6 ms·
>We believe cyberattacks, in any form, should be relegated to the dustbin of history. Unless, of course, you are an _enabler_ of such attacks. This is where C
by creeble 4y ago
>We believe cyberattacks, in any form, should be relegated to the dustbin of history.
Unless, of course, you are an _enabler_ of such attacks.
This is where CF's hypocrisy shines through.
instant-stresser.com
str3ssed.co
freestresser.co
metastresser.com
(dozens more)
These are all sites hosted with CF DNS, who provide services that are literally the opposite of free speech -- they are in the business of _suppressing speech_, for money (or for free!). They are the providers of the service CF protects its paying customers against. There could be no more simple definition of a shakedown racket than this: Pay us for DDoS protection, or risk being brought down by one or more of our (non-paying) customers!
For all their completely defensible talk about free speech, this is a category of customer that is indefensible, and completely identifiable.
Except for one thing: If they were "relegated to the dustbin of history", so too would be CF's business model.
So before defending CF's stance on "free speech", take a good look at their business model, and who they support.
- Borgz 4y agoThis is very interesting, thanks for posting. According to completedns.com, instant-stresser.com has been using Cloudflare on and off for almost 8 years, and continuously for the last 3 years. It's also the 2nd result on Google for searching "free stresser". It seems impossible that this site hasn't been reported to Cloudflare by now, indicating that they have made the decision to continue protecting it. Very bad. I haven't checked the other sites you mentioned, but if this pattern holds, it definitely changes my perspective on Cloudflare.
- creeble 4y agoWell, maybe this site will help: ddosforhire.net They're a lovely recommendation/review site that lists a few dozen DDoS-for-hire sites. Take a random look at who hosts the individual sites' DNS. Their business is fundamentally a shake-down racket, disguised as a free-speech defender.
- skrebbel 4y agoWait, you’re suggesting they had board room discussions where they consciously, actively chose to protect and encourage ddos-for-hire sites because the threat of ddos attacks helps keep cloudflare in business?
- ldldksks 4y ago
- creeble 4y agoI'm saying that, despite frequent reports of DDoS-for-hire sites using CF for protection, they do nothing. And they do nothing because they profit from their existence. Again, this isn't free speech -- it is the antithesis of free speech. That's called hypocrisy. And yes, of course they cooperate with the FBI on specific cases (or, at least one specific case) of DDoS-for-hire prosecution. Not only because they are compelled to do so by law, but because they are the only company that can identify where the perpetrators are actually hosted.
- joepie91_ 4y agoI don't know whether they did, but it certainly wouldn't be unprecedented in the DDoS mitigation industry.
- photochemsyn 4y agoSo, the claim is that Cloudflare is acting like the window glass shop that drums up business by running around smashing windows at night? That's quite the claim. Here's a recent report on a DDoS-for-hire outfit that was criminally charged and convicted, related to downthem.org and ampnode.org https://www.malwarebytes.com/blog/news/2022/06/ddos-for-hire-service-provider-jailed https://www.malwarebytes.com/blog/news/2022/06/ddos-for-hire... Interestingly, the affidavit in that case does note that Cloudflare provided services for downthem.org and ampnode.org. However, this is a criminal indictment of the guilty party. I suppose the issue is, what kind of 'public reporting of criminal activity' is needed to provoke CF to drop services? In cases like this I also imagine CF cooperates with FBI investigations.
- gpm 4y ago> In cases like this I also imagine CF cooperates with FBI investigations. Seems to be the case, > The FBI’s Anchorage Field Office and its Los Angeles-based Cyber Initiative and Resource Fusion Unit investigated this matter. [...] Cloudflare, Inc. [...] assisted this investigation. https://www.justice.gov/usao-cdca/pr/illinois-man-sentenced-2-years-federal-prison-operating-subscription-based-computer https://www.justice.gov/usao-cdca/pr/illinois-man-sentenced-... Edit: And for anyone looking for the affadvit reference by parent, I believe they mean this: https://storage.courtlistener.com/recap/gov.uscourts.cacd.734708/gov.uscourts.cacd.734708.1.0.pdf https://storage.courtlistener.com/recap/gov.uscourts.cacd.73...
- creeble 4y ago> So, the claim is that Cloudflare is acting like the window glass shop that drums up business by running around smashing windows at night? That's quite the claim. That is not my claim; they don't operate any DDoS-for-hire sites. My claim is that their "free speech, we won't shut them down" claims are utter hypocrisy when they do nothing to shut down their support for DDoS-for-hire sites, the ultimate (on the internet, anyway) anti-free speech perpetrators.
- pier25 4y ago> If they were "relegated to the dustbin of history", so too would be CF's business model. If DDoS didn't exist I'm sure CF would still thrive as a CDN and all the other services they provide (Argo, Workers, etc). If anything, I'm sure CF would be more than happy to stop providing DDoS protection for free. They'd save a lot of money.
- tedivm 4y agoCloudflare has always hidden behind this stance as a way to justify doing awful things. When I worked at Malwarebytes we had regular issues with malware being hosted on Cloudflare. Now I don't mean like "hey download this file so you can learn"- that kind of thing we fully supported. I mean that these files were being explicitly used in drive by exploit attacks- if a user with a vulnerable browser went to the wrong webpage, that webpage would load exploit scripts from the Cloudflare network and then inject the malware. To me this is a very simple example of abusing a network. It is not a free speech issue, unless you think punching someone in the face is free speech. We proved that this was happening by providing pcap files showing the entire network transaction and the fact that users were not initiating this on purpose. Their response was to ignore us until we started blocking their end nodes, at which point they came to our forum and straight up lied. > Unfortunately, the new system is unlikely to resolve the current controversy which is more political than technical in nature. The current controversy involving Malwarebytes blocking CloudFlare IPs is centered around one site. To be clear, this site does not distribute malware itself and visiting it will not infect your computer. It does, however, provide information on how to create malware. Philosophically, we believe there is a difference between distributing malware -- which we will prohibit through our network -- and distributing information about malware. We do not believe our role is to play censor to any information on the Internet, even information we find disturbing. Publishing the Anarchists Cookbook does not make you a terrorist. Blocking sites based on the information they contain, as opposed to the actual harm they do, takes a step down a slippery slope I find deeply troubling. https://forums.malwarebytes.com/topic/108447-my-site-using-cloudflare-is-being-blocked/?do=findComment&comment=542997 https://forums.malwarebytes.com/topic/108447-my-site-using-c... This was a 100% dishonest lie, and it's the same pattern Cloudflare has been following for a decade now. In this case they lied claiming we were blocking educational material, which is something Malwarebytes never did. He said all of this after we sent the pcap files proving that this wasn't an issue with educational sites. From my perspective Cloudflare has always been willing to hide behind free speech even if it isn't relevant. It's their go to excuse for any bad behavior.
- schleck8 4y agoThis entire 'freedom of speech' absolutism bullshit is so incoherent. They host and protect a website only dedicated to muzzling people the userbase disagrees with...
- 015a 4y agoHosting a DNS zone file is not tantamount to enabling attacks. Its like saying Google enabled murder because Maps provided the directions for a murderer to get to the victim's house.
- creeble 4y agoIt's also not tantamount to saying "relegating cyberattacks to the dustbin of history" either. Maps isn't a service used for suppressing free speech. It's the hypocrisy that is galling. If you stand up for free speech, it is inconsistent to support those whose business plan is the suppression of free speech.
- 015a 4y ago> It's also not tantamount to saying "relegating cyberattacks to the dustbin of history" either. Are you certain of that? Could it be that CF's demonstrated history of cooperating with law enforcement actually makes identifying and shutting down these sites easier if they have fingerprints all over CF's network? They'll exist with or without whatever services CF offers; its better that they exist within an entity with the mission to action on their misbehavior. Sure; smarter site operators just don't use CF. Many aren't smart. But some are: and bingo! We've hit the same outcome you want, but we gained something tangible toward our goal along the way. This isn't hypothetical. This is literally how CF operates. > Maps isn't a service used for suppressing free speech. It sure is! But, to be fair to the analogy; Google Maps isn't a service that claims any element of free speech in defense of its policy enforcement. Anyone can use Maps to navigate anywhere, then assert their own morals and values on others at their destination. Leftist protestors use it to attend abortion rallies. Rightist protestors used it to find the Capital during the riots. Police use it to find innocent black people to kill (ok, forgive me for dramatizing the illustration here). The Tool wasn't necessary for their actions; just like CF isn't necessary for these DoS sites. But it did enable them to do it nonetheless, and they did use it. That is the dual-edged sword of Tools; their creators rarely get a say in how they're used. Internet Services are, maybe, among the first tools like this where we have this voice dictating control over their usage, and the creator has the Power to listen. Its a New Capability. Dewalt power tools and Git are both probably used in the development of weapons by enemies of the state; there's little to be done about it. Do you believe the CEO of Toyota felt pride seeing so many Toyota pickups powering ISIS' war machine (well, its a pretty harsh environment, kudos to their engineering no doubt)? Sure, export controls, laws, policies against who you sell to, all crude tools from the stone age compared to DELETE FROM users WHERE.