The only other beef I can think of against CloudFlare is how they play both sides of the DDoS game, hosting the sites selling them (free speech!) and charging the victims for protection.
PS. CloudFlare does deserve some flak / second thoughts for the whole Cloudbleed thing, but I don't think your response is quite on target.
It's unusual to see someone accused of blatantly lying on HN and I put my alternative interpretation out there to hopefuly temper that opinion a bit.
As you mentioned, the end result is pretty much equivalent since all we have is the completely wrong output.
I would differentiate that from lying, and fairly, he gets to deal with the consequences either way because he is the CEO.
What if a booter site advertises itself and says "you must confirm you have legal authority to run an attack test against this site"? What if it's legal in <some jurisdiction>?
CF should only take down sites after getting a direct court order to stop services (even then jurisdiction is an issue).
Your comment seems to fairly accurately reflect CloudFlare's position: Thoughts on Abuse | https://blog.cloudflare.com/thoughts-on-abuse/ (2012)
Here is a semi-recent take from one of their more vocal opponents: Spreading the DDoS Disease and Selling the Cure | https://krebsonsecurity.com/2016/10/spreading-the-ddos-disea... (2016)
Here is how it works out in practice for a few fellow HN-er's: The New Normal: 200-400 Gbps DDoS Attacks | https://news.ycombinator.com/item?id=7242377 (2014)
So this jurisdiction issue actually goes both ways.
I would have been happy to give him the benefit of the doubt and still would. To me it seems to me he continually repeated these claims over the whole incident and ignored people who pointed out that what he was saying was obviously false. I only pointed to the most egregious example.
To be clear, I'm not super worried about companies just screwing up, shit happens. However, I have a personal bias against dealing with people who are dishonest when that happens.
Thanks for following up!
When Anonymous ran some anti-ISIS operation, they accused CloudFlare of "hosting" dozens of pro-ISIS sites[1]. It turns out Anonymous was entirely wrong about the CloudFlare customer sites (confirmed by DHS) and hypocritical (because CloudFlare tried to remain content-indifferent and, as such, protects lots of Anonymous sites). But their image took a spanking for it in the news, despite (1) investigating the claims, (2) contacting DHS to confirm they were in the right, (3) having a rational counterargument (even if it wasn't as simply as "TERRORISTS!!!!1!!1one").
Remaining quiet isn't the solution either. @eastdakota was actively corresponding with the HN community while his security+product teams were actively mitigating the "CloudBleed" damage.
Sometimes you will lose the news cycle, even if you are in the right and did everything right as a company should.
[1] https://www.theregister.co.uk/2015/11/18/cloudflare_ceo_rubb...