Flowtrackd: DDoS Protection with Unidirectional TCP Flow Tracking
blog.cloudflare.com
blog.cloudflare.com
Every time I’ve used Cloudflare, it’s been on a dedicated, cookieless subdomain serving static content only. Call me paranoid, but this company may be doing serious damage to our privacy online.
Thats pretty difficult with nearly all web service companies saying 'just put our script in <head>'
It won't leave behind much evidence if you're only doing it for targeted attacks. I doubt NSA will burn such a valuable resource like cloudflare to do mass scale injections.
I have written a mitming proxy that is capable of blocking by ASN (https://en.wikipedia.org/wiki/Autonomous_system_(Internet)), beside blocking domains and other things we are used from the times of proxomitron. I have once tryed to block all 3 companies to see what will happen.
Nothing worked any more. From CDNs breaking pages of those rare occurances where they werent hosted on some cloud owned by those 3 companies. Even duckduckgo wasnt accessible anymore.
The funny thing was that yandex and baidu were still working flawlessly.
Welcome to dark ages of internet, we blew it. Instead of beeing capable of surviving third world war (as it was designed for) it is now in hands of 3 companies out of pure lazyness, lack of knowlidge and greed.
(I will release the proxy in next 2-3 months)
This may be my relative youth, but I don't really recall people complaining that Akamai or--well, I don't know as good an analog to the modern major cloud providers, but maybe, say, Equinix or Rackspace--handled so much of the internet back in the day.
Cloudflare may have more of a consumer brand presence because they intentionally market that with their free plan, branded error pages (the "Intel Inside" of CDN services), and ancillary services (1.1.1.1 and their phone VPN), but it's not like the internet of yore was some decentralized collaboration of freeholder fiber owners running their little own 1-person ISP cum hosting provider. Maybe in the early, early, more academic and hobbyist days, but I don't think it's surprising that those were more of an anomalous landscape after the internet's birth than the norm.
This is a big double-standard here on HN. Everyone hates Google for making decisions on behalf of the internet as a whole; yet Cloudflare has done the exact same thing with a different OSI layer.
I'm not very trusting of Google, but I certainly dont trust Cloudflare any more-so, because they keep things much closer to the chest.
Meanwhile upthread...
> Cloudflare essentially centralizing the Internet is disturbing to me.
Maybe different people have different standards, and HN isn't a completely homogeneous group with a single viewpoint. Just like every other group where individuals are free to express themselves.
>flowtrackd is then able to determine if a packet is part of a new connection, an open one, a connection that is closing, one that is closed, or if it’s an out of state packet.
How?
Which of our claims are false according to you?
Fundamentally the question is about Zones. I personally don't believe "zones" in the modern internet make sense. Modern DNS is not pure-bind/flat file. It's autogenerated labels, managed and pulled from different sources. Fundamentally, answering ANY is at least super hard if not impossible.
I'm sorry you think we were not transparent. I wrote two blog posts, and helped with the draft to promote the deprecating on ANY. But the real push to do something about ANY wasn't us - it was firefox who tried to query resolvers for ANY in order to save AAAA query for IPv6. This is totally bonkers. Proved that nobody understands ANY and that it only brings cost and confusion.
https://blog.cloudflare.com/deprecating-dns-any-meta-query-t...
https://lists.dns-oarc.net/pipermail/dns-operations/2015-Mar...
You have forced changes in the DNS standard based on your own personal value judgment, and Cloudflare was duplicitous in its support of this relative moral position. I could not have made the argument against trusting Cloudflare better, myself.
No, I made a decision that it was time to fix an obscure feature that was impossible to use correctly, and caused real damage to the internet - see firefox ANY saga.
Fun fact. We kept on supporting ANY until the RFC was ratified.
> You have forced changes in the DNS standard based on your own personal value judgment
No, we worked on the standard in the working group. I'm not the one assigning RFC numbers. This is a process.
Later pursuits used different providers where we could use BGP to shift our network around.