I understand the position of CloudFlare where they basically don't like governments to block their IP's. On a smaller level this is exactly what CloudFlare is doing. Why is that justified?
I understand the position of CloudFlare where they basically don't like governments to block their IP's. On a smaller level this is exactly what CloudFlare is doing. Why is that justified?
Here's a couple of thoughts I've had about Cloudflare recently;
One is that Cloudflare are a problem because they are self appointed policemen who do not know who the good guys or bad guys really are. Such well intentioned but naive "helpers" almost always cause more harm in the world then they solve.
Another is that Cloudflare do not understand the nature of Free Speech at a fundamental philosophical level. There are two essential sides to it. The freedom to write/speak must be matched by the freedom to read/listen. Cloudflare's model pf the world recasts this as a "tradeoff" and pits the speakers against the listeners. It does this because there is money to be made from "service providers" but none to be made from ordinary internet "users". It robs Peter to pay Paul.
Solving this in a way that doesn't block tons of regular users (since doing so would cause the site owners to drop Cloudflare) is precisely where nearly all of Cloudflare's $15B market cap comes from.
It's not a binary solution. Cloudflare very much does block tons of regular users, which is where all the hate is coming from in this thread. If the solution is in the domain of "a bag or squishy heuristics" it's going to be somewhat inaccurate, so then the only question is tuning... how many false positives are acceptable, which depending on the area could be anything from "how many can you get away with" to ">0 hurts our bottom line".
To reframe the problem in the latter, consider "The optimal amount of fraud is non-zero" [0]. Where it's understood the cost of inconvenience to customers ultimately will also hurt the business's bottom line. So instead the balance is very much in the favour of the customer, to make sure the wheels stay greased businesses eat the vast majority of the fraud where they could employ stricter but slower methods to verify funds etc.
There is this cost benefit balance in many things. Some things naturally balance themselves, especially when the ultimate bottom line is monetary... others not so much.
I suppose the problem with serving requests is twofold: firstly it's not necessarily a business, and even if it is, an individual visor represent a very tiny peace of the pie over their entire life. Second, bandwidth is paid for twice, by both the visitor and the provider... It could be argued this whole problem wouldn't exist if it weren't for the latter. At most DDoS problem may still exist. Either way the ultimate cost is to fairness, people are discriminated arbitrarily. It also depends on awareness of the site owner, if they care about fairness and know the cost of using cloudflare is potentially unfair to visitors, they may not bother... unfortunately I think most site owners don't realise how many false positives there are, and I'm not even sure Cloudflare does, I mean how would they, you get blocked enough you just give in and close the page, and they think they did a good job it's a negative feedback loop.
[0] https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...
If cloudflare actually only blocked bots, a lot of criticism towards them wouldn't exist. Personally, I have some more abstract concerns about the position they occupy, but the primary reason that I emotionally dislike them is because they like to block me and then pretend that it's my fault ("are you sure you aren't infected with malware?").
1. The internet worked fine before Cloudflare, and there was no mass blocking of IPs before that.
2. Websites are commerce based. Their operating costs are already far covered by their income (ads or a service)
3. Cloudflare is a CDN so customers feel no impact from excessive traffic unless their site - which 99% of the time is pure static content - is poorly designed
4. Cloudflare could just choose to throttle the highest traffic IPs to one particular site (the one being attacked) during an actual attack, which is what DDoS mitigation companies do. Instead they just block every shared IP address forever (or force them to solve captchas, which after 8 years of bad implementation, moved from from wasting tons of the users time to being just barely acceptable)
Don't give me any further lectures on how businesses work until you understand how technology works.
It's almost like all intermediaries are responsible for this damn mess.
Nit pick: it's not "actions" impacting others. It's when person A exercises their rights to impede anothers. This kind of argumentation that cloud providers don't provide conduit or extenders for free speech is pretty lost on me, but I'm also of the opinion that all of these services should be highly regulated or government owned so that these silly pedantic, and at times opportunistic, arguments stop. It's become the wedge issue of the internet.
The courts have precedent that would cover this if online speech equals free speech. Part of the reason I want the government to assume responsibility is because it'll either force them to acknowledge they're the same or craft specific laws for online speech. Part of people's frustration is that the rules are all over the place.
> Even if you do, and everyone's in agreement, you're effectively sanctioning off the social media sites to only allow posts from US nationals
That's a silly conclusion. Do US companies only enforce US fraud or sanction laws despite operating in another country? The answer is no. There's regionalization baked into services operated on other regions. I've worked on such services.
Websites, as they globalize, have to do this with regular frequency.
Cloudflare's power fundamentally comes from the good job they do protecting website owners. GP may not like it, but many website owners clearly feel they need the protection.
There is no Grand Moral dilemma here, just basic tradeoffs between costs and availability. No different than a shop not shipping to a country with high shipping costs.
The power came from "free" CDN as loss leader (which is clever because the long tail of readerless sites costs essentially nil to cache but will still bump up the NPS).
A heading called "Lack of transparency with IP blocking"? Let me get my tiniest violin CloudFlare... This is a joke until they stop serving a stream of captchas for some IPs.
I still mourn the fact industry got conned into DoH and funnelling all DNS traffic on "modern" and "secure" apps thru cloudflare's 1.1.1.1
How so? Do any programs force the use of DoH and not let you configure which server they use?
How is that taking control away from a local sysadmin? It'd be a great thing if they did that, since then malicious network administrators won't be able to disable DoH on computers that aren't theirs anymore. If you're really trying to control devices that are yours, you'll still be able to turn it off via local Firefox policy.
1. People who want to censor and/or surveil other people's devices and traffic. These people hate DoH because the entire point of it is to protect against them doing so, and by running over port 443, it's really difficult for them to block it. This is the group that people who say DoH would be a good thing if only it used a network-provided DoH server, or that they wish DoT would get used more instead of DoH, usually fall into.
2. People who have a workflow that it breaks. In most cases, there's some setting or workaround for that workflow that still lets you use DoH for most Internet queries, though.
3. People who say it's making the Internet more centralized or bad for privacy. These arguments are valid to say "don't everyone use Cloudflare as your DoH provider" but not to say "don't use DoH even with other providers", since there's no reason DoH servers have to be any more centralized than regular DNS servers.
This is me, with the caveat being that it's my damn device. It's only the OEM trying to say it's theirs and that I'm "censoring other people's traffic". If I bought it, I should be able to do as I like. If I tell it the DNS server is local and/or that domain is elsewhere/non-existant, I don't want it deciding otherwise and sneaking traffic out over port 443.
Unfortunately, with DoH, this now means that I have to go scorched earth and block all common DNS server IPs at the firewall. You use my gateway to resolve (DNS - 53) or you're out of luck.
I suppose it's only a matter of time before even the cheapest IoT junk just establishes a VPN to its maker's cloud and sends zero unencrypted traffic.
In your specific case, that means that while devices should offer a configuration setting for which DNS server to use, it shouldn't be via blindly listening to the possibly malicious DHCP server.
Because you shouldn't be able to control other people's devices just because they happened to connect to your Wi-Fi. And you don't have to configure them all individually anyway: you can use Group Policy, MDM, etc. to configure that setting on your whole fleet at once.
Why? If it's my network, why should I not have control over all the traffic on it?
2. Why should their workflow be broken so that the dns info gathered by CloudFlare is more valuable to CloudFlare.
3. The argument is that doh through privately owned servers is bad, so I don't know why you tried to specify that only CloudFlare is bad. DoH is, by definition, more centralized than DNS servers unless all DNS servers implement some form of doh. In which case you're not using doh and you're just updating dns to support encryption. If every DNS server doesn't implement doh then you're just adding a few centralized points which have access to unencrypted DNS data, making that data more valuable to the private entities holding it.
Sure, but "CloudFlare can see my data but my ISP can't" is strictly better from a privacy perspective than "CloudFlare and my ISP can both see my data".
> Why should their workflow be broken
My point is their workflow doesn't actually have to be broken.
> so that the dns info gathered by CloudFlare is more valuable to CloudFlare.
Huh?
> The argument is that doh through privately owned servers is bad
How is it any worse than insecure DNS through privately owned servers, which basically everyone uses today?
> DoH is, by definition, more centralized than DNS servers unless all DNS servers implement some form of doh.
Is IPv6 also by definition more centralized than IPv4, since not all IPv4 servers implement some form of IPv6?
> In which case you're not using doh and you're just updating dns to support encryption.
What are you saying is the difference between those two things? And don't forget there's a huge anti-censorship benefit, even if you don't care about privacy at all.
> making that data more valuable to the private entities holding it.
Wait, are you arguing that reducing the number of entities that can access our data is a bad thing, since then our data will be more valuable to the ones who still can? That seems completely backwards.
But that's not really the trade-off here, it's about sharing data with Cloudflare that would not necessarily end up there if you were using services from your local ISP. Whether this is a good idea is more complicated. It depends on how ISPs are regulated and what they actually do with user data. Cloudflare's services, being optional in nature (the website operator or the end user chooses to use them, but not necessarily both at the same time), are likely to be less constrained by law, particularly if you are not a resident of California.
Or put differently, it's far easier to say “you shouldn't have used Cloudflare if you don't agree with their business practices” than “you shouldn't have browsed the public Internet if you don't agree with your ISP's business practices”.
2) I don't see why the workflow should be at risk of breaking if there's no good reason to introduce the new tool. Sure it's possible that requiring an animal sacrifice doesn't have to break their workflow, but why are we doing it in the first place?
3) Fully adopted IPV6 is less centralized than IPv4 since the larger address space allows for centralized layers(like nat) to be removed. IPv6 gateways in an ipv4 network would be more centralized since they would require traffic from many sources to be proxied through a single source.
In the same vein, DoH that proxies many connection through a single source would be more centralized than not proxying those connections.
The difference between DoH and updating DNS to support encryption is that the latter doesn't allow for a "CloudFlare" to exist on top of existing DNS infastructure which has exclusive access to unencrypted DNS data.
> Wait, are you arguing that reducing the number of entities that can access our data is a bad thing
It's a bit more nuanced than that. Adding doh proxies on top of existing DNS infasructure increases the number of entities that are required to access your data while decreasing the number that has access to the data to "number thats needed to function + the proxy".
I'm arguing that the number of entities that have access to the data should be "number required to function" or "everyone", "number required to function plus the proxy" only benefits the proxy because they have exclusive access to data. Data is worth money the less people have access to it, so a solution that sends data through a proxy is rife for exploitation and not the best solution.
Anyway, the fourth category is people who want to own their devices on their network and are being fought by the vendors of their Internet of things devices. When I have dns queries I can build a pattern of what it takes some rando device to operate and then lock down and alert on anything else. Can’t do that with DoH.
With DoH, I just have to allow opaque DNS smuggling to the wider Internet and hope that the device hasn’t been compromised. It’s trivial to run bidirectional c&c over DNS and DoH makes that invisible to anyone. It’s a monumental step back in security for the local network to improve the privacy of the individual device.
It’s completely fine for there to be conflicting goals even held by me. I want to not have my traffic interfered with when I’m on someone else’s network but I don’t want the vulnerable internet of shit stuff to be even more opaque on my network.
In theory, sure, but in reality they are more centralized.
Cloudflare but also others from small to large services justify blocking IP addresses using the basis of "some IPs being a source of too much trouble"... but this doesn't make sense in an internet age of highly NATed and highly recycled IPs.
One IP != one person, anything based on this assumption today is severely broken.
The issue is not blocking of IP addresses, the issue is one company hosting almost half the internet and having too much power causing such unintended consequences.
On the other hand, we rarely can opt out from the government blocking.
I’ve been planning to use Cloudflare for an upcoming project, under the impression that ‘Essentially Off’ really did mean essentially off, and would only block obvious DDoS traffic. I could understand a legitimate user being blocked if they shared an IP with a host actually engaged in a DDoS attack, but short of that, I don’t want anyone being blocked. It sounds like I should look at other CDN options…
If you're using CF for DDoS protection, then blocking and captchas are the features you want to use. Just not abuse.
You run privacybadger? To CF purgatory for you!
There was likely botnet activity in the network - on the users' machines connected through the VPN - triggering anti-DDoS protections.