IP address blocking banned after anti-piracy court order hit Cloudflare
torrentfreak.com
torrentfreak.com
The level of desperation the ISP’s engineers have felt in front of such incompetence must have been through the roof. I am getting tired of our politics here in europe: tech literate people in governments are put to work on surveilance stuff, never for actual policymaking.
The shit show continues.
If I was an engineer there I would block the addresses and call it a day. What do I care? After all it's customer service who will deal with the angry calls.
Of course it could be an accident, and you didn't know. But if it was clearly malicious compliance, personally and I think I speak for many, I wouldn't continue to have on the team somebody with these kinds of traits.
for context, i didnt experience this yet. I hope i never do.
The job if the engineer who notices this is to raise it to their boss and legal counsel and let them decide whether you should still execute the planned block or not. If they decide you should then you do, if they decide you shouldn't then you don't.
...shouldn't the legal department be involved way before the issue reaches the engineer? Why should the engineer ever care about it in the first place? Chances are these orders do not come directly to their email.
Possibly, but the legal department might not know what cloudflare is or the implications until the engineers explain it.
Then that engineer looks at the specific IPs and realizes that some of them are cloudflare ips and the collateral damage of blocked content would be significant. Their job is to then escalate and pass it back to higher managers and the legal department to confirm they knew about that implication and want to move forward.
The legal department at the isp having specialists means that they could understand this situation in a single email from the engineer, not that they obviously have the foresight or capability to even find out that some of the IPs might be for cloudflare. Or sometimes the lawyer might even assume that's not a big deal but higher managers can realize that it is a big deal and then discuss options.
All that I mean is that even at FAANG companies with extensive and competent legal departments its not correct to just blindly execute a change like this if you think it looks wrong; it's not at all a safe assumption that what you know is somehow a subset of what they know.
Let them be hoisted by their own petard.
CF will probably retort {common carrier, we are American and you are not etc}. Austrian policy makers get upset and ... THIS NONSENSE IS STILL NOT SORTED.
The internets are somewhat broken, quite badly. We all allow ourselves to end up in a series of virtual walled off silos - Facebook, Twitter etc, run by some pretty worrying monster commercial companies, whilst living within quite disparate physical societies. I think that the fediverse is a possible contender for the way forwards. I dumped Reddit for Lemmy and that seems to be working so far. I know a lot of 'X'iles are finding a home with Mastodon.
I worry about quite a few networks. One of the tools in the box is the IP block list. With the rise of the hyper-scalers, the IP blocklist is becoming increasingly useless. Same with SMTP filtering for spam. You can't block M365 or Gmail en-masse (tempting for my home setup, though!)
I recently gave CrowdSec a run at work (I will stick with it but with care). Great idea for the 2010s but not so much now. I got it to watch HA Proxy logs (proxies on site Exchange) and it pretty soon decided that my real users should be banned because of how Outlook works, or rather how the auth that Outlook uses works. Outlook doesn't just use Kerberos, it also uses EWS for the Addressbook and the good Lord knows what else. So you get a connection to a endpoint from Outlook without auth creds which generates a 401 (failed auth) error, then Outlook tries again, this time with creds and it works OK (200). To a CrowdSec agent those repeated 401s look like bots pissing around.
That is one reason why we cannot have nice things.
I'm a Brit (yes we Brexited) but I am still very much a European and so is my little country, like it or not - I have seen shed loads of number plates from across the EU trundling along the large A30/A37 crossroads/roundabout called Yeovil in Somerset. Mostly lorries and quite a few cars and campervans.
So I am from country X (GB in my case, not that X!) but I engage with (w,x,y,z) societies on line. Now whose laws apply? In general it seems we muddle along effectively but should there be a formal internationally accepted agreement?
401 indicates it should send it's kerberos ticket.
Kerberos verifies it should send a ticket, then sends it.
200 cause you are now authenticated.
401 does not indicate anything apart from authentication failure. Bear in mind that I am trying to parse logs to decide what is happening.
I'm no expert but I suspect that http works a bit like this:
C: hello web server S: yes I exist and I speak the following languages: lol, rofl, powershell (on thursdays) C: cool, let's talk lfor and I will sacrifice my first born child and give you my wallet S: no chance, but I speak lol and thank you for your wife C-S: witter on in "lol" for some time. <cat memes flow regardless>
Kerberos has overloaded how auth should work and inadvertently fucked up log processing. Actually I think it is really NTLM. It goes in with auth instead of hello.
Considering how quickly they reversed course on their grand statement about having principles, any such retort would probably be about as effective as they predicted in that statement.
.
> The internets are somewhat broken, quite badly. We all allow ourselves to end up in a series of virtual walled off silos
The problem with the Internet is that between nat and annoying rules and asymmetric connections, most home connections aren't suitable for serving things.
The big services being centralized isn't a problem with the Internet, which can be seen from how often non-Internet things consolidate the same way.
Foreign licensed vehicles can operate and drive in the UK for up to 30 days without applying to the DVLA (DMV) for UK registration.
However the UK government has never subscribed to any of the available EU crime and general population administration data sources which has always left the UK vulnerable to overseas criminal activities concentrating here because there's obviously no reciprocating return of information to the continental authorities either and so the UK has become the best place to let the law slip if you're up to no good in Europe.
Edit: slip not slop
... Being able to talk to someone without an intermediary is a problem?
> That doesn’t mean governments don’t have the right to regulate content on networks in their boarders: they absolutely do so long as they follow principles of Rule of Law.
Pretty sure governments have the right to do whatever they want regardless. It's that pesky "sovereignty" thing.
> But blocking on an IP can never be transparent
What do you mean by this?
And the funny thing is that their blog post complains of the following:
> In a deeply troubling response, after both terminations we saw a dramatic increase in authoritarian regimes attempting to have us terminate security services for human rights organizations — often citing the language from our own justification back to us.
Well, yeah. That’s what happens. It’s just a lot easier to justify something you wanted to do already, isn’t it?
It’s particularly effective if the rules are a large part of their collective grievances with management, as it highlights to all involved that the current rules need changing, and can sometimes result in fairly quick and positive changes since it demonstrates to management that the current “rules as written” are not the most fiscally effective set of rules for running the business.
here rules are cretinous to start with
I certainly wouldn’t expect to see it in the real world, I was mostly just musing on ISPs deploying/leveraging their layer 7 gear if required.
Fortunately, CF is great at providing DDoS protection and adaptive WAF services; which should incentives other website owners to keep using CFs services. And even better, now it cannot happen anymore because it violates (whatever is left of) net neutrality- awesome.
It is adorable that at this point people still believe collateral damage will prevent a political move.
> “With regard to the blocking of access to the IP address 190.115.18.20, the Telekom Control Commission found a violation of Article 3 Paragraph 3 of Regulation (EU) 2015/2120, because the IP access block poses the risk of ‘overblocking’ any website content.”
Thank god for net neutrality. We of course have that here in America right? Cus freedom!
https://www.multistate.us/insider/2018/1/24/montana-leads-st...
Montana's had it since 2018, which was a first:
> Montana Governor Steve Bullock (D) signed an executive order requiring internet service providers (ISPs) with state contracts to adhere to “net neutrality.” The state became the first to enact such measures in response to the Federal Communications Commission's (FCC) decision to repeal net neutrality rules last December.
Which is what I said way back then: There's nothing wrong with net neutrality but it's simply not necessary.
protections are important even if someone's not actively and noticeably abusing people right this minute.
No one is fighting "so hard" this is a dead topic.
T-Mobile offers to zero rate YouTube if you let them throttle it - it's your choice. Would that be legal under Net Nutrality? Would they have to get permission from YouTube?
AI was a pretty dead topic after the 80's boom as well. Hell, we can argue VR is still a "dead" topic, but we know sometime in our (millenial+) lifetime that we're going to have major landmark cases over VR/AR tech.
I'd rather patch loopholes before they get abused at this point.
https://www.freepress.net/blog/net-neutrality-violations-bri...
That same set of scoundrels[1] that CF backtracked on defending keeps having routing issues (on top of their ddos issues).
Supposedly they (or someone related?) recently complained to a state AG under a state-level net neutrality rule. Not sure if it's been long enough to know if anything'll come of it.
.
[1] https://www.goodreads.com/quotes/52416-the-trouble-with-figh...
It wouldn't work very well, but then they won't ask again next time.
As such, any CF server not within the nation in question would effectively be a circumvention tool.
Maybe Cloudflare has an Ethernet cable between the server in question and itself, but that seems unlikely to me. There is probably some ISP in the middle that will play ball, right?
I'd imagine that CF's first act would be to remove any of the "offending" content from the country, at which point BGP blocking would no longer do anything.
Since the blocking was illegal per the European Union's regulations, presumably any other EU nation would have to enact similar decisions if this blocking was done elsewhere in the EU.
They still do (or did?) get grants from a few federal agencies though. But they had no strings attached. This is probably what you're thinking of.
Source: Hung out with a few Tor devs in Berlin a few years back. Including He Who Shall Not Be Named.
I've seen people talk about encrypted SNI for a very long time now and it's still not working; someone must have dropped the ball pretty hard regarding that
Edit: it looks like as of late May if you enable some dev flags in Firefox any site behind Cloudflare should use ECH.
It's also dependent on a new kind of DNS record and the original design wasn't great for DNS load balancing. Some tweaking had to happen there too.