in your earlier comment that "Cloudflare was helping keep his website up." You are saying that "Cloudflare helped keep his website up" does not logically imply "Cloudflare helped me run a DDoS network". Even if you genuinely believe that, how are you confident enough that people generally share your interpretation of what constitutes help to call the statement in question "false"?
- e63f67dd-065b 4y agoIsn’t DDOS pretty illegal? In my opinion, selling illegal services is a strong case for CF to kick them out because they quite clearly break the law.
- lionkor 4y agoThe issue that arises with "thats illegal, CF should ban them", is that they need to pick some jurisdiction, and become an executing power in that. A lot of wacky things are illegal in some less free countries - if a website clearly breaks a saudi arabian law they care about a lot, does that count? What about a german law that is very important to germans? Does CF have to be an executive force in keeping the law of the US regarding non-US customers, or should the laws of the country the customer is in count instead, ... You see the issue. The solution is that CF should remain as neutral as they can without breaking the law in their country themselves.
- Aeolun 4y agoWhat a weird argument. Cloudflare is like a fire department that still fights fires in the homes of known pyromaniacs. Whether or not they set the fires themselves is irrelevant to the job of the fire department, if someone needs to stop them it’s the police.
- deleted 4y ago[deleted]
- quickthrower2 4y agoNot pyromaniacs necessarily but definitely “firestarter for hire”. Also a fire department that can scale and is paid privately. More fires mean more business.
- Aeolun 4y agoMore fires mean more business, but that’s kinda irrellevant to the goal of the fire department, which is to prevent burned out houses. If the police never does anything about the firestarters for hire, it’s a bit hard to see how that would be the fire departments fault (and certaily not something they should solve by not fighting fires any more).
- 7952 4y agoOr they are like an insurance provider that doesn't consider the risk of a particular client. That is good for growth but not ideal in the long term.
- zaptheimpaler 4y agoThe deplatforming logic is practical but pretty shaky as a long term strategy. Kiwifarms absolutely may have been a despicable place causing real harm to people. In that case, the police should initiate a request to take them down that Cloudflare or ISPs etc. are obligated to follow. The problem is the government is completely ineffective and regularly offloads their responsibility to platforms like Facebook, Cloudflare etc. A private company should not be making decisions on essentially freedom of speech. Its just one more responsibility that law enforcement has completely shirked leaving others to clean up the mess.
- deleted 4y ago[deleted]
- shadowfox 4y ago> A private company should not be making decisions on essentially freedom of speech On the other hand, a private company has limited obligation to uphold what is essentially a government concern ... Unless we start redefining a lot of things related to private obligation.
- blfr 4y agoThis particular private company wants to get out of being forced into a role of content moderator for a fifth of the Internet. This is an infinite time sink with no good outcomes for them. More importantly, this seems to have no good outcomes for us, the viewers. I also don't want Twitter mobs and DDoS-ers to have a say in what I can and can't read.
- daptaq 4y ago> I also don't want Twitter mobs and DDoS-ers to have a say in what I can and can't read. This is honestly what I find the most disturbing about the entire story. This "keffals" person -- an individual! -- managed to organise enough attention to make all of this happen. From what I understand the argument is based on a threat towards this person, but considering the (public) information they were gathering on them (From what I recall it was stuff like flirting with underaged people, selling HRT drugs via Discord, old sexist tweets, etc.) I don't see why it was not in their interest to pseudo-anonymously have these threats posted themselves. Of course it could just be that some user was stupid enough to post these threats themselves, but I believe the fact remains that "keffals" had more to gain from threats against themselves, since most of what was being posted was perhaps vulgar and certainly impolite, but practically harmless -- more embarrassing for those being "investigated". Just some people with too much time on their hands. The site is probably going to be resurrected some way, soon enough. I believe hearing that they were considering an onion site. When this happens, I'd be interested to see the post histories of those issuing threats. But of course, since this is a private entity, they have no obligation to look at any evidence that would run contrary to the accusations. Of course this is their right, when considered in isolation, but CloudFlare has become a disproportionately significant player that thinking of them as just another company is rather difficult. In the end this all speaks for the fact that the internet was never intended to work on the scale it does. It is almost a miracle that it appears to do so most of the time ^^.
- ftyhbhyjnjk 4y agoAah.... an attempt to give more de-platforming powers to more private companies...
- ethotool 4y agoEveryone wants to bully and pick on Cloudflare now because it’s the cool thing to do I guess. The issue is not Cloudflare — it’s just the sad reality of the Internet in 2022. Imagine a criminal pumps a full tank of gas into his vehicle and then uses that vehicle to commit crimes. Nobody goes out and blames the gas station or holds them accountable. The owner of the vehicle should and would be held accountable in real life. And in any case related to the Internet or Cloudflare, the owner of the website should be held accountable.
- luckylion 4y ago> Nobody goes out and blames the gas station or holds them accountable. If the gas station operator knows the criminal's identity and hides it, I'm pretty sure everyone would go after the gas station. DDOS-protection is one of Cloudflare's services. The other one is hiding where you host your stuff, so people cannot contact your host to have them shut down the illegal operation.
- nostromo 4y agoIf SWATing is the weapon of choice for harassment mobs, then fix that first. Note that this particular SWATing wasn't in the US, it was in Canada -- so it's not necessarily even a uniquely American problem.
- MichaelCollins 4y ago> If SWATing is the weapon of choice for harassment mobs, then fix that first. How do you counter this weapon? Obviously you have to break the kill chain, but which part? 1. A target is geolocated; this is impossible to prevent if the target shares this information about themself freely. 2. The attacker makes a phone-call to emergency services, likely but not necessarily using a method they believe will anonymize them. Is it technologically feasible to close anonymity holes in the phone system? Should 911 calls from anonymous numbers be null-routed? 3. The attacker needs to persuade the emergency operator that an armed police response is necessary. This is theoretically possible in any country that believes armed police responses are sometimes needed, even those in which police normally patrol without weapons. 4. The armed police response will probably fail to kill the target. This seems to be the weakest part of the kill chain, where most murder-by-swatting attempts fail. Training police for this scenario could reduce the risk even more, but the possibility of an accident will always be non-zero if you have armed police responding to what might be some sort of murder in progress. I think SWATings would probably continue to happen even if you completely resolved that third or fourth stages, eliminating the possibility of an accident completely. The anonymous troll probably still gets his rocks off at waking up the victim in the middle of the night by unarmed conflict resolution social workers banging on his door looking to resolve the [probable] misunderstanding. Breaking the kill chain at the second stage seems more promising for this reason, but I am not sure eliminating anonymous 911 calls is practical or ethical.
- NotPetya 4y agoOne of the laziest articles I've read recently. I was looking for a gotcha, some concrete evidence Cloudflare actually helps booters to boost their own sales, and the closest he comes is saying DDoS sellers host their websites behind Cloudflare. It feels like this was written to take advantage of the moment and tie the Kiwifarms to actual online criminal activity.
- nikanj 4y agoWe simultaneusly act annoyed that Visa/Mastercard act as gatekeepers, and demand Cloudflare should become the new moral police
- MichaelCollins 4y agoMy side getting our way is good. Their side getting their way is bad. It seems rational for any partisan to think this way, no? People standing on opposite sides of the battlefield, shooting at each other with the same sort of weapons, both believing in the goodness of their cause.
- deleted 4y ago[deleted]
- SergeAx 4y ago> That is the equivalent argument in the physical world that the fire department shouldn't respond to fires in the homes of people who do not possess sufficient moral character So, to continue the analogy, we are reading the post by (ex-)arsonist?
- dcow 4y agoThe linked post by Prince is pretty frustrating. “This is not our stance, but we do it anyway for all the reasons we just said are bullshit.” I have a ton of respect for Prince but this spineless double standards stuff is BS. PS: I have no idea what the deal is with Kiwifarms and frankly I don’t care. If it’s really that bad then we need to have a judge order an injunction.
- SyzygistSix 4y agoI thought it was pretty clear that they basically said "Things went from 'freedom of expression we don't like that we find questionable' to things that are almost certainly illegal, so we are forced to move, even though we would prefer law enforcement did it."
- dcow 4y agoI would expect a lot more detail from Cloudflare like a list of alleged crimes and some supporting facts. Maybe even an injunction from a judge, perhaps? You know, the stuff you would normally expect in a case like this before law enforcement decided to intervene. Honestly anything supporting the “there was an emergency and deplatforming kiwifarms just avoided it” claim would help. They weren’t forced to do anything.
- joecool1029 4y agoHN and Matthew Prince really struggling with these two things: 1. A company can arbitrarily do whatever it wants within the confines of the law. Additionally a company's chief executive and/or leadership team can do whatever it wants so long is it is not in breach of their bylaws and/or they have the support of the board. 2. A company which is publicly traded is beholden to public perception if it affects current and future shareholders views on share price and health of the company. If shareholders believe being associated with potentially illegal activity means Cloudflare could be open to lawsuits, then leadership kicks off that activity. Leadership can't give an honest answer on this because it would admit they were worried about being complicit in illegal activity. This is why you see the response of 'we don't believe this is our responsibility, we're just a neutral entity' PR spin. To return to OP's post, Cloudflare directly benefits by letting DDoS-for-hire operators use their service. They've been informed of this, this post is one of many on the topic. If you go a few comments back in my comment history you'll note I mentioned Cloudflare also pulled down sex worker sites in the fallout from SESTA being enacted. Why didn't they make the same argument then? Unlike SESTA at the time the caselaw on CFAA supports that DDoS-for-hire is illegal activity, going back a little over 10 years with plenty of prosecutions. The US prosecutor handbook on it was updated around 2010 to add it https://www.justice.gov/criminal/file/442156/download https://www.justice.gov/criminal/file/442156/download, the last time I remember anyone trying to claim it was legitimate protest was back in 2013 when some Anonymous indictments were handed out. Cloudflare also responds to DMCA takedowns even though they don't host the content, why would they do that if there's no liability? Lets break it down a little more then: If my business is damaged because my website gets DDoS'd by a protected service Cloudflare knows will make me require the purchase of a service like theirs, why wouldn't I name them as a conspirator in a legal complaint?
- deleted 4y ago[deleted]
- lionkor 4y agoI feel that, if cloudfare wants to be neutral, they should simply do that. In my eyes, as long as they dont break any laws themselves, they are okay.
- lovasoa 4y agoIt's incredible that cloudflare compares itself to a firefighter answering all calls wherever they come from. They are more like a private security company working for a mafia boss that pays them well.
- BeFlatXIII 4y agoThe fact that DDoS protection is a viable market and losing it is tantamount of kicking a website offline belies fundamental flaws with the infrastructure of the internet.
- 28304283409234 4y ago> However CloudFlare is not a neutral utility, they are a publicly traded company and have shareholders to report to, can any fire department in the world say the same? Publicly traded? No, but fire depts in the US were commercial entities paid for by insurance companies. Arguably just as bad. You had to be a paying member if you wanted them to put out the fire burning your house down. Well documented that fire depts would stand idly by and do nothing for the neighbours. But yeah, that's what you get with Cloudflare's shitty analogy.
- timwaagh 4y agoThe author mentions he doesn't want us to judge him on his past. But I don't think teenagers are that different from adults so I doubt there is any real basis for that. He'd probably still do it if that was the best way to make money. If he had not written that, I probably wouldn't have given it any second thought though. It's a good article just don't tell people what not to think they might just start to think what you didn't want them to. I strongly agree with the points made. What Cloudflare is doing is terrible. They should remove this protection and publish an apology to the victims before a court decides to think the same.
- fffehdya 4y ago
- fffehdya 4y ago
- fffehdya 4y ago
- fffehdya 4y ago
- mildmotive 4y ago> As the infrastructure provider for over 20% of all www traffic traversing the internet today, CloudFlare is in a position to enforce it's beliefs on a global scale. > Who interprets what qualifies as hate speech? Exactly the issue. We should not give “activists” a free pass on this one. I wonder now which one(s) of them will commit the crime of actually DDoSing KiwiFarms. We probably will never know. Vigilante “justice” is problematic because it leaves room for people to harm others without proper evidences of wrong doing. Mind you, I’m no way denying that Kiwifarms are reprehensible, but there are people out there claiming that KF is literally causing people to die, which I’m wondering where is the evidence of that? If someone is suicidal, one of the better ways to help them is to (among other things of course) make them understand that they have power over their circumstances by telling them that they are responsible for their actions. Claiming that some internet bullies can cause you to kill yourself is not helpful, nor is it true.
- pfisherman 4y ago> Vigilante “justice” is problematic because it leaves room for people to harm others without proper evidences of wrong doing. Isn’t this exactly what the people are KF were doing? Only instead of trying to get a website kicked off the internet, they were trying to get people fired from their jobs, weaponizing the police, trying to drive people to suicide. And not in the service of any sort of justice, but for entertainment. That is sick and it is evil. They should absolutely be shunned and ostracized for their antisocial behavior. Free speech means that other people have the right to show you the door if you are acting like a jerk.
- reisse 4y agoAs far as I understand, protecting from DDoS attacks is a big enough part of Cloudflare business. Doesn't it create the conflict of interest here? I can imagine how it makes sense for Cloudflare to facilitate DDoS attacks by sheer ignorance with plausible deniability, to sell more DDoS protection to the targets. Using their own analogy, the real fire departments actively prevent fires by enforcing safety policies, not merely fighting existing ones. If fire department is paid only for the fires extinguished, they are strongly disincentivised to enforce safety policies.
- stevespang 4y ago
- prvit 4y agoIf the numbers from DoJ are to be believed, this was far from the largest DDoS-for-Hire operation by revenue.
- Justsignedup 4y agoJUST ONE SINGLE NOTE: Cloudflare is a private company responsible for a product that they sell which they can choose not to sell to someone as is any company's rights. The Fire department is a public sector entity, funded by our taxes, and we don't have any choice in which fire department we choose. Anyone can come up with a cloudflare competitor for nazi materials, they have all the ability, money, and ability to build out data centers. All they need to do is to find people willing to build/fund it all. And it turns out those leading the charge don't know how to run a good business, and don't want to put money in, and can't find talent willing to work for them.
- afrcnc 4y agoThere already is one in Russia called DDoS Guard. They're collecting all the nazi sites under their umbrella lately
- Justsignedup 4y agoAnd there you go, and if DDoS Guard is not sufficient for your traffic in say... the United States... Well you can certainly pay DDoS Guard a couple of hundred million to expand into the united states. I'm sure your lord and savior will happily foot that bill (/s).
- BeFlatXIII 4y agoHow is that not an indictment of basic internet infrastructure such that basic freedom of association has tradeoffs with needing to pay protection money to anti-DDoS companies in order to stay online?
- unixbane 4y agoAm I missing something or does everyone here unironically believe that Cloudflare should be punished for kicking a customer off? Because your comment has absolutely zero relevance to the point made by the article.
- 4y ago
- nindalf 4y agoOne thing I don't see covered here - cost. Specifically, the cost of providing DDoS protection vs the cost of processing every complaint and evaluating if the complaint is legitimate. At Cloudflare's scale, providing service to one additional site costs exactly $0. It's actually beneficial because it spreads their fixed costs (hardware, staff) over more customers. Great (for Cloudflare and the site). But that only works if they don't have to do any marginal work for each site. Actually investigating each new website, going through potentially each page on the website, making a judgement call on if there is sufficient moderation to allow it or they shouldn't - it could take several hours or days of a skilled worker for each website. Just putting an example out there - how long would it take you to evaluate if reddit.com adheres to all the terms in Cloudflare's TOS? There's a different standard for user generated content, but it gets a pass if there's a good faith attempt to moderate the site. This stuff is actually hard. If they actually had to process every complaint, regardless of where it came from, the economics of their business might not make sense. And of course, they open themselves up to false positives. They might ban a forum that looks dodgy but ends up being a leukaemia support group, which spawns yet another #dropCloudflare. And lastly, if they're going to listen to outrage from Twitter, they don't have a leg to stand on if they receive lawful requests from sovereign governments in Turkey, Saudi Arabia etc. They hoped to sidestep all of these issues - money, false positives and state sponsored takedown requests by saying "we don't take down anyone for any reason". Well, it didn't work out.
- unixbane 4y agoWhat a stupid fucking article, including "I grew up with cloudflare, therefore know nothing about how the internet works", and "cloudflare is a racket because I said so and give the benefit of doubt to myself". Web hosters never cared about what content they host. It was previously the norm to not even check for child porn and wait for law enforcement to make any decisions, and rightly so, as it's, literally, not their concern. Some web hosters did care about their content, but there were few and you could quickly move to another. Cloudflare are one of the new generation of webshit services, run by little babies, enamored by their big userbase (yeah, I had a big userbase when I was 12 and quickly got over that phase), and feel some sort of moral but mainly pretentious need to save the world, often by limiting who uses their service, or implementing some sort of snake oil. New conspiracy theory: all these drama about absolutely irrelevant websites like 8chan[1] and kiwifarms are to distract from the fact that cloudflare has killed anonymity on the internet. Since 2011 or so, browsing any website behind cloudflare over Tor or pretty much shared IP address got you essentially blocked. You would have to fill out a captcha to even see the front page, and not just any captcha, but the worst one which almost never works when on a shared connection: recaptcha. THEN you had to open up the cdn.myshitwebsite.com and repeat the same bullshit, and then you can see images, css, scripts, whatever on the site. ONLY in 2018 they fixed this (it was always possible to bypass it by changing your user agent to a specific string and such things, but almost nobody knew about this), and then broke it again, I'm not sure what the current state is. Then around 2020, a bunch of cloudflare imitators popped up, which includes having the pointless captcha at the front of pages. Cloudflare literally killed Tor, it was solely their fault. 1. "But oh no, a jihad thing was posted on it", same with facebook but 1000x worse
- deltasepsilon 4y agoTechnically, by way of the analogy provided in the article, Cloudflare is simply putting out fires at all houses, even those that are known to start fires. Their moral game is that it's not their responsibility to act on this knowledge, unless, it seems, there is some clear and present imminent danger, which is something for them to determine. This community, by which I mean HN, likes to have its cake and eat it too. Perhaps they're not all the same people, but HN also gets upset that VISA polices what businesses are deserving of accepting credit card payments. Regardless of which side you fall on, consistent and clear messaging is important. In that way, Cloudflare deserves some respect for attempting this, when every other corporation, be it VISA, or the FAANGs, simply do whatever is expedient to avoid negative attention, be it PR-wise, stock market wise, or regulatory wise.