This script also pushed ads for a fake AdBlock app that was a dropper for banking trojan apps.
Amazon refused to do anything about it.
More info:
https://forum.xda-developers.com/t/massive-mobile-advertisin...
This script also pushed ads for a fake AdBlock app that was a dropper for banking trojan apps.
Amazon refused to do anything about it.
More info:
https://forum.xda-developers.com/t/massive-mobile-advertisin...
At a minimum we should demand transparency and accountability from all of these scale-enabling organizations.
Making takedowns automatic on any user report means the dictators take down the apps of the dissidents.
In the absence of AI that would necessarily have to be good enough to also radically change society and the economy, the only solution I can even think of is a big increase in funding for the policing of apps. Who exactly would fund that? Governments would want to use such powers to pursue their own agendas, while Big Tech taking a proportion of App Store income is already being called “[Apple|Google] tax”.
I mean — why is this not obvious? Force these companies to adhere to certain regulatory standards - the minimum of which is transparency and accountability.
Voting with the dollar doesn’t work anymore.
Also, while we are on this subject, your language has some pretty orientalist vibes to it. I wonder who you think created these problems and who feeds them today?
In the olden days of the internet, ISPs that ignored abuse complaints would be blocked by their peers. Now that Gmail and AWS are too big to block, they act with impunity.
How did we get to equating selling tools for murdering journalists to spam in just three comments?
Amazon (and others') pervasive shitty handling of non-DMCA abuse reports seems relevant, however.
Does anyone here know what an individual reporter should do? Is there an escalation ramp that exists but was so poorly marked that neither sloshnmosh nor Amazon support was able to find it? Does the ramp go through other organizations (e.g. report to CERT or some other org first and come back with a case ID)? Does the ramp not exist and need to be built?
Those two things are actually the same thing, both are wilfully ignoring situations like this.
Also, would you take that job?
Some poor support person probably got this and punted because they couldn't pattern match to something in their handbook.
For every thoughtful, detailed security report there are about 500 others that involve voices from appliances, self-xss, csrf on logout and 5G coronavirus. It is extremely difficult for L1 support to make sense of these. Having a support contract or attracting attention on the forums are decent ways to pop out from the background noise.
Hanlon's Razor is a good first approximation or initial approach to a situation, not the end of the discussion. There are many situations where incompetence may appear to be an explanation, but is in fact not the root cause, and may even be being actively used as a cover for malicious actions.
The point of the razor is that it is up to us to sort out the difference, not to just jump to a conclusion that it is malice, or that it is incompetence.
In this case, Amazon has had plenty of time, resources, and skilled people to see the need and implement an escalation & resolution pathway. That they have so persistently failed to do so for so long indicates a cause beyond mere incompetence. Even if they are not being as actively malicious as the malware distributors, they clearly and actively DGAF.
So you are claiming that they have had so many opportunities to do the right thing, that they aren't merely incompetent, but are in bed with the evil doers? That would be a huge claim, to say the least.
The first example is that it's simply more profitable for them to turn a blind eye unless one of the relationships becomes a public problem. They wouldn't be actively aiding and abetting the crime, but neither are they stepping up to ensure that it isn't happening on their systems. It's being complicit several steps beyond incompetence, but not the same level as active cooperation.
And, considering that Amazon has no shortage whatsoever of funds and skilled people to prioritize anything they want to prioritize, I'd say more than sufficient time has passed that they're at least at something resembling this sort of willfully ignorant stage.
Poor communication channels happen even when folks don't want it to. Humans are bad at doing such things.
The CEO publicly broke their policy on this on two occasions: the neo-Nazi website The Daily Stormer, and 8chan. In each case, only after a long saga played out.
For The Daily Stormer: after they mocked the deceased victim of the Charlottesville rally, Cloudflare received public pressure to boot them but refused, and then the owner subsequently tried to troll them/the public by claiming Cloudflare executives secretly supported their ideology, causing them to finally be removed. (https://blog.cloudflare.com/why-we-terminated-daily-stormer/ )
For 8chan: Cloudflare received a lot of heat for not removing them after the first and second incidents of posters becoming mass shooters, eventually removing them after the third mass shooting. (https://blog.cloudflare.com/terminating-service-for-8chan/)
I forget the term/aphorism for this (like "double-bind", sort of), but they put themselves in an awkward position because they're probably one of the most neutral service providers out there - still far more than probably anyone else to this day - but by marketing themselves as 100% neutral, being only 99.99999% neutral created lots of lasting negative PR that people still regularly bring up.
Any other company would've kicked those people off way sooner and there would've been little to no publicity, because they routinely do such things, but now Cloudflare is hated by both the pro-censorship and the anti-censorship crowd. (See: https://en.wikipedia.org/wiki/Cloudflare#Mass_Shootings and everything below. It's quite a rollercoaster.)
They are known for protecting DDoS-for-hire and Cryptolocker services.
Anything that's actively serving malware or phishing pages is removed.
- no longer a dumb pipe, no longer neutral, actually active in directing law enforcement to take you down and possibly take people out.
Link to relative info is posted on another comment (https://news.ycombinator.com/item?id=27884821) - but for those who have not read it, here is an excerpt from a 2019 cloudflare post/statement:
"...what we have done to try and solve the Internet’s deeper problem is engage with law enforcement and civil society organizations to try and find solutions. Among other things, that resulted in us cooperating around monitoring potential hate sites on our network and notifying law enforcement when there was content that contained..."
So I stand by the statement, I can't see any other way to read it.
https://blog.cloudflare.com/why-we-terminated-daily-stormer/
funny how fast things can change.
I believe many of cloudflare's early customers especially felt protected and safe because of the stances - and I bet most don't know about the 180..
I also think most average web people would think if you set 'whatever' for your DNS - that the dns routing is basically a dumb pipe - it's not spying on you and sending copies of your data to gun agencies.
Just as I think most people would not expect their cell phone company or internet provider to spy on data and send snippets of your communications to agents. I would not expect my web server co to deep packet inspect all comms looking for bad things. (not without a warrant and being directed to look at a specific line, now a whole data center / cell co, etc.)
I think it was a terrible choice to make for cloudflare, but I know not an easy one either way.
So 'pipe' is a term that has been used in this way for a while now in similar fashion I thought - and it's not meant literally like a copper water line.
Also in some ways cloudflare has been a pipe - a pipe for flowing data that would be choked by ddos attack if were to try to send/receive across the net in most other ways kinda of.
No response is a response and in this kind of situation it is explicit "I will not do anything and I'm dishonest enough to not acknowledge that.".
Actually "refused" to do anything about it, or didn't respond to you?
I call it a “constructive refusal”.