Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Hanlon's Razor applies here. "Never attribute to malice that which is adequately explained by stupidity."

    Pretty much anyone can get onto the free tier for Cloudflare. The fact that someone is, doesn't mean that there is a business relationship with Cloudflare. There isn't.

    In order to make this business model work, Cloudflare does essentially no due diligence. Getting onto the free tier before you need it, is cheap. And then if you really need them, you have every reason to start paying.

    Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against. They wouldn't have a business if they made that a viable target!

    But the result of these business decisions, made for their main customer acquisition flow, makes them a tempting place to host malicious content, as well as good. Black hats make a sport out of taking each other out. And so have every reason to use Cloudflare.

    Still doesn't indicate a relationship between Cloudflare and the bad actors who are taking advantage of the setup.

  • What you are saying is that Canonical should have first updated the DNS to point at the attacker's web site IP (hosted by Cloudflare) for a few hours to let Cloudflare eat 3.5Tbps for a bit? :)
  • > Ideally you'd hope that they would allow third party takedowns. But the ability to do third party takedowns provides a target for the exact attackers that their business is trying to protect against.

    I don't think that argument holds water. There's a world of difference between knocking a site offline with a DDoS and making a legal request which results in a hosting provider shutting it down.

  • I'm not sure how correct this is but when you upgrade your tier on Cloudflare aren't the costs basically up to Cloudflare?

    With the horror stories heard over the years I think a real issue is no hard pricing cap with forced shutdown.

    Unless that's changed? I booted them a year ago..

  • With this kind of logic we can blame keyboard manufacturers for the illegal things their products wrote.
  • Or water companies for selling water for them. Where is the line?
  • This is a flawed analogy. The "keyboard manufacturer" in this scenario is the "router manufacturer" who Cloudflare buys off of, not Cloudflare.

    In your scenario Cloudflare is more like a newspaper aggregator which carries all sort filth along with it's normal commentary.

    If this was a normal situation one could just decide not to read some filthy newspapers, while letting those who want to read it make that decision for themselves.

    But in the Cloudflare scenario all the major relevant normal newspapers decided to publish all their content through Cloudflare and if something objectionable is published along with it, instead of taking your beef to the original publisher, you have to to take it up with Cloudflare who might just forward your details to some very unsavory people without you having a chance to know beforehand.

  • Not the same case. If you get a bomb on a ups package, that's not UPS' fault.

    But if you tell UPS someone is using them to send bombs to people, and they don't act on it in the least and even look like they are shielding bomb senders, then it starts being their fault a little bit, doesn't it?

  • This is a service, not a device sale. Continuing to provide a service to an organization that is using it to support criminal activity is very different and terminating clients for illegal activity is not controversial.
  • That'd be extortion, not blackmail. CF did neither thing.
    by luma
  • I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail, so that hacking group could exploit as many targets during that time as possible
  • copy.fail patches can be applied with minimum downtime, and a VM reboots in 30 seconds, tops, regardless of size. I believe all the apex servers are configured as HA to keep the load distributed, so normal users won't feel anything when copy.fail is patched.

    Our users didn't feel a thing when we rolled out the patches.

  • > I always assumed ubuntu was brought down to prevent ubuntu servers from patching copy.fail

    On Ubuntu copy.fail could be mitigated against with some modprobe(8) config tweaks:

        # echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
        # rmmod algif_aead
    
    There may be some processes that use this functionality ("lsof | grep AF_ALG"), but it is not that widespread AIUI, and so disabling it should not be an issue for the vast majority of systems.
  • Completly agree, cloudflare protects scammers on a huge scale and no one cares...

    All the faceshops I have reporeted to cloudflare, all these phising pages behind cloudflare I reported, never came down.

    None of them.

    For a company making billions, protecting people, they should take this stuff serious.

  • Would you prefer a huge organization that arbitrarily censors websites without a mechanism for appeal or legal process? The current state of affairs is way better.
  • If you’re not using the legal system to seek action from Cloudflare, you’re unlikely to be heard by them. “I was injured for $20 and I seek as redress the customer payment details (issuing bank, account number) provided to Cloudflare so that I can identify and file a claim for financial redress against them” would be a lovely small claims lawsuit, for example. I haven’t heard of anyone trying that yet but I’d love to admire the results if someone does!
  • The article puts it very succinctly: Cloudflare fronts attackers for free and bills the victims for relief.

    Ddos protection services can be cast as a digital protection racket where they have a perverse incentive to keep attackers attacking. “It's a dangerous internet out there; you'd better pay us to protect your website from the attackers using our free tier.” At the least, even if there is no active collusion or profit sharing or anything like that, there is not a clear side that the DDos protector service is on?

  • It's a protection racket born of fundamental weaknesses in the Internet's bedrock protocols.
    by api
  • The thing is, you can control a neighborhood, a country etc. from attackers and establish control over violence.

    How can we do that, if we would like to preserve relative anonymity and global nature of the internet?

    People can indeed form cooperatives to handle the protection, but this is hard to manage globally as an entity. DDoS protection is done by primarily having too much capacity to tank it and then filter it. The required investment is rather high.

  • There's a simpler explanation: Cloudflare (generally speaking, not 100%, as in the case of The Daily Stormer[1]) does not censor presumably-legal content traveling through their systems, and do not themselves opt to be arbiter of legality.

    [1]: https://blog.cloudflare.com/why-we-terminated-daily-stormer/

  • Ok, so what's the solution?

    I do agree with your comment. But obviously Cloudflare didn't invent DDoS. If Cloudflare just magically disappears tomorrow, the AI crawlers won't stop. So what's the alternative? It's not a world you need to upload a government-issued ID to browse the internet, right? ...right?

  • I dislike CFs role in the modern Internet as much as the next person, but this is a bunch of speculation trying to connect dots with no basis other than that a Canonical cert renewal happened on the same day as a company transfer.

    There might be somewhat of a tangential story, however, in that Njalla seems to have reorganized or changed ownership fairly recently[1], and that Njalla and immateriali.sm seem to be related entities[2]

    https://xn--gckvb8fzb.com/njalla-has-silently-changed-a-word... https://www.wipo.int/amc/en/domains/decisions/pdf/2026/dio20...

  • Relevant post from last week:

    > Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?

    https://news.ycombinator.com/item?id=48025001

  • Articles like these seem to hold a weird belief that Cloudflare does not react to security reports or legal orders? From my experience, they react appropriately and relatively quickly compared to rest of the industry.

    Could Cloudflare be more proactive or add more friction to their signups? Yes, probably, but the reasons they have outlined for not playing internet police make sense to me.

    I don't think it should be a requirement to provide your credit card, phone number and a copy of your ID in order to host content on the internet...

  • That's not a "weird belief". Cloudflare positions itself as "infrastructure". That means they think they are not responsible for the content that they carry.

    In a normal scenario, if you want to protect your systems from other "bad" systems on the internet, you can block them on the IP layer.

    But Cloudflare operates at the IP layer proxying data between you and good and bad (and everything in between) systems.

    In a normal situation you could block and report a site that is run by the the mob, by either blocking them at the IP level or by contacting the abuse@ of the organization that is hosting the content.

    Cloudflare is making it so that you can't do either. And if you send an abuse report to Cloudflare, you cannot be sure that they will not just forward your contact information directly to the entity that you are complaining about. They have changed their stance over the years to appear more responsible, but the fact remains:

    If I want to send an abuse@ report to a system that is hidden behind Cloudflare I can not be sure that they won't just forward it without me knowing who they are forwarding it to.

  • Cloudflare & AWS wouldn't even INVESTIGATE a abuse report I sent because there weren't any "infringing URLs" or "specific resources".

    I provided enough evidence for them to at least be able to kickstart a internal investigation or even CONTACT the abusive customer, which they did not do.

    If it were a stresser, all they would see is a login panel. It's not like these sites are publicly advertising what they're doing...

  • I don’t think it should be a requirement to talk to cloudflare at all to host content on the internet. I certainly don’t.
  • The internet worked for so long because people responsible for each little island did what was for the most part in the best interests of the rest of the islands. If you didn't, other islands would shut off their links to you. Law enforcement was a last resort because 1. the courts don't move at the speed of the internet and 2. nobody wanted the internet getting top down governmental regulation because it was trans-national.

    Cloudflare spent a bunch of venture capital to give away expensive things for free and buy market share. If you convince all the grocery stores to move to your island, you can operate a den of criminal activity with no fear of everyone else shunning you.

    Talk to anyone who fights botnets, malware, or online scams. Once you hit the Cloudflare dead end you just have to give up. Law enforcement isn't going to take up a case where only 7,000 peoples computers are infected, and Cloudflare isn't going to investigate and take action themselves.

    by dsl
  • people will always be able to pick a handful of sites they think shouldnt be allowed to use cloudflare hosting services. the problem is that every person will have a different handful of sites. cloudflare should host everything and anything unless and until a lawful order is received.

    if they start sticking their fingers into sites and determining whether the site's content is "appropriate" or whatever, based on some sort of nebulous set of criteria, people will get (justifiably) big mad about it, guaranteed.

    the "renting attack capacity [from cloudflare]" should have some evidence behind it, because as far as i am aware, the attackers are not using cloudflare infrastructure for the actual attack.

    (its really jarring to see the general sentiment on this submission vs. the general sentiment on google submissions)

  • Most people on planet earth will be able to trivially agree on a subset of all their lists which in fact shouldn't be able to use it