i think Schneier likes this analogy, he has used it before:
https://www.schneier.com/blog/archives/2012/12/feudal_sec.ht...
He then calls for the state and the law to protect us from our overlords; now that was all written before Snowden (the presnowdonian period)
Still nice that google does this hosting + ddos protection work; they could have chosen not to do it.
It's fairly easy to evade attribution, let alone apprehension, if you're a ne'er-do-weller with a broadband connection. You have no option left but to hide inside rich people's castles.
John Gilmore, an American entrepreneur and civil libertarian, once famously quipped that “the Internet interprets censorship as damage and routes around it.” This notion undoubtedly rings true for those who see national governments as the principal threats to free speech.
However, events of the past week have convinced me that one of the fastest-growing censorship threats on the Internet today comes not from nation-states, but from super-empowered individuals who have been quietly building extremely potent cyber weapons with transnational reach.[1]
and also:
But as my friend and mentor Roland Dobbins at Arbor Networks eloquently put it, “When it comes to DDoS attacks, nation-states are just another player.”
[1] https://krebsonsecurity.com/2016/09/the-democratization-of-c...
As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289
* Cloudflare has a growing number of competitors, like Incapsula.
* These services only protect the front-end of the booter websites. These are barebones CRUD apps for managing accounts and typing the IPs you want DDoS'd. It'd be pretty easy to throw that template up on any other server or domain. Most of that whole workflow could be replaced by IRC, Slack, Discord, Skype along with Bitcoin or similar payment methods. As proof, booter sites do still regularly get DDoS'd (usually by exposing their origin server IP or otherwise fucking up configuration) and breached (often exposing the entire user DB and source code) yet pop back up within a few days and still retain most of their customer base.
* They could just move everything to a Tor hidden service, or the equivalent to I2P.
It's the botnet and/or list of IPs and URLs (scripts and shells on compromised servers they planted or paid for access to) that serves the foundation of booter services. If that remains untouched, then the booter can stick around indefinitely.
Cloudflare's CEO reiterates the same points here: https://news.ycombinator.com/item?id=12577690
As for whether they have a moral obligation to stop reverse proxying these sites... I think he makes a pretty good argument for why they should be considered a common carrier. They do forward all abuse reports to the respective hosting providers.
Sure, chase down how they do payment. But ultimately a web front end isn't the thing that makes the payment happen.
The "brochure" argument makes 100% sense to me for something like the distributed web, but not for a dynamic web application. Brochures just sit there and look at you. Brochures don't take payments and process callbacks, and send commands to attack.