14 ms·
Cloudflare lobbied FTC to stifle security researchers
- balentio 4y agoSomeone just posted up a pull quote the other day on Hacker News about how Cloudflare doesn't bend to cancel culture, and I remarked that they all ready had more than once. Now the big reveal is they ARE Cancel Culture, but they have no idea they are!
- cassonmars 4y agoFor starters, these events are totally unrelated, and are a very strange false equivalence. Would be very curious to see more details of Tavis’ claim though. That being said, CF is still in the right for the stand they’re taking on not being a content regulator of their base internet utilities.
- 6c737133 4y agoNothing better than claiming the perks of "being a utility provider" while bearing none of the burdens lol If CF didn't offer free DDoS protection - ironically, whilst providing cover & protection to the greatest # of DDoS-4-hire websites on the clear-web - they would have nothing else to offer that would be considered best-in-class But yeah, they're the preeminent force in ensuring free speech on the internet lol
- llama052 4y agoI think they offer a lot of best in class services, have you used the enterprise tier or just the free tier?
- fjfbsufhdvfy 4y agoA lot of their services, such as R2 storage, have literally no competition.
- fjfbsufhdvfy 4y agoHope the guy who down voted me enjoys paying 100-1000 times more to Amazon's egress racket!
- markovbot 4y agonot the one who downvoted you, but backblaze has similar pricing: https://www.backblaze.com/b2/cloud-storage-pricing.html https://www.backblaze.com/b2/cloud-storage-pricing.html
- trollied 4y agoBackblaze also has free egress to Cloudflare. Which is very cost efficient.
- fjfbsufhdvfy 4y agoUsing this for significant amounts of non-html content will get your account disabled. They only allow it for R2.
- _8j50 4y agoI am all for a law compelling companies like CF to cooperate with LE and censor on behalf of the state if that is the will of the people. They are a utility provider that has not been expected by society to fund and administer a censorship operation. Go and vote if you think they should be compelled to censor.
- Hamuko 4y agoUnless I'm misunderstanding your idea, that sounds like it goes against the First Amendment.
- _8j50 4y agoThat's why I said vote. But not neccesarily, companies are not people they are not protected by the bill of rights and this is already happening when LE forcibly takeover domains to censor them with cause of course. Also, freedom of speech does not include speech made with thr intent and effect of causing demonstrable harm.
- Hamuko 4y ago>That's why I said vote. Constitutional amendments are so tricky that I'm not sure if just going out to vote is gonna change anything. >Also, freedom of speech does not include speech made with thr intent and effect of causing demonstrable harm. I don't think that is a legal standard for the First Amendment. Advocacy of violence is protected speech under the First Amendment.
- _8j50 4y agoStates needs to ratify amendments so having enough state legislatures and laws to support the amendment is the best way. Having someone propose it at the fed level is the easy part.
- 6c737133 4y agolol plz see my reply to OP
- phillipcarter 4y ago> That being said, CF is still in the right for the stand they’re taking on not being a content regulator of their base internet utilities. This is entirely unrelated to the issue of if they should stop offering their services to known Very Bad People. Nothing about current events with CF is related to regulating content.
- cassonmars 4y agoIt absolutely is about regulating content. Just because the content and the people that generate it are vile does not mean an internet backbone utility should play great internet censor about it. I say this as exactly the kind of person (trans) that the community in question loves to attack.
- phillipcarter 4y agoCF isn't a utility. KF is perfectly capable of operating on their own, without CF's products. This is strictly a matter of CF's desire to continue to do business with them. Their whole spiel on the blog post about how they're a utility is just dancing around the issue - they have no legal obligations that an actual utility does. It's an interesting discussion if they, and others like them, should be considered a utility. But that's neither here nor there because they aren't one.
- derangedHorse 4y agoI don’t think CF ever said they had a legal obligation and I don’t think they ever wanted to be perceived as if they do so I don’t think the reminder in your comment changes any stances. The fact of the matter is that people are mad because CF is protecting a site against digital vigilante justice instead of finding a better means to approach taking down KF. As a company CF could deny service to KF but then it would be giving power to the vocal dissidents who could seemingly quiet any site they find disagreeable.
- xenago 4y agoThis is a really bad look. InfoSec is a very tight-knit industry and this will really make working with/using CF an unpleasant proposition to many.
- dsl 4y agoIf it wasn't already, you aren't paying attention. Cloudflare is quite literally the largest bulletproof hosting provider for bad actors on the internet, and unless you know someone at the company personally takedowns are like pulling teeth.
- zccrkn 4y agoNot to mention that CFs policy is to forward takedown requests, unredacted, to the site you're trying to takedown. CF users like KiwiFarms have been weaponizing this policy for years by publishing their takedown requests, knowing their userbase will seek retribution against whoever sent them.
- charcircuit 4y ago>CF users like KiwiFarms have been weaponizing this policy for years If your complaint is that the host should be the only one to see the full report then your point doesn't stand since Josh pays to have his own ASN so he can personally handle reports for it. If your point is that only Cloudflare should have the name I don't think it counts as a valid DMCA takedown since it's not like you have a signed document from the copyright holder or someone on their behalf.
- xenago 4y agoHuh? Are you suggesting sites shouldn't have access to takedown requests? That is unreasonable.
- zccrkn 4y agoI'm suggesting there should be a path to complain to Cloudflare without the site being put into the loop, for cases like this where the site is not acting in good faith.
- jgrahamc 4y agoI saw this Tweet earlier and reached out to our public policy and legal teams. Also reached out to Matthew (eastdakota here). They all have no idea about this. We appreciated Tavis/P0 finding and making us aware of Cloudbleed. Kicked off a very stressful time for the team at Cloudflare but glad the bug got found and addressed. Tavis: happy to chat, I've dropped you an email. Follow up: https://twitter.com/taviso/status/1566159561148362753 https://twitter.com/taviso/status/1566159561148362753
- tooltower 4y agoA follow-up of this tweet indicates that you found the person responsible for this mess, and was not authorized by Cloudflare to do this. Great. But it also sounds like a reasonably common occurrence, and hence a systematic problem.
- ferdowsi 4y agoReminds me about how yall had "no idea" that you had banned benchmarking. Remarkable how much leaders can not know about their company's operations! https://news.ycombinator.com/item?id=29468771 https://news.ycombinator.com/item?id=29468771
- bawolff 4y agoBig companies having the left hand not know what the right is doing is hardly a new phenomenon.
- hn_throwaway_99 4y ago> Remarkable how much leaders can not know about their company's operations! Oh please. These are large corporations, I would honestly be flabbergasted if leadership knew every mundane detail. Particularly in the benchmarking issue you noted, it's pretty easy to understand how that could have been added as legal boilerplate, but just went too far.
- mook 4y agoLeadership might not know every detail, but that doesn't absolve them of the responsibility to know (and find out, and correct it once they do so similar things don't happen again). This one only came to their attention because Tavis Ormandy is famous and it got on HN front page; how many other insurance didn't?
- trasz 4y ago
- zccrkn 4y agoCloudflares indifference to DDOS-for-hire providers using their service is also raising some eyebrows, considering a large part of their business is mitigating DDOS attacks. Do a search for "stresser" or "booter" services (euphemisms for DDOS-for-hire) and check their DNS records, 9 times out of 10 they're hiding behind Cloudflare. Intentional or not, helping the attackers stay online while also selling mitigations for their attacks is basically a protection racket.
- deleted 4y ago[deleted]
- _8j50 4y agoI echo the top comment on that pro-nazi post, too much missing info to form an opinion. I don't like or hate CF either way but quit this "_______ also did some bad shit" that's not the topic of discussion and is a clear attempt at "cancelling" instead of discussing the topic at hand. Which so happens is also missing a lot of info and HNers are jumping the gun without knowing who did lobbying and why and what consequences they faced.
- kortilla 4y ago> EDIT: Also, “We find that several providers are disproportionately responsible for serving misinformation websites, most prominently Cloudflare” Cloudflare is disproportionately responsible for serving all websites.
- subsistence234 4y ago
- braingenious 4y agoThis is tangential but kind of on-topic since Tavis mentions KF in the replies, but I’ve found it pretty amusing that Cloudflare’s position on enabling doxxing, harassment and DDOS-for-hire has been “Aw shucks, we’re just too darn powerful to do anything about any of this!” It’s as if anybody could fall ass backwards into a situation where they built up an organization that dictates what’s on the internet as a whoopsie, and oh no, you too would have to enable harassment, doxxing and DDOS-for-hire because shucks, all that darn unlimited, unchecked and unregulated power, access to money and legal resources is actually the same thing as having no power at all! Poor Cloudflare, they can do literally whatever they want and that means they can’t do anything at all!
- penrouse 4y agoSeems to me they're operating on a matter of principle. The Christians who run my local food bank do similar. Their clients include some of the worst people: rapists, paedophiles, murders - released from prison, with nothing and no-one to help them, other than these kind churchly individuals. Their principle is that Jesus would want them to help their fellow humans in need, no matter what their sins. So they do. Obviously it's a bit different with Cloudflare as they're a for-profit company of diversely ideological employees, not a non-profit charity of devoutly religious volunteers. But the former type of organisation can run on principles other than making money hand-over-fist too.
- sofixa 4y agoI think you can appreciate the difference between not letting former criminals (released from jail) starve and helping them integrate back in society, and actively providing them tools that they use to do terrible things, including crimes.
- ThrowawayTestr 4y agoKF is just a forum, nothing posted there is illegal.
- 4y ago
- _8j50 4y agoGood luck fighting about CF's morality HN. But the root-cause here is lack of legislature explicitly defining rights and obligations of security researchers and the vulnerability reporting process. As it stands, you can get raided for vuln reporting (doesn't happen a lot because if common sense not law), harrassed, face retaliation and have the vendor silently fix it without crediting you. For some reason everyone thinks this is a matter to be legislated and resolved by poularity contests (don't use vendor X) and/or capitalism. Which is interestingly why the FTC is even involved I guess? In an ideal society you wouldn't need such laws and the default is liberty but in this society the only reason researchers are even being allowed to do their job is things like twitter and fears of PR nightmares (which won't work with every vendor/company ).
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- xenago 4y agoFor anyone not aware, the CEO has responded. https://twitter.com/eastdakota/status/1566160152684011520 https://twitter.com/eastdakota/status/1566160152684011520
- hericium 4y agoGoogle Zero exists to discredit competition.
- jgrahamc 4y agoYou know, I hear this from time to time. And I hear criticism of Cloudflare's reaction when Project Zero told us what they'd found. I don't think they were discrediting Cloudflare and imagine the opposite scenario. Imagine P0 hadn't found Cloudbleed and it hadn't been stopped as fast as it was. As tough as Cloudbleed was, I am grateful Tavis spoke up. And a lot of people should be also.
- hericium 4y agoCloudflare is a neighbor player to poke. In general, I'm more worried about smaller players. Tavis seems to have a very dopaminergic personality and I appreciate your position but I feel that (fully and professionally done) responsible disclosure means more than impulsive twitter posting.
- UncleMeat 4y agoYet GPZ regularly publishes serious vulns in Google products like Chrome and Android.
- astrange 4y agoThis is a good policy. Security people are universally annoying and full of themselves. Many other kinds of bugs (accessibility, performance, bad UI copy) harm users and none of them go around having cool Vegas conferences, giving names and logos to all their bugs, and seeming to think they’re characters in The Matrix. I propose that anyone who gives a talk about anything first apologize for causing people to perceive them.
- omegacharlie 4y agoFeel like there is more to this story than just a single tweet. What exactly was lobbied and under which grounds?