8 ms·
It's rather disappointing that Cloudflare's policy is to not host content that is "illegal, harmful, or violates the rights of others, including content that di
by Borgz 4y ago
It's rather disappointing that Cloudflare's policy is to not host content that is "illegal, harmful, or violates the rights of others, including content that discloses sensitive personal information, incites or exploits violence against people or animals, or seeks to defraud the public", but they do not apply that same policy to content that they provide DDoS mitigation services for.
I don't see why their policies should differ depending on whether they are hosting or protecting the content in question. Either way, they are in part responsible for making that content accessible. I get the feeling that this is just an arbitrary distinction that they've made since hosting this content is more likely to have legal consequences for Cloudflare than simply providing DDoS mitigation services for it.
- wahnfrieden 4y agoThe policies differ chiefly because of massive difference in revenue
- sophacles 4y agoMore realistically the policies probably differ because they are different technologies and different use cases with different legal requirements.
- wahnfrieden 4y agosimply differing legal reqs and use cases are as unlikely an explanation as it is for why cf sets policy and behaves so much apart from rest of industry peers repeatedly who are under the same or similar constraints
- elefantastisch 4y agoThey address this: > Giving everyone the ability to sign up for our services online also reflects our view that cyberattacks not only should not be used for silencing vulnerable groups, but are not the appropriate mechanism for addressing problematic content online. We believe cyberattacks, in any form, should be relegated to the dustbin of history.
- Borgz 4y agoMy point is this: if there are certain types of content that they deem unacceptable to host, why do they deem it acceptable to protect? I disagree that the paragraph you quoted is relevant to that. But if it is, then it doesn't seem good that their goal of eradicating cyberattacks is more important to them than actual human lives.
- subsistence234 4y ago
- AtNightWeCode 4y agoAgree, there are double standards in work here and I think cf must pick a side.
- Georgelemental 4y agoTo use the analogy in the blog post: renting out a building to drug dealers is different from having firefighters save the drug dealers from a fire.
- schleck8 4y agoThat analogy is obviously manipulative. A DDoS is not going to kill anyone unlike a fire (or swatting evidently).
- tauntz 4y agoHosting and DDoS protection are different services. Think of them like a landlord (hosting) vs fire department (ddos) situation - one of them can morally refuse their services to people that they think are doing wrong/illegal/immoral things, the other one doesn't. Not that I agree or disagree with this argument - just wanted to point out what their reasoning seems to be.
- somesortofthing 4y ago> Think of them like a landlord (hosting) vs fire department (ddos) situation This is kind of a ridiculous comparison. A real-world landlord is a private individual extracting rent from their tenants while a real-world fire department is a publicly funded institution with a duty to protect everyone. Cloudflare offers both its hosting and DDOS services as a private company. They aren't morally obligated to provide anything, regardless of whether the DDOS protection is offered for free.
- kube-system 4y agoThis is totally orthogonal to your argument, but most fire departments are volunteer in the US (and a number of other countries).
- 015a 4y agoBut that's the point! CF sees this aspect of the policy as acting like a public utility. Is that so wrong? Isn't that better than the alternative? Maybe, if we lived in a world where the government provided CDNs and DDoS mitigation and DNS zone file hosting and resolution and such, then its a reasonable argument to say: We have an entity beholden to Higher Laws which we can hold responsible, and marginalized voices have recourse when they're failed by private infrastructure. We don't live in that world, and its not on the radar. Sure, private companies aren't beholden to Free Speech laws. But maybe its better that some opt-in to a standard higher than "if Jassy hasn't had his coffee this morning we better have an extra on-call SRE". Or, more commonly: when deplatforming decisions are made either by a blackbox AI written by engineers who left 2 years ago, or Twitter outrage.
- dannyw 4y agoThe public library may not want to curate Neo-Nazi books, but the police should not refuse to protect a Neo-Nazi from murder.
- sophacles 4y agoDDoS attacks don't just hurt the target of the attack. If any link on the path to the target is overwhelmed by the attack traffic, all users of that link are affected. Large attacks are hundreds of Gbps - a datacenter with 100Gbps of internet connectivity would be effectively offline. A datacenter with that much connectivity will likely host more than one site. I know you aren't advocating that other sites be taken down, but that is the effect of allowing DDoS against a site. Perhaps you don't mind collateral damage but it should be acknowledged as a consequence of your suggestion.
- raxxorraxor 4y agoI think it is good that they stay neutral and I believe even banning the Daily Stormer from their infrastructure was a mistake. As they write themselves it immediately created expectations for other content to be removed. Yes, the difference here is arbitrary, in my opinion a host should stay neutral as well. The Daily Stormer tried to unsuccessfully groom kids with cute comics. They could not have fallen any lower. An intervention here would not be required. A negative example is also an example you can learn from.