5 ms·
Do I want to see booters online? Of course not. But if CloudFlare were to shut them down without due process, that would damage their credibility - to the poin
by DanielDent 10y ago
Do I want to see booters online? Of course not.
But if CloudFlare were to shut them down without due process, that would damage their credibility - to the point where I would feel uncomfortable doing business with them.
I'm sure there's a group of people where CloudFlare's stance is damaging to their reputation.
But there's also a group of people where any other stance would damage CloudFlare's reputation.
Think also from the customer standpoint: people who need DDoS protection are people who are having their site shutdown without due process (by criminals who launch DoS attacks). When the company you hire to fix the problem becomes part of the problem, it's not good - and they would be part of the problem if they offered a 'send us an email and we shut down our users' denial of service attack vector.
- kbuck 10y agoEither way, CloudFlare is a part of the problem. They're either protecting booter services (thus necessitating your use of DDoS protection in the first place) or terminating the booter sites without "due process". It's relevant to mention that CloudFlare already does terminate a class of sites without "due process": malware hosts. What makes malware hosts that much worse than booters? Answer: CloudFlare's IPs can get blacklisted for it.
- stcredzero 10y agoIs it of comparable difficulty to reliably empirically establish 1) malware hosting and 2) operating a booter site?
- kbuck 10y agoI'd say yes: if you visit a purported malware URL and you are served malware, then it is a malware site. If you visit a purported booter site URL and it advertises booter services, then it is a booter. If the booter sites start trying to hide their identity, fine, I can see not removing that without proof. That will also severely injure the booter's signup rate, though.
- yoo1I 10y agoEven when reporting malware hosts to them, the response to my abuse reports is "we are a reverse proxy, we do not provide hosting" - and then no further action is taken.
- pjlegato 10y ago"Due process" means, quite literally, "process that is owed to you." It is the process that the government must, by law, provide when it is depriving you of liberty or property, to which (absent due process to deprive you of it) you otherwise have an inherent right. Customers of a private business have no right or expectation of due process whatsoever, since nobody enjoys any inherent right to be a customer of a business. With a very few narrowly defined exceptions, private businesses are generally permitted to refuse service to anyone they wish, without explanation. CloudFlare (and all other businesses) have always refused service to numerous classes of customer whose activities they deem abusive, in their own sole judgement, without any due process. Read their terms of service, read AWS's terms of service, or Google's, or any other company's. They all already shut numerous people down without any due process, every single day. OP is simply suggesting they add one more category to the already long list of prohibited activities on their platform.
- fweespee_ch 10y ago> Do I want to see booters online? Of course not. > But if CloudFlare were to shut them down without due process, that would damage their credibility - to the point where I would feel uncomfortable doing business with them. The problem with this stance is it appears to be a conflict of interest. The easier it is to access a booter site, the more people who need Cloudflare's services. I'm not saying that is the reason they do it. I'm just saying that is a conflict of interest that can really only be resolved by removing clearly labeled booter sites. > Think also from the customer standpoint: people who need DDoS protection are people who are having their site shutdown without due process (by criminals who launch DoS attacks). When the company you hire to fix the problem becomes part of the problem, it's not good - and they would be part of the problem if they offered a 'send us an email and we shut down our users' denial of service attack vector. Hosting booters makes them part of the problem is the flaw in that logic.