4 ms·
>Cloudflare, please don't be part of the problem. You've long been a champion of a more open web How exactly? Cloudflare has been a threat to the open web for
by stemlord 2y ago
>Cloudflare, please don't be part of the problem. You've long been a champion of a more open web
How exactly? Cloudflare has been a threat to the open web for as long as I've been paying attention to them
- deleted 2y ago[deleted]
- mschuster91 2y agoWithout Cloudflare, a lot of the internet sites you use daily would have had to give up rather sooner than later. The dream of a free and equal Internet died on the day shitheads could rent 0wned devices for ddos attacks for 10$ an hour in bitcoin. There would have been a tiny window where governments could have stepped in and demanded that ISPs follow up and act on abuse reports, but Obama on his last legs didn't have the power any more and Trump didn't care. Ideally, there would be an FCC regulation requiring ISPs above 500 customers have a time frame of two hours between getting notified of an attack originating from their network, investigate it, and cut off the other party unless they had shown evidence of effort to be a better netizen. That would also have led to economic pressure on Microsoft and other vendors (looking at you Java) to actually make their products more secure.
- apitman 2y agoIt would be nice if there was some sort of system in place to resolve attacks at the source. Sounds like a really hard problem though. Based on reports ISPs can identify which routers are causing problems. With more invasive routers they might even be able to identify the specific devices. Then I guess they inform the customer via email or something? What happens if customers don't do anything about it? Also what's to prevent attackers from sending tons of bogus alerts to ISPs to muddy the waters and undermine the entire system?
- mschuster91 2y ago> Then I guess they inform the customer via email or something? What happens if customers don't do anything about it? They get disconnected and have to provide evidence they cleaned up shop before getting reconnected. > Also what's to prevent attackers from sending tons of bogus alerts to ISPs to muddy the waters and undermine the entire system? Do I care about multi billion dollar companies having to hire a few thousand employees actually skilled to investigate abuse reports? No.
- account42 2y agoThis is exactly how you get hosting providers threatening to nuke your server if you don't respond in an unreasonably short time even though there is nothing actually wrong with it. No thanks.
- mschuster91 2y agoHence why I mentioned that ISPs have to, gasp, hire people to investigate. Someone complains about portscans or has indicators of a server being compromised? That is something the ISP can easily verify on their own.
- TiredOfLife 2y agoThe problem is that Cloudflare is the company that protects those that do the ddos atacks. Their whole existence as a company depends on there being a healthy market for ddos attacks.
- account42 2y agoCountries can still just as well step in now, there is no window that has passed. However, swift shutdowns not involving a court would be the wrong way to do it - as wrong as the DMCA is. All that is needed is appropriate consequences for bad behavior, including those shielding bad actors.
- mschuster91 2y agoCourts are not customer support, the court system is already massively overloaded as it is. I agree that courts have their place, in this case to provide an appeals solution if someone remains blocked by their ISP despite provably not being a bad netizen. But they cannot shoulder the load of policing - in the meatspace, that's done by police, in the digital space the ISPs are the closest equivalent.
- PinkiesBrain 2y agoThere should be internet 2. Kick off all ISPs which refuse to do good ingress/egress filtering. Kick off all customers which absolutely positively need to be completely exempt from the filtering because of their ultra special snowflake networks, when creating source spoofed abuse a couple times. So now you have an internet with reliable source IPs. Allow ISPs for their customers to push firewall rules blocking abusive traffic to the originating ISP, subject to some fair use rules. If an ISP's firewall slows down because they are overloaded with rules for obvious abuse from their customers ... well that's working as intended then.