6 ms·
Update: Just received an email from CF. -------------- Hello, With regard to your inquiry, we have restored the domain names in your account to active status
by malikNF 4y ago
Update: Just received an email from CF.
--------------
Hello,
With regard to your inquiry, we have restored the domain names in your account to active status. Please allow for normal propagation. You will need to re-add mnf90.com to your account in order to manage it. Our apologies for any inconvenience this may have caused.
Kind Regards,
Cloudflare Trust & Safety
------------
Not much info lol, but guess its fixed now?
Thanks HN for up-voting my post and helping me get the attention of CF. Time to go figure-out how not to get in to this situation again, and a way to mitigate this incase the AI gets angry again. Funniest thing about this is, I wanted my own email because I was afraid of this scenario, getting locked out of everything, what happens if big G or M decide to close my account down?
Again, thanks HN. Really appreciate you folks for helping me get the attention.
- malikNF 4y agoUpdate 2: ----------------------------- Helo, To clarify the issue, this account was identified in a recent fraud review, however it appears to have been a false positive. We have left a note in this account for future reference. Kind Regards, Cloudflare Trust & Safety
- Veen 4y agoThat's really quite worrying. You'd have been screwed without HN, but not everyone has that recourse. How many other domains have been affected by "false positives" announced with a "we've banned you and we aren't telling you why; now fuck off" type email.
- akersten 4y agoNot to mention the "don't worry, we've put a sticky note on this account so it won't happen again (to you)" instead of an "oh shit, we need to immediately stop and fix this automated process that is catching legitimate customers and banning them with no recourse."
- malikNF 4y agoI agree 100%. And yes, without HN I will be really screwed.
- temp8964 4y agoI am really curious about this. How screwed is this? Can you move your domain out, if you want to?
- malikNF 4y agoCloudflare marked my domain as PENDING DELETE. So from what I have read in the past few mins my only option was to buy the domain the moment it gets released through another registrar and hope no one else snatches it. So yeh, VERY screwed.
- temp8964 4y agoWOW. This sounds extremely bad. I started using a personal domain just for email to avoid Google AI kind of screwups, I didn’t know a domain name can have this kind of screwups. I am using a traditional domain hosting company now, definitely not going to use this kind of new tech company to handle the most critical thing.
- ryandrake 4y agoVery worrying. One of the reasons I'd choose a non-huge company like Cloudflare would be I'm less likely to encounter one of these "our automation banned you, we won't tell you why, fuck off" episodes. Looks like more and more companies are cargo-culting this horrible practice. Waiting for my utility company to turn off my heat: "Your house is fraud. We won't tell you how we know. Fuck off and freeze."
- barkingcat 4y agoCloudflare is by no means a "non-huge company" - don't they route/cdn like 1/4 of the entire internet? going with cloudflare is a choice towards centralization.
- RHSeeger 4y agoI read it as > non-(huge company like Cloudflare) not > (non-huge company) like Cloudflare
- FerretFred 4y ago> one of these "our automation banned you, we won't tell you why, fuck off" episodes More like "We can't tell you because it's AI and the (AI) won't tell us why it made that decision".
- johnklos 4y ago"fraud review". That's intentionally vague, especially considering how often they simply ignore complaints about clear and unambiguous phishing sites they host.
- deleted 4y ago[deleted]
- batter 4y agoWhen I reported fraudulent activity (attacks on enterprise accounts) from CF IPs they told me to f*ck off, their customers know what they're doing. Wondering what it takes to ban someone on CF.
- rozab 4y agoDenying abuse and aggressively policing for it are both ways of achieving the same thing, that is, minimising liability
- ffhhj 4y ago》it appears to have been a false positive That's a scary answer. Guess I'll put only mirror/backup domains behind CF in the future.
- OJFord 4y ago'behind CF' isn't the problem, if I understand you correctly, it's that in OP's case CF was the registrar.
- akersten 4y agoYou keep framing this as "how do I make sure I don't get into this situation again," but with the attention this is getting (#6 on HN) and just how bad the issue is (both functionally and PR-wise)... Cloudflare should really do a public post-mortem here. It sounds like it's their fault.
- malikNF 4y agoSorry, if my post wasn't clear. What I meant by mitigating this issue is, I am going to start looking in to other providers and escape routes if I anger the all mighty AI again. I too am really interested in figuring out why I(free) and my clients(paid subscriptions) will trust cloudflare. Mistakes happen, but I can't even imagine my situation if HN didn't come to my aid.
- akersten 4y agoYeah, I agree it's totally valid to want to avoid the AI ban hammer. I find myself doing it too - e.g. paying cash at stores I would normally never go to, for fear Mastercard thinks it's fraud. I was just saying that it's an egregious enough error that in your shoes I'd be a lot more upset with CF.
- px1999 4y agoThe irony in paying cash instead of using your card is that you're likely training their model to be more likely to flag transactions as fraudulent. This sort of stuff is why explainable AI is IMO important. Assuming the CSR could see _why_ the original domain was flagged by the model as fraud, they could respond in a meaningful way, other than just requiring the OP to go and find someone with more authority than the machine to override the decision. Unfortunately in these types of situations, getting a satisfying explanation of why something happened is incredibly rare - my understanding is that it's usually at best an educated guess.
- TrueGeek 4y agoI also want to see a Cloudflare post-mortem here. All of my domains are with them. The worse part of OP's story is that they even prevented him from moving the domains to another registar. So if this happens to any of us we're completely locked out of our email.
- srrr 4y agoIf you live in the EU the article 15 of the GDPR grants you the right to ask about the details. Often companies reply that they don't need to answer because of ¨security¨ but this is not true. You can in detail ask about ALL personal data that was used as an input for this decision, information about the ¨automated decision-making¨ (algorithm), and all personal data that resulted out of this process. https://gdpr.eu/article-15-right-of-access/ https://gdpr.eu/article-15-right-of-access/ If any of this data is false you have the right to rectification. https://gdpr.eu/article-16-right-to-rectification/ https://gdpr.eu/article-16-right-to-rectification/
- usr1106 4y agoGood point. But even if they (any of those corps running algorithms but no customer support worth the name) comply (which I won't take for granted), you will get some code or keyword that fraudulent activity was detected. Very unlikely that they have technical details of the root cause in their customer DB.
- srrr 4y agoI don't think so. I have not worked on many fraud detection systems but in all cases there was a very detailed record in the logs of what happened and how the decision came to be. In addition, if there was a human review additional data is often generated. You can't just flip a bit in the customer record, or can you? (Edit: And if no information is in the logs I would argue that all information is in the input data and fraud detecting algorithm and thus the algorithm itself gets part of the data. Whatever happened, if the action can not be "replicated" / understood with the data you got after the article 15 request the data is not complete.) Since the domain and account belongs to you as a person, this is all personal information under GDPR.
- usr1106 4y agoWell, I'd hope affected users could submit (reasonably anomymized versions) of what they got to HN in the future, so we can stop speculating.
- 4y ago
- devoutsalsa 4y ago> The suspension is permanent and we will not be making changes on our end. "J/K LOL"