For sure I don't support their decision to ban blind users and hope to see that resolved. But that's not enough to change my mind, not even remotely.
For sure I don't support their decision to ban blind users and hope to see that resolved. But that's not enough to change my mind, not even remotely.
But they have built the perfect shim in the middle to do ALL of these things at some point in the future.
The only thing preventing it is a handful of moral executives, who someday will move on or retire. At that point a smart Wall Street type is going to figure out that a merger between CloudFlare and $adnetwork is going to generate a shit ton of money (think Google+DoubleClick).
I don't doubt that CloudFlare is full of smart well meaning people, but what they have built is a ticking timebomb. The solution is to have ten CloudFlares so that the path between consumers and websites isn't regulated by a single organization.
Edit: to be clear, the internet was successful because any host could talk to any other host. If people did dumb shit you could work around it in creative ways. Even in the most oppressive countries censorship is still bypassable. CloudFlare's business model is centered around convincing companies to effectively disconnect their services from the internet so they only talk to CF servers.
This is hardly a solution, it just spreads the pain around. A solution would be a democratically planned organization, or group thereof, which is responsible to all shareholders including users, employees, executives, and investors.
(And if you wanna be snarky and say "what about your ISP" I can choose to use different ISPs. And even that is getting threatened.)
Which company are we talking about again?
https://www.nbcnews.com/news/us-news/los-angeles-cuts-utilit...
I did say part. Regulation and transparency also help. None are individually sufficient.
The fact is, a number of companies control a huge number of eyeballs. An unethical exec taking advantage of that would cause enormous PR nightmare. If you're making money with a great brand reputation, you don't mess with the recipe.
Juggernaut is unstoppable.
Corporations (beyond a certain threshold of market control) doing shady, consumer hostile things for profit is the norm. So I don't think the ticking time bomb concept is nonsense at all.
As a recent example, Google was an overwhelming net positive for years. They genuinely made the internet better. But the day they went public their eventual abuse of their market position, intentional or not, became inevitable. We're only in the early stages of seeing what that will look like.
Asking questions about whether we want to help give companies the market position to become abusive makes the most sense early, not after it's already happened.
I'm arguing against the logic: "every big company always ends up being a den of advertising evil". Cherry picking examples like Google is not proof of this.
Not every company is Google or Facebook. Is Apple selling its soul to advertisers tomorrow? Is Netflix going to insert ad breaks every 5 minutes any day now? Is Tesla going to have you watch an ad every time you start the car?
Ngnix/Websever-as-a-service is literally their business. They could not have provided the services that they do any other way.
The reality is we live in an interconnected world where everyone uses hundreds of vendors to live and work. There's a certain amount of trust involved, backed by business relationships and the law. It's not perfect but it works just fine.
If you really think Cloudflare is excessively risky then of course you don't have to use it, but it's a strange conclusion to arrive at after looking at their actions all this time.
For example you can drop requests to fbcdn.net (which last time I bothered to check was a good mix of Akamai) and still make a connection to Facebook itself and at least logged in and view HTML.
Obviously ISPs, internet exchanges, datacenters, and clouds operate very differently. But I imagine you know the difference.
My point is that there are lots of vendors with lots of control involved in pretty much every business transaction. There's nothing special about Cloudflare in this regard, in the same way you trust your bank or ISP or power utility or office custodial staff. Risk management is a mature process; no wild conspiracies required.
There are! Cloudflare is by no means the biggest CDN provider - plenty of others exist out there. Akamai, CDNs from Google/Azure/AWS, Fastly, at least.
What makes Cloudflare so unique in it attracting criticism like this? They're just a bog-standard CDN, the likes of which has existed long before Cloudflare. Is it just because they're the most "visible", having a free plan that people use?
They provide me a lot of value right now, for free. If they ever started doing something shady, I trust that people like you would cause enough of an uproar/pushback that I (and other site owners) would find out about said shady activity... and then move off CF.
I'm not as concerned with the what-ifs of what a company could do in the future as I am with their track record so far.
But they will harass your visitors with captchas for no good reason. I also sometimes run into Cloudflare's "this website is using a protection service" with no way around; it turns out it's a geoblock because it does load just fine when I use a VPN through Germany.
The internet was meant to be decentralized. The IP addresses were meant to be used for routing and for routing only, and otherwise treated equally.
The Internet wasn’t meant be decentralized. The ARPANET was meant to be able to function in the event of a war.
Why would a website care where I'm from?
As far as we can tell no one in China has ever bought our product in the ~15 years it has been available. None of our pages are localized for China. If someone in China wanted a product that does what ours does there are Chinese companies whose products are cheaper and probably better for Chinese users.
Yet last time I checked something like 95% of downloads of our product came from China. I took a bunch of IP addresses from the download logs and looked to see if I could figure out something about these downloaders.
All of them seemed to be at hosting companies, not end user machines. Looking at nearby IP addresses to see what else is hosted at the same hosting company they were mostly scam or borderline scam sites or porn sites. The later was a bit unexpected because at least according to Wikipedia porn and any involvement with it is prohibited in China.
I don't see any good reason I should not block Chinese downloads. We have to pay for the bandwidth they use, they are extremely unlikely to generate any revenue for us even indirectly, and they are coming from sketchy commercial IP neighborhoods rather than end users.
Then they want you even less.
In any case, if a company doesn't want to do business with your country, that's it. What matters whether you want to buy it or not? (Not to mention a lot of the abuse towards developers comes from no buying customers as well - people who want some feature added "before they buy", who just use the trial or free version, etc.).
You can always find a competitor company that does serve you.
The other fun part about those captchas is they also gatekeep blind people in a way. They're using a service called HCaptcha which doesn't offer an audio alternative like ReCaptcha does. Instead they give you an "accessibility cookie" delivered to your e-mail address, which you can then use to automatically pass the captcha. (Very useful for everyone btw; give it a try.) The problem is that this cookie--and the e-mail address it's attached to--allow CF and potentially HCaptcha to track you around the internet. There's no way to anonymously browse the net through TOR or a VPN unless you create a throwaway e-mail address for that session.
HCaptcha recently expressed interest in creating a text-based alternative, but I wonder how this will stack up against modern AI. For now, it doens't bother me because I don't encounter it often and I have throwaway e-mail addresses, but it's just one more step I have to go through to remain anonymous where any sighted person could just click the traffic lights.
It is up to you to harass your visitors or not. CloudFlare does not enforce it. You can disable the firewall if you don't want that kind of protection.
We might argue about whether it should come turned on by default or not, but as far as I remember the default setting is not a strict but a moderate protection level anyway.
> But they will harass your visitors with captchas for no good reason.
Be careful with that. To be trustworthy, a party has to be willing and able to act in your best interest.
As a company (or any group) grows, their ability increases, but beyond a certain point, history shows that their willingness to act in your best interest decreases.
For companies and countries this trend often correlates with political and/or economic power being concentrated among a few individuals.