8 ms·
That's not the case. There are a lot of hosting providers and reverse proxies that will gladly host malware and their upstream ISPs (which this thread is about,
by byyll 4y ago
That's not the case. There are a lot of hosting providers and reverse proxies that will gladly host malware and their upstream ISPs (which this thread is about, not hosting) will not block them. But what happens instead is they (either domains or IPs) get added to lists of phishing or malware enabled by default on most clients (browsers). Google has Safe Browsing and SpamHaus is probably the most popular spam list.
In contrast, nobody accidentally visits KiwiFarms. And there is nothing done to you (malware to download or your information being stolen) if you accidentally do.
- insanitybit 4y agoMalicious domains, users of email services for spam purposes, etc, get removed by their hosts all the time. That's simply a fact, I have made or been involved with the process as I work in security. There are some providers that are more cooperative than others, and certainly lists like Safe Browsing exists as well to deal with that + they can be more false positive tolerant. My point is that these providers make choices about the content that they host all the time. They do this because some content is just bad. Kiwifarms tipped too far into "bad" and got removed, just like malware would get removed, just like spammers get removed. Visiting a site, accidental or otherwise, isn't relevant.
- luckylion 4y agoI've previously reported phishing and scams to sendgrid, aws and azure. Neither took the domains down.
- insanitybit 4y agoI'm not sure what your anecdote is supposed to contribute. Are you trying to say that because of your experience you don't believe that hosting providers take malicious content down? That doesn't even seem worth responding to, if so, especially as I have given anecdotes to the contrary.
- luckylion 4y agoThey certainly don't do it reliably. You might have different access to them, and they listen to reports from you, or it's an "you need this many Twitter followers before we take reports from you". Them removing malicious content "all the time" is certainly not something I've seen. I disagree with an argument that goes towards "they care and that's why they do it this way today".
- insanitybit 4y agoIt doesn't matter if they do it sometimes or all the time or 90% of the time or whatever. The point is that they do it, they already take those actions and no one cries "censorship" because it's obviously a good thing that a malware C2 gets taken down.
- yucky 4y ago>Malicious domains, users of email services for spam purposes, etc, get removed by their hosts all the time. That's simply a fact, I have made or been involved with the process as I work in security. Yes because it's illegal. Deadnaming a transperson might be mean but it's not illegal. If there are countries where it is illegal, then they could just do like China does to "protect people from offensive material" by banning sites in those locales.
- insanitybit 4y ago> Yes because it's illegal. What exactly is illegal? None of what I have described goes through a legal process, there is no official judge saying "yep, that's spam" or "yep, that's malware". In general things are very murky with regards to what the legality around malware is - if it has not been used to access another system maliciously you're really going to have to stretch the CFAA (partly why the CFAA is so vague). Beyond that, just because something is not legally required does not mean that it's wrong to do it, so I don't see why the distinction even matters.
- yucky 4y ago>just because something is not legally required does not mean that it's wrong to do it, so I don't see why the distinction even matters. Define "wrong" though. That's the problem, and why the distinction matters.
- insanitybit 4y agoMy point is that the distinction already doesn't exist. This is because it really doesn't need to exist for most cases - no one worth talking to is on the "actually malware should be legal and providers should be forced to host it" side of the argument. Where things get murky is the "Potentially Unwanted Program" ie: programs that really really suck, are kinda sketchy, but don't cross over into malware territory. That's to say that there are grey areas, but there are also black and white areas, or areas that are so far on the fringes of grey that it's fine to just treat them as black or white. We do that all the time. In the case of Kiwifarms we have what I think is a very straightforward case. A website that exists for the sole purpose of organizing malicious acts falls well into the "maybe it's not illegal, but it's blatantly unethical".
- dmatech 4y agoFor decades, we've had a pretty consistent notion of what constitutes "network abuse". It's traffic that threatens the stability of the network itself (such as spam and worm traffic). Obviously illegal stuff can be taken down by law enforcement. But stuff that's simply "bad for society" is generally given a free pass. If you don't like it, your options should be: 1. Don't visit them. 2. Sue them. 3. Get law enforcement involved. Note that there is no #4 that says "harass everyone they depend on in an attempt to get them taken offline".
- hairofadog 4y agoI guess I don’t understand the argument that it’s ok for Kiwifarms to harass everyone in an attempt to get them taken offline, arguably criminally, but not for other people to harass Kiwifarms or their web hosts. If Kiwifarms doesn’t like it, can’t they 1. Stop patronizing Cloudflare 2. Sue Cloudflare or the people speaking out 3. Get law enforcement involved? From Cloudflare’s statement: > However, as the pressure campaign escalated, so did the rhetoric on the Kiwifarms site. Feeling attacked, users of Kiwifarms became even more aggressive. Over the last two weeks, we have proactively reached out to law enforcement in multiple jurisdictions highlighting what we believe are potential criminal acts and imminent threats to human life that were posted to the site.
- byyll 4y agoKiwifarms is a forum, it doesn't itself harass anyone, it does as much as Facebook or Twitter do (they don't, their users might be). Facebook wasn't taken down when the Christchurch event was streamed there. > However, as the pressure campaign escalated, so did the rhetoric on the Kiwifarms site. Feeling attacked, users of Kiwifarms became even more aggressive. Over the last two weeks, we have proactively reached out to law enforcement in multiple jurisdictions highlighting what we believe are potential criminal acts and imminent threats to human life that were posted to the site. I don't think you've heard the other side of the story. Although not mentioned, I am pretty sure they are referring to this post https://i.imgur.com/S1z3Po2.jpg https://i.imgur.com/S1z3Po2.jpg which was taken down in under 30 minutes - as soon as the admin saw it. Making the comparison to Facebook again, the shooting stream was 36 minutes, they claim "no reports" until 12 minutes after it ended (which I doubt, 200 people were watching it live and 4000 watched it afterwards [0]) and no indication of time to reaction for a company with so much resources. There are some theories that people that wanted the forum taken down made that post; even if that is not the case, does it mean that making a threat on any platform that allows UGC (for example, HN) and takes more than 30 minutes to get it taken down means that platform has to be taken down? Again, this post is not talking about any web hosts, it's about an ISP. It's the same as if every bottling company was pressured into stopping to do business with you so you made your own bottling company. Then, your water spring was pressured into stopping to sell water to your bottling company because that bottling company sells bottled water to bad people. Springs are probably easier to find or buy though. [0] https://www.theverge.com/2019/3/19/18272342/facebook-christchurch-terrorist-attack-views-report-takedown https://www.theverge.com/2019/3/19/18272342/facebook-christc...
- byyll 4y ago> Visiting a site, accidental or otherwise, isn't relevant. Might not be relevant to your point but it is relevant to the discussion.