Austrian ISPs Block Cloudflare IP addresses after apparent court order
netzsperre.liwest.at
netzsperre.liwest.at
https://yandex.com/search/?msid=1661717771857485-52510224241...
My understanding of Yandex was that it's just another user-information-is-primary-income search provider this time HQ'd in Russia, neither of which exactly appealing to the typical DDG crowd.
Though I'd throw Kagi out to anyone who puts a lot of weight on such things as being a more pure example than either.
Do you have a source for this? I'd be interested in reading the technicals of merging search results from multiple sources.
A Russian company having my data given the current state of relations between it and my government is less worrisome than Google having the same.
That said, this has nothing to do with ads. It's a matter of foreign intelligence.
Compare vs AllSides https://www.allsides.com/unbiased-balanced-news
On politically sensitive content here's an example I've shown before of how a search for "Trump" might differ between Google and Yandex, https://imgur.com/oPXP0wh If searching for controversial figures or organisations you'll find Google tends to return news articles from left-wing media outlets where as Yandex tends to just return links associated to the individual / organisation. You can see this difference for yourself if you search for individuals like "Alex Jones".
Other notable examples would be extremely controversial content that Google / YouTube hides from results or removes completely. So for example if you want to find various alt-right / extremist content you basically need to use Yandex at this point. I'd rather not share specific examples of this, but as someone who's interested in online extremism if you want to view source materials you'll quickly find you need to use alternative search engines like Yandex to find this. There are also examples I'd consider extremist-adjacent like discussions around race and IQ or immigration policy which tends to be fairly one sided in Google. You will find some diversity of opinion but because Google downranks a lot of the more controversial sites the conversation is certainly biased towards what's political acceptable. I'm not necessarily criticising Google for this by the way, I'm just saying it's something that Google does and you should be aware of if you're ever searching for things considered politically incorrect.
I'm also aware of examples where Google searches tend to be more "diversified". This isn't something I've noticed or am that concerned with personally, but I'm aware of people who feel Google biases search results for things like "white families" to show more interracial families while Yandex doesn't. And I think there are examples where you can search for things like "famous scientists" and get more women scientists in the results than you might expect. From what I've seen I think this can be explained in good faith and isn't necessarily evidence of Google tampering with the results, but I've seen people (mostly in alt-right circles) share cherry-picked examples (in my opinion anyway) of stuff like this.
However since those are Cloudflare addresses there is a ton of collateral damage.
It's a strategic fact that they use to their advantage, not their ultimate evil goal to make your life worse eventually.
I think we're quite spoiled with how much we benefit from their economy of scale.
Which is exactly what Cloudflare wants and has planned all along.
The idea that it's all planned and was a strategic bid to get into a stable business position and so on...P.S.: I'm not serious, of course.
Nope, you are totally wrong; they are immune by US law.
AFAIK, CloudFlare removed only a handful of sites, but protected 100s - 1000s.
The historical purpose of safe harbor was to allow AOL to have a walled garden without become responsible for all the illegal content that snuck past.
IANAL, but DMCA safe harbor doesn’t really apply to a companies like CloudFlare, nor is it needed, because they are not moderating UGC on a publishing platform, they are a routing optimization utility.
Content moderation is covered by the CDA section 230; completely separate from the DMCA
And it 100% should apply to Cloudflare as well; if they're caching copyrighted material they need to respond to takedown requests or lose that safe harbor protection. Just as it applies to Google for indexing alleged copyright material; if you've ever seen that "links removed due to DMCA takedown notices" in search results, even when they are not hosting said content.
IANAL also, and I don't know how much DMCA stuff is handled cross borders (I do believe some DMCA provisions are applicable thru trade treaties and the like, but not sure); and I do think DMCA takedowns are rife with abuse; but content moderation really has nothing to do with it..
Edit: btw, the domains added with date August 29 are already blocked in Germany and some other EU countries for a while: https://onlinefilter.info/cuii-dns-sperre/newalbumreleasesne... .
There is definitely a good amount of collateral damage, not all ISPs rolled out the block already, but some did.
I myself noticed a lot of sites stopped working or fail to load scripts/external resources. On reddit r/austria there are also multiple complaints.
Most normal users probably just suspect their router/pc acting up. It took me a day too to get to the gist of this issue with sites not loading without tor.
Only media backlash and a shitstorm actually was able to correct this and it is unclear if all providers fixed this. Everyone is now blaming high court decision, local government and the EU. Wonder if anything will change.
Here is the verified story :https://www.derstandard.de/story/2000138619757/ueberzogene-n...
Some people played this kind of game with Internet censorship in Russia.
If they really are having to block actual ips I would be surprised
I’m just wondering about this as Austria historically has been very lax about falling for demands of the intellectual properties bullies.
Edit: I see it’s mostly Austrian film makers (some great ones in there to be fair) and Elsevier (yikes!) behind those takedown attempts.
https://www.bleepingcomputer.com/news/government/russia-bans...
Fun(and very disappointing) talk in German about their fuckups during the pandemic: https://media.ccc.de/v/gpn20-12-die-unterhaltsamsten-sterrei...
I suspect that most anti piracy groups are now moving to long game by increasing the difficulty in getting to piracy websites rather than blocking them. I remember significantly more seeds on popular torrents in 2014 compared to now. I think this is a mix of streaming services as well as complexity of piracy.
I do take solice in the fact that piracy will act as a disruptor in unruly markets. Advertisement breaks in streaming platforms, increased cost per service or service fragmentation and other user hostile activities will increase the rate of piracy, creating a balance between good and unscrupulous.
Isn't this a bit like taking the phone numbers out of the phone book? Sure, people can't easily look them up, but if you know the right numbers, you don't need that.
Or is there more than that?
Source: I have been worked for an ISP and I was in charge of that.
Is this done simply by intercepting UDP port 53 requests somehow? I've only ever had to intercept https as part of development, but have no idea how this would work for UDP. Any details you can share?
Naturally, a lot of HNers hate encrypted DoH which solves both the active MITM and passive monitoring problems. Example: https://news.ycombinator.com/item?id=25344358
I’ve worked for several who didn’t. Of course all have the ability to do just that so as a user you can’t tell. If you’re in the EU they can’t sell that data at least.
To make matters worse, they engage in gratuitous blocking; for example, they won't resolve addresses of private networks (192.168.x.y, 10.x.y.z, etc...). For example, 192.168.1.1.nip.io won't resolve on my mom's network, but will almost everywhere else.
The solution, as another poster pointed out, was to use DNS-over-TLS.
That's called "DNS rebinding protection", and it's meant to protect against DNS rebind attacks (https://en.wikipedia.org/wiki/DNS_rebinding).
If it isn't a shared IP, your own browser will block it because of a cert mismatch.
The best way to do this is to update your own /etc/hosts file to point the domain at the correct IP.
https://help.dnsfilter.com/hc/en-us/articles/1500008110182-transparent-proxying
It's also good to know that many newer browsers aren't affected since they've started to enable DoH out of the box (at least that's what firefox has done).Anyway, other programs on your system may be affected too so addressing the issue at the system level is also important.
the courts order blocks, the ISPs block it at dns because it's cheap and easy and pirates are either scared off by the warning message or just use Google dns
It's good enough and mostly non disruptive
Stay classy, "free" societies.
The people who didn't know about these site before probably didn't practice piracy at all anyway, so having this list of blocked websites won't help them now anyway as they can't access them easily now anyway.
So IMHO these blocks mainly work at stopping Average Joes from accessing low-friction, low hanging fruit piracy and annoying them enough that they'd rather give Netflix 12 Euros than learn how to bypass these annoying restrictions.
So blocks like these will definitely discourage more Average Joes from low hanging fruit piracy and keep them as law-abiding paying customers rather than turning them into "hackers".
But as an Austrian myself, piracy was alive and well when I was in the age group where that usually happens and many "regular" people used free streaming sites when kino.to and others were still popular.
The libraries of streaming services are tiny compared to international offerings and some don't even offer anything in Austria at all because it's a small market.
Pirating is still alive and well, not necessarily because people can't/don't want to afford the alternatives, but because they just aren't as convenient.
Low tech wages and archaic working practices, stuffy bureaucracy, cash and physical paperwork needed for many things, poorly developed, expensive and slow internet infrastructure, corrupt and idiot politicians who don't understand the modern technology sector, litigious politically connected companies who sue anyone they don't like and lobby for anti-consumer laws that only benefit their cartel, privacy regulations taken to the extreme which mainly protect the crooked and unlawful people and businesses from being known to the public, etc.
This news isn't surprising to anyone familiar with Austria and these intelectual property bullies from the list of companies that got the Austrian court to block those IPs is just the tip of a huge shitty iceberg in Austrian tech & politics.
Sure, life is good here, if, you're not a tech worker, and that sector become more and more important in generating wealth, skilled jobs with a future, attracting skilled immigrants to pay taxes, and to project influence and soft power globally, that's why so many smart but not necessarily rich countries jumped to take advantage of this new sector (China most famously).
So a high GDP per capita might not save you in the long run if every ambitious tech graduate is leaving your country to Switzerland, London, Germany, Ireland, SV, etc. for a better environment where they can grow their career and earn better salaries, which leads to most tech products and web services used in your country all coming from abroad because your domestic tech industry is shit since your country got complacent and decided to sleep through the tech revolution with the idea that you'll "be fine since we're 8th GDP/capita in the world".
Edit: Okay i tried a few links now - many show a „this domain is for sale“ page, while some work - so I dunno what to do with that…
Some cloudflare worker page are also not loading correctly. A reply I got on twitter pointed out that you cannot load urbanarrow.com from Austria properly (for me it gets stuck after language selection).
Also you are more likely to see failures if you are only using IPv4 as some hosts also answer to IPv6.
*Fixed
But I'm baffled at the Oxford definition returned by Google: "having the strong flavour or smell of game, especially when it is high". There are very similar definitions that use "tainted" or even "spoiled" instead of "high". I think I'd rather my roo steak tasting of marijuana than of rotten flesh.
Also failures won’t happen if you have an IPv6 connection and it can connect that way.
I don't know whether the DNS is being resolved first, but in the url it's listing the IP: http://www.ukispcourtorders.co.uk/?JNI_URL=104.21.36.27/&JNI... ...
My DNS is Quad9 over TLS.
it doesnt matter what the issue is behind this blocking, it matters that we have no safety nets for gov blocks on thought.
Bandwidth is prohibitive expensive there, and as such - Cloudflare has routed around Australia resulting in much higher latencies.
Australia has pushed for tech companies to install back doors into user data. [1]
Now this.
[0] https://medium.com/@SimonEast/the-declining-value-of-cloudfl...
[1] https://www.accessnow.org/closing-backdoor-australia/
EDIT. I have to laugh at myself. I misread this as “Australia”, not “Austria”. Doh.
I feel we need to get someone on clearing up this mess of confusingly named localities.