https://www.youtube.com/watch?v=wW5vJyI_HcU
Skip to minute 19:35. Then skip to the Q&A at minute 45:00 to hear my response.
https://www.youtube.com/watch?v=wW5vJyI_HcU
Skip to minute 19:35. Then skip to the Q&A at minute 45:00 to hear my response.
Your approach is to try to avoid taking down any content proxied behind a single consolidated service, which is controlled by a single organization and is managed under ASNs and IP addresses assigned to you and under your control.
The approach I prefer is to try to improve the problem by decentralizing control of autonomous systems - putting more ASNs, IP blocks and SSL terminators into the hands of independent operators, which makes it harder for governments to single out organizations for things like, for example, mass scale wiretapping via FISA court orders. ASNs are also previously where legal precedent generally accepted that autonomous service providers exist for purposes of handling legal issues, and are the spot where one's strong control over their "Terms of Service" generally begins (though the IP transit provider will usually set a few anti-network-abuse policies (https://he.net/tos.html), including DDoS related ones, realizing that protecting speech has to be balanced with maintaining the health of the internet).
The point I want to make is that the problem with adding "DDoS-for-hire" sites to your list of protected speech is that it directly harms the latter approach of improving decentralization and diversity of ownership in a way that no other service that has existed has ever done before. By making it so that those independent groups require an enormous amount of routing equipment and bandwidth in order to run their own services without risk of DDoS attacks, or being forced to hide their autonomous systems behind another autonomous system (like yours), I strongly believe that not only is your organization directly contributing to the consolidation problem on the net, but that your organization, by enabling these attackers, may even be the leading cause of it.
I have no problem with your anti-censorship policy. I don't think anyone in here does. I would even defend your right to proxy a terrorist web site. But even IP transit providers make exceptions related to DDoS for the health of the internet itself. If it comes down to a choice between protecting DDoS-for-hire sites and protecting the internet itself, which one is the right choice?
• A site that actively encourages 3rd parties to launch attacks
• A Twitter account that takes requests on sites that people want DDoSed
• A phone number that you can call and request attacks get launched
• A blog that provides instructions on how to launch attacks
• A company that sells boxes that facilitate oppressive regimes censoring the Internet
• The political sites of the oppressive regimes themselves
• A search engine that includes DDoS for hire sites in its index
Agree that if there's something that is per se harmful then the choice is easy. What's hard is that the universe of per se harmful is pretty small.
I personally think the line can be drawn, not perfectly, but pretty comfortably at the point where they are taking payment to execute the attack. In this context, they would either be accepting money with intent to commit a crime, or committing fraud by taking payment to not conduct that activity. Either way, it is highly obvious that a crime will be committed there.
I've seen parallels of this approach in hitman-for-hire stings. Payment for the assassination is usually the point where criminal intent to murder is made - they don't wait for someone to actually be killed to determine if it's "the real deal" or not.
Your follow-up will probably note that this involves law enforcement, and I understand why you don't want to go there. I run a service with 90,000 hosted sites and I run into similar issues all the time. But outsourcing this to public law enforcement to go after is a really tall order. They're simply not going to have the resources to approach this problem. And even if they do, they're being expected to focus those resources on the more "critical" issues of our time (terrorism, murder, etc).
There is also, IMHO, a general understanding that (forgetting the illegal NSA dragnets for a moment), as a trade off for government generally leaving their hands off the internet, we police ourselves voluntarily in situations where it's necessary for the network to function. Up until now, we've done a pretty good job at that. After watching DDoS attack capabilities triple within a year, I'm not so sure anymore.
I fear what might happen if we cannot figure out how to come together to take on the DDoS problem (for everyone, not just a few large autonomous organizations), and we start to see more government intervention in this space to address the problem. Any such legal intervention would likely also contain a bunch of wonderful earmarks by the lobbyists-of-the-moment, further constraining our ability to provide people with free speech protections.
Anyways, I'll stop here because I think we've both made our points. I don't think it's as blurry of a line as you do, but I agree that it's a blurry line. Thanks for chiming in.
I appreciate your concerns in the sense that the web is no longer decentralized. You might be interested in http://zeronet.io/, which is at least an interesting attempt in encouraging decentralization. But let's face it. Cloudflare is hardly forcing the rest of the web into centralization. They're just helping to protect people that sign up for it, regardless of who they are. They're not here to judge who stays up or not. I feel like that is more in the spirit of the internet than anything.
If Krebs worked with Cloudflare when they had made their offer, I don't think his website would have been down. He's using Project Shield now. And that's fine too.
And I can only combine his direct insults on stage (Whereas Krebs was directed at the service, not the man) with CF's insistent take on Tor. They are a bad actor, bar-none.
Interesting. Do you have a source for that? I'd like to check it out.
____________________________________________
Yes, you can see Brian's critique of us here:
https://www.youtube.com/watch?v=wW5vJyI_HcU
Skip to minute 19:35. Then skip to the Q&A at minute 45:00 to hear my response.
____________________________________________
He repeatedly badgers Krebs on "why didnt you respond to my emails to meet", to the point they nervously laugh/cough on stage.
"Who needs to actually ask questions, as a journalist?", said eastdakota (https://youtu.be/wW5vJyI_HcU?t=2887). This was what got me. I expect better composure from a CEO than childish and churlish jabs.
(edits were purely for formatting and separating eastdakota's writing from mine.