4 ms·
> In a phone interview today, Prince emphasized that he has seen no indication that actual malicious packets are being sent out of Cloudflare’s network from the
by devicenull 13y ago
> In a phone interview today, Prince emphasized that he has seen no indication that actual malicious packets are being sent out of Cloudflare’s network from the dozens of booter service Web sites that are using the service. Rather, he said, those booter services are simply the marketing end of these operations.
This is how they justify hosting *booter.com. Personally, I don't see a big distinction. If you weren't hosting the frontend site, there would be no malicious packets going out from other people's networks. These booter sites attack each other all the time, so without DDOS protection they'd take of shutting each other down for us :)
- lstamour 13y agoNot sure how that works. Wouldn't it simply amp up the attacks? It also doesn't address the root causes: DDoS attacks happen because they can. People do these things for social reasons more than profit, when they're easy.
- pktgen 13y agoI agree with you. Having sent multiple abuse complaints to CloudFlare regarding booters, I have found them difficult to work with. As we've established, they will not censor anything; instead, if they determine your complaint to have some level of validity, they will send you to the actual host. In one instance, the booter site had no information on registration or what was offered, so I gave them the hackforums thread where the service is being sold. I realize this is basically hearsay and not sufficient evidence to actually shut a site down, but remember that they won't shut a site down in any case. They did not consider this acceptable enough to release information about the host. They wanted me to register an account there and provide it to them for verification. Luckily, I could register without actually paying anything, providing me a nice UI with a big "launch attack" button, and this was sufficient for them. More recently, they will not even release the site's IP address. All they will do is tell you to email the abuse department of [host] and ask the abuse department to contact them for details. This is ridiculous. CloudFlare purports to be against DDoS attacks, yet has no problem providing service to admitted DDoS attack services. In other words, CloudFlare is a racketeering operation. They create the problem, indirectly, and offer services to solve it. (I realize they offer a free tier, but their advanced mitigation features are only available on paid tiers.)