7 ms·
CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article. "CloudFlare, which offers con
by qeorge 12y ago
CloudFlare is probably not a good choice. They recently blocked access to a similar service, Lantern, per the linked WSJ article.
"CloudFlare, which offers content-delivery network services, said last week it cut off Lantern’s use of the service, saying it was unauthorized. “We don’t do anything to thwart the content restrictions in China or other countries,” said Matthew Prince, chief executive of CloudFlare. “We’re a tech company and we comply with the law.”"
http://www.wsj.com/articles/u-s-cloud-providers-face-backlash-from-chinas-censors-1426541126 http://www.wsj.com/articles/u-s-cloud-providers-face-backlas...
I'm not very impressed. Maybe someone from CloudFlare is around to defend that position further.
- pktgen 12y agoLOL. Booters (that carry out DDoS attacks which are illegal in CloudFlare's own country)? No problem for CloudFlare. Trying to circumvent Chinese content restrictions? Nope, that's unauthorized!
- throwaway20434 12y agoYep, it's hilarious. Cue Mr. Prince to come in here and give a half-assed explanation as to why it's not actually a contradiction, even though it clearly is.
- diminoten 12y agoForgive my outburst, and maybe this sentiment won't be well received given the context, but I just find it to be downright unpatriotic for a US company like CloudFlare to stand there saying things like what Matt Prince says in your quote, when someone comes under attack by an opposing nation state. Again, I realize this place isn't exactly a bastion for this kind of sentiment, but have some thought for freedom here, CloudFlare. The US may suck at helping a lot of the time, but if you've got a group of folks trying to deliver some good ol' freedom to a country like this, and that country is trying to shut them up, maybe put out a helping hand, or at least don't shut off service. Come on...
- AYBABTME 12y agoNot everyone desires to take part in geopolitics and become a tool of diplomacy. Some people just want to do their business and it's perfectly fine in my opinion. You can't force people to be patriotic or to feel a patriotic call.
- notsony 12y agoFrom the FAQ: > Due to the sensitive nature of the content on our web sites we prefer to remain anonymous at this point If they want help they need to be transparent about who they are and what their objective is. One man's tool of diplomacy is anothet man's... etc.
- MichaelGG 12y agoI worked with a DDoS protection provider briefly. Suffice to say, it's quite possible that being public with identity can bring a significant chance of physical harm. Dunno about this particular case, or China, but for other people offering services to that continent-area, they had real concerns.
- mauricemir 12y agoAh freeriders
- deleted 12y ago[deleted]
- gclaramunt 12y agoI got confused, are you talking about bringing freedom to the US ? :) Kidding aside, not saying you're wrong, but companies that want to maximize profit take a too big of a risk alienating a possible big market...
- eastdakota 12y agoThanks for the feedback. In the case of Lantern, they were taking advantage of a bug in our system. Specifically, they were setting the SNI field (outside the encrypted packet) of a request to look like it was going to an actual CloudFlare customer (e.g., news.ycombinator.com) and then setting the host header inside the encrypted request to point to some restricted site. The bug was that we did not check that the SNI field matched the host header, which allowed Lantern to do what they were doing. Lantern was not a customer of ours, instead they were exploiting this bug to essentially disguise traffic to look as if it was coming from one of our actual customers. One of our biggest concerns was that this would put CloudFlare's actual customers at risk of being blocked. And, beyond that, even if it weren't being used to avoid Internet restrictions, that someone could effectively impersonate the identity of a customer on our network is, per se, a flaw that we should patch. As soon as we became aware of the issue, we began matching the SNI header to the host header and, effectively, patched the bug. We've always been very supportive of a free and open Internet. However, even if we support what someone is doing, we can't put our current customers at risk of collateral damage or keep open bugs that allow our network to be exploited. Matthew Prince Co-founder & CEO, CloudFlare @eastdakota
- at-fates-hands 12y agoThis is actually pretty eye opening to me considering they tout themselves as a top notch defense against DDoS attacks. I might have to reconsider mine and my clients choice of providers for this very purpose.
- deleted 12y ago[deleted]
- hackuser 12y ago> "We don’t do anything to thwart the content restrictions in China or other countries," said Matthew Prince, chief executive of CloudFlare. "We’re a tech company and we comply with the law." There's a popular idea that businesses (and people) have no responsibilities to anyone but themselves, because what they have is theirs; they built it themselves. But if you think about it a little, it's obviously false. Here's a more accurate statement: We're a tech company whose success is completely dependent on the freedoms in our nation and many other nations around the world, and on the political and economic systems, infrastructure, and enormous wealth that blossomed from them. Without the sacrifices of blood and treasure by our predecessors of hundreds of years, and of many people today, we would not have these resources or opportunities today. There are many talented people born in many countries who, without these benefits, have no opportunity for success. They can't sacrifice their company for every principle, every time, but there's a middle ground between that and 'we're just a tech company so we have no responsibilities'.
- toomuchtodo 12y agoThat's an optimistic view. My take on it is "market share|revenue > human rights". EDIT: It turns out Lantern was using an exploit at Cloudflare [+], and wasn't a customer. My apologies /u/eastdakota. [+] https://news.ycombinator.com/item?id=9234367 https://news.ycombinator.com/item?id=9234367
- LLWM 12y agoWhat counts as human rights is subjective. The UN says that it is a human right to receive and express opinions through any medium. Does that mean that we should hold "human rights" to be more important than revenue and forbid service providers from charging for access to information? Like the WSJ who wrote the article that's supposedly to blame here?
- deleted 12y ago[deleted]
- 1ris 12y ago
- chishaku 12y agoI imagine it's more about calculated self-interest than it is taking a political or moral position.
- riobard 12y agoWhat do you expect? One third of CloudFlare's planned data centers are in China [1]. It's commercial suicide to not comply. [1]: https://blog.cloudflare.com/one-more-thing-keyless-ssl-and-cloudflares-growing-network/ https://blog.cloudflare.com/one-more-thing-keyless-ssl-and-c...
- gscott 12y agoSimilar to not comply with the wishes of the United States. Qwest communications didn't comply with the NSA wishes and are now out of business. http://www.businessinsider.com/the-story-of-joseph-nacchio-and-the-nsa-2013-6 http://www.businessinsider.com/the-story-of-joseph-nacchio-a... Same thing with anyone who operates in China. The only difference is China is more transparent with their demands.
- jgrahamc 12y agoI'm not very impressed. Maybe someone from CloudFlare is around to defend that position further. Response from CloudFlare's CEO here: https://news.ycombinator.com/item?id=9234367 https://news.ycombinator.com/item?id=9234367
- throwaway20434 12y ago> I'm not very impressed. Maybe someone from CloudFlare is around to defend that position further. That's really rich, considering CloudFlare happily takes money from booter services. These guys are scum, I have no idea why HN fawns over them.
- LLWM 12y agoBecause they provide a useful service and do it well?
- sinak 12y agoHistorically Cloudflare have been quite strong in their support for free speech. For example, they run Project Galileo to protect public-interest sites against DDOS attacks: https://www.cloudflare.com/galileo https://www.cloudflare.com/galileo I'm guessing in this case it's simply a case of them choosing which battles to fight. They probably don't want to commit to run an open proxy for everyone in China to access banned websites. That would likely get them banned outright in China, which, for a CDN like Cloudflare, would really hurt their core business.
- Matt3o12_ 12y agoThat's funny, cloudflare has a project to "Protect Free Expression Online"[1]. It even states: "Often these attacks appear politically motivated — going after, for instance, citizen journalists reporting on government corruption. The promise of the Internet is that it is a great leveler — that anyone with an idea can reach a global audience. These attacks threaten that promise." [1] https://blog.cloudflare.com/protecting-free-expression-online/ https://blog.cloudflare.com/protecting-free-expression-onlin...
- irascible 12y agoExcuse my ignorance.. is it really the case that website a gets ddosed, website a gets charged by amazon for the ddos traffic... and amazon isn't inclined to mitigate the attack? Will wonders never cease......?