Cloudflare lobbied FTC to stifle security researchers
twitter.com
twitter.com
Tavis: happy to chat, I've dropped you an email.
Follow up: https://twitter.com/taviso/status/1566159561148362753
When a person employed in the government interacts informally with their friends, relations, acquaintances, the unoffical involvement should stop with "here's the name of the office where you file that complaint" or possibly "my office handles that; send it in through the usual method and I will make sure that I don't work on it". But human nature is to make things a little easier for the people we like or are predisposed to like. That's often harmless. It is sometimes quite the opposite.
The "old boys' network" feels good to the participants but is corrosive to fair treatment.
Lobbying can happen in many ways, and have many different implications. It certainly sounds like it didn’t happen as a result of company/executive action (and at least Tavis believes that), and neither parent, gp or ggp claim so (in fact they agree the opposite is the case).
I rarely have casual discussions with friends working at regulatory agencies that come back to haunt other people. I also don’t think the word “lobbied” was used in a harmful or particularly egregious way, especially considering the context in which it was used (and explained).
Great. But it also sounds like a reasonably common occurrence, and hence a systematic problem.
Speaking up about events like this is hard to do as an executive and I appreciate the honesty here.
Source: trust me bro.
For a Stanford paper documenting Cloudflare widespread involvement in spreading lies see https://ojs.aaai.org/index.php/ICWSM/article/view/19292/1906....
Oh please. These are large corporations, I would honestly be flabbergasted if leadership knew every mundane detail. Particularly in the benchmarking issue you noted, it's pretty easy to understand how that could have been added as legal boilerplate, but just went too far.
Decisions individuals make in large organisations are, on average, downstream of institutional culture, so if a large organisation is responsible for a lot of bad decisions then the leaders are responsible for the culture which made those decisions seem reasonable.
…On a public message board and seems interested in figuring out what is or isn’t happening.
It's possible to be thoughtful and introspective, and try to learn about the things you don't know, but still fail to learn literally everything. We're only human.
This is really naive. Every layer of indirection misses out on details, esp in an organization (public, private, gov, even at team levels).
Surely you understand this basic concept?
Therefore it's completely implausible that even one word written there hasn't been discussed with C-level staff.
Saying the opposite is just throwing PR smoke grenades in the hope some naive people will believe that kind show.
The fish always stinks from the head. (That's why "plausible deniability" is of so great importance to those people, btw).
I think this is just proof that you are not familiar with how C-level responsibilities work at large corporations.
There's an entire wikipedia article dedicated to that: https://en.m.wikipedia.org/wiki/Plausible_deniability
Given the current controversy, it would be much more reassuring to enter an .onion address rather than an IP address, to be entirely sure that servers can't be unmasked. At least not without compromising Tor or exploiting the proxied-to web server.
It’s as if anybody could fall ass backwards into a situation where they built up an organization that dictates what’s on the internet as a whoopsie, and oh no, you too would have to enable harassment, doxxing and DDOS-for-hire because shucks, all that darn unlimited, unchecked and unregulated power, access to money and legal resources is actually the same thing as having no power at all! Poor Cloudflare, they can do literally whatever they want and that means they can’t do anything at all!
Which they wielded their unlimited power to ignore.
The Christians who run my local food bank do similar. Their clients include some of the worst people: rapists, paedophiles, murders - released from prison, with nothing and no-one to help them, other than these kind churchly individuals. Their principle is that Jesus would want them to help their fellow humans in need, no matter what their sins. So they do.
Obviously it's a bit different with Cloudflare as they're a for-profit company of diversely ideological employees, not a non-profit charity of devoutly religious volunteers. But the former type of organisation can run on principles other than making money hand-over-fist too.
That’s what I’m talking about. The “principle” argument is genuinely funny! They have unlimited power but because they’ve chosen to follow an arbitrary rule based on their arbitrary definition of neutrality, they have no power. It’s a coincidence that they enable doxxing, harassment and DDOS-for-hire because they’re religiously bound by a sacred covenant! They dare not cross the ancient gods lest blood and pestilence rain down upon all our heads!
They’re not making a choice to continue enabling harassment, doxxing and DDOS-for-hire, they are simply doing as the sacred runes prescribe, as all orthodox stewards of the realm should and would do. It’s actually noble, we should actually be thanking them for acting this way.
It’s just plain funny.
As for your food bank analogy, do they provide food for active murderers and pedophiles? Like, if they were visited by current victims and the families of victims asking them for help, would they respond with a box of food for the perpetrators and tell the victims to kick rocks?
KF uses cloudflair specifically because it's haters try to DDOS the site.
How about it - you tell me. What reason would so many people, maybe in this thread chain, argue so strongly for a company to revoke its ddos protection of a website they dont like. Its weird right?
It appears you were hoping that they would remove it. What possible reason did you have to hope that a site took away their ddos protection?
Its weird right?
It is weird!
It sounds like CF didn't ban them because of revolting or otherwise commonly illegal content, but actual death threats against individuals that have been reported to law enforcement.
The government, in the united states at least, cannot restrict freedom of speech. Its kind of a big deal. Hoping that corporations revoke their ddos protection so that terrorists can ddos them down is laughable. "I know the government can't do it, but ... just walk away wink wink and I am sure the problem will be fixed wink wink".
Come on.
But USGOV doesn't run Cloudflare. They are perfectly able to pick and choose their own customers without any reference to 1A.
> if a website is hosting content that is illegal
No-one is obliged to service them.
If a group is doing something illegal, the government should act. You seem to imply "Well if they are doing something illegal, people shouldn't have to work with them."
I think you know what I know - they aren't going to be targeted by the government because they are not, in fact, doing something illegal.
Yes but as you surely know, the government has limited resources which precludes them from acting on every illegal act in a timely manner. Which means that groups can, and do, get away with illegal acts for a long time before they get to the front of the queue for being dealt with.
> they aren't going to be targeted by the government because they are not, in fact, doing something illegal.
It is a fact that the government may not target you because you are not doing something illegal - 100%, yes. But it is also a fact that you can be doing something illegal for a long time before the government targets you. You cannot use government inaction as proof one way or the other.
It _sounds_ like you are suggesting that private firefighters should let houses burn down if its something disagreeable.
I have that wrong, I'm sure, so feel free to correct me.
https://www.npr.org/templates/story/story.php?storyId=130435...
In this case, we all appear to have been cheering and begging the private firefighter to just walk away so we can burn their house down in peace.
Nevermind, found it: https://www.washingtonpost.com/technology/2022/09/03/cloudfl...
Cloudflare is quite literally the largest bulletproof hosting provider for bad actors on the internet, and unless you know someone at the company personally takedowns are like pulling teeth.
The problem is what they do is legal, beneficial (because we have a lot of bad people) but not without downsides (again, because it helps some (or the same) bad people).
Since there's no easy way to sort out people and content it's hard to fault them for not doing so.
If what they were doing were 100% bad then it would be politically straightforward to ban it. But we already ban those things.
So what's needed is better systems, models, rules, processes that help with one of the underlying problems (eg. we need to either reduce the number of bad people or we need to get better at sorting content), then it again becomes politically simple to pressure providers to actually do better.
(One of the possible things that could be improved is a better way to do incremental changes. Currently CF can drop clients once, so they are not going take this lightly. If there were other ways to signal to clients that they are doing something problematic that would incentivize CF to utilize that incremental tool more.)
If your complaint is that the host should be the only one to see the full report then your point doesn't stand since Josh pays to have his own ASN so he can personally handle reports for it.
If your point is that only Cloudflare should have the name I don't think it counts as a valid DMCA takedown since it's not like you have a signed document from the copyright holder or someone on their behalf.
How they handle takedowns is important in its own way but completely unrelated.
I propose that anyone who gives a talk about anything first apologize for causing people to perceive them.
If CF didn't offer free DDoS protection - ironically, whilst providing cover & protection to the greatest # of DDoS-4-hire websites on the clear-web - they would have nothing else to offer that would be considered best-in-class
But yeah, they're the preeminent force in ensuring free speech on the internet lol
CF has *no power to censor anyone*
Refusing to provide FREE DDoS Protection, and refusing to FREELY CACHE vitriol, are not "censorship"!
Nor are either of those actions an infringement on any American's rights as defined by the 1st Amendment [friendly reminder that there are nations, other than America, in the world]
Sure - CF are not content moderators ... but, neither are they "a public utility provider" ... they are, however, a *for-profit commercial enterprise*, and as such, they get to choose who they DO, or DO NOT, do business with
If you think any of the sites offloaded by CF deserve the free DDoS protection and caching services CF was providing - by all means, spin up some servers and provide it to them yourself - you have that right.
But not neccesarily, companies are not people they are not protected by the bill of rights and this is already happening when LE forcibly takeover domains to censor them with cause of course. Also, freedom of speech does not include speech made with thr intent and effect of causing demonstrable harm.
Constitutional amendments are so tricky that I'm not sure if just going out to vote is gonna change anything.
>Also, freedom of speech does not include speech made with thr intent and effect of causing demonstrable harm.
I don't think that is a legal standard for the First Amendment. Advocacy of violence is protected speech under the First Amendment.
This is entirely unrelated to the issue of if they should stop offering their services to known Very Bad People. Nothing about current events with CF is related to regulating content.
As a company CF could deny service to KF but then it would be giving power to the vocal dissidents who could seemingly quiet any site they find disagreeable.
As it stands, you can get raided for vuln reporting (doesn't happen a lot because if common sense not law), harrassed, face retaliation and have the vendor silently fix it without crediting you.
For some reason everyone thinks this is a matter to be legislated and resolved by poularity contests (don't use vendor X) and/or capitalism. Which is interestingly why the FTC is even involved I guess?
In an ideal society you wouldn't need such laws and the default is liberty but in this society the only reason researchers are even being allowed to do their job is things like twitter and fears of PR nightmares (which won't work with every vendor/company ).
Tavis seems to have a very dopaminergic personality and I appreciate your position but I feel that (fully and professionally done) responsible disclosure means more than impulsive twitter posting.