6 ms·
Also another Italian here. For context, the "Piracy Shield" mentioned in the order is basically a legislative hacksaw authorized by the regulator (AGCOM) primar
by enricotal 9mo ago
Also another Italian here. For context, the "Piracy Shield" mentioned in the order is basically a legislative hacksaw authorized by the regulator (AGCOM) primarily to protect Serie A football rights. Soccer rules Italy more than the Vatican..
It’s a mess technically: it mandates ISPs and DNS providers to block IPs/domains within 30 minutes of a report, with zero judicial oversight. It’s infamous locally for false positives—it has previously taken down Google Drive nodes and random legitimate CDNs just because they shared an IP with a pirate stream.
The NUCLEAR threat regarding the 2026 Winter Olympics (Milano-Cortina) is the real leverage here. He’s bypassing the regulator and putting a gun to the government’s head regarding national prestige and infrastructure security.
My personal take idea likely outcome: Cloudflare wins.
EU Law: The order almost certainly violates the Digital Services Act (DSA) regarding general monitoring obligations and country-of-origin principles.
Realpolitik: The Italian government can't risk the Olympics infrastructure getting DDoS'd into oblivion because AGCOM picked a fight they can't win. They will likely settle for a standard, court-ordered geo-block down the road, but the idea of Cloudflare integrating with a broken 30-minute takedown API is dead on arrival.
- immibis 9mo agoCan someone report a bunch of government websites and legal streaming services and see what happens?
- ta9000 9mo ago> The NUCLEAR threat regarding the 2026 Winter Olympics (Milano-Cortina) is the real leverage here. He’s bypassing the regulator and putting a gun to the government’s head regarding national prestige and infrastructure security. Kind of wild that a private company has that kind of power, both in terms of being one of the few that can offer this service and they can make threats at this level.
- retr0rocket 9mo ago[dead]
- asa400 9mo agoThis is one of the consequences of outsourcing this (and other capabilities) to the private sector. Many governments simply don’t have the skill and political will to invest in these kinds of capabilities, which puts them at the mercy of private actors that do. Not saying this is good or bad, just trying to describe it as I see it.
- miki123211 9mo agoGovernments just can't come to grips with how much money software engineers make. Paying a contractor $x million? Yeah no problem, projects are projects, they cost what they cost. Does that $x million pay for 5x fewer people than it would in construction or road repair? We don't know, we don't care, this is the best bid we got for the requirements, and in line with what similar IT projects cost us before. Paying a junior employee $100k? "We can't do that, the agency director has worked here for 40 years, and he doesn't make that much." Variants of this story exist in practically every single country. You can make it work with lower salaries through patriotism, but software engineers in general are one of the less patriotic professions out there, so this isn't too easy to do.
- tsimionescu 9mo ago> Paying a junior employee $100k? "We can't do that, the agency director has worked here for 40 years, and he doesn't make that much." I can assure you that junior software engineers in Italy or anywhere else in the EU make nowhere near that amount of money. In fact, few of even the most senior software engineers make that amount of money anywhere in the EU (in Switzerland or the UK they might see such salaries, at the higher tiers).
- xinayder 9mo agoItaly can also buy the bluff and you know, partner with an EU company to provide them the service Cloudflare would offer "for free".
- pyvpx 9mo agoThere is no “EU” company with remotely the same network capacity or capability, in general
- xinayder 9mo agoBunnyCDN is a good contender for the network. They can find another provider for cybersec.
- lgeek 9mo agoBunnyCDN don't run their own network, most of their servers are hosted at DataPacket(.com), but they use some other hosting companies too. DataPacket has a very large network though and is kind of, sort of EU-based. AFAIK most operations are in Czechia, but the company is registered in UK. And there's also the Luxembourg-based Gcore.
- atmosx 9mo ago> but the idea of Cloudflare integrating with a broken 30-minute takedown API is dead on arrival. Why? Technically it’s very easy. Wha if JDV asked CloudFlare to implement this on a different occasion? Would it be dead on arrival?
- torginus 9mo agoI don't get how censorship of this kind is even technically feasible? I can rent a vpn on AWS, then connect to a stream hosted in Kazakhstan. You can't take down a website there, and you certainly can't rangeban AWS ips.
- mlrtime 9mo agoWhich stream, asking for a friend :)
- Imustaskforhelp 9mo agoCan they not block your AWS account though?
- Nextgrid 9mo agoA system like this could actually work as long as every takedown request involves posting a significant bond into a holding account and where the publisher can challenge the block and claim the bond if the block is ruled illegal. This achieves the advantages of quick blocking while deterring bad behavior, and provides cost-effective recourse for publishers that get blocked, since the bond would cover the legal fees of challenging the block (lawyers can take those cases on contingency and get paid on recovery of the bond).
- mercutio2 9mo agoThis is one of the very few non-money-laundering use cases for crypto. I would support a “5 cents per unsolicited email” email system, in a similar way. If you make it a mildly enjoyable $5/hour task to read the first sentence or two of your spam folder, the overall internet would be better.