7 ms·
A quick search shows exactly what he means. No elaboration necessary. http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.webhostingtalk.com/show
by nothxbro 12y ago
A quick search shows exactly what he means. No elaboration necessary.
http://www.webhostingtalk.com/showthread.php?t=1235995 http://www.webhostingtalk.com/showthread.php?t=1235995
http://www.organicweb.com.au/17240/internet/cloudflare-security-review/ http://www.organicweb.com.au/17240/internet/cloudflare-secur...
http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gbps-ddos-attacks/ http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...
- jlogsdon 12y agoThanks, what I searched for didn't really bring anything up.
- lucb1e 12y agoIn all 3 links this is the only relevant part I've been able to find regarding them being malicious: > Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good! So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a village and then have them perform criminal activity on each other. The link to Kreb's is basically the same: people protecting themselves. Should CloudFlare play for judge and ban people that do not violate their terms? Because I'm sure they boot people that perform illegal activities on their network or otherwise harm their network from within, but I can see why they don't proactively take down any website mentioning "we offer DDoS attacks". Like I said before, that person A kills another person doesn't mean that another person may kill person A, at least not within our current laws. Even if it did, is CloudFlare the one who should be calling the shots? Finally your first link is someone complaining to CloudFlare about LOIC (or related perl scripts launched from VPSes) and cloudflare responds that they see no harmful traffic and that logs or other details should be attached. Merely saying "hey I'm having trouble" has never gotten anyone further in resolving issues. That's why we have logs so that CloudFlare can check their own logs to see what happened. Perfectly reasonable. So yeah elaboration is necessary. I do not see why CloudFlare is harmful.
- akerl_ 12y agoThe point being made above is that Cloudflare charges users to protect them from attacks, but they're also providing protection (from attacks and identification) to the people performing the attacks. To many, it appears that they're helping to allow malicious activity because it benefits the sale of their services.
- mst 12y agoThis sounds like the same argument would apply to selling bullet proof jackets to people who also own guns.
- tokenizerrr 12y agoAs far as I understand it the problem is as follows: 1. Bad guys get a site behind cloudflare, and host illegal content 2. You want to report said bad guys to their host, for whatever reason. 3. You discover they use cloudflare. You now do not know where they are hosted. 4. Cloudflare will not tell you their actual IP addresses.
- lucb1e 12y agoIf it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.
- pktgen 12y agoHave fun filing lawsuits and sending out subpoenas when you're just trying to host a game server as a hobby and not making money off it. Cross-jurisdictional issues will also make this very difficult, even if you know who the attacker is.
- 12y ago