Cloudflare takes legal action over LaLiga's "disproportionate blocking efforts"
broadbandtvnews.com
broadbandtvnews.com
The result is that web browsing in Spain on weekends, when football is on, is severely impaired, with thousands of web sites going down as matches play. This is a breach of the court order itself, which clearly states that "no unrelated sites may be affected", all while the court order itself probably being illegal as well. And, of course, IPTV pirates found ways around the block.
bandaancha.eu is doing a fantastic job on the reporting of this.
At the risk of non-Spaniards being unable to understand: that's the most pandereta thing I've heard this year so far.
I've seen reports that Orange may have imposed the block as well, which is the #2 provider. Definitely a nontrivial slice of the population
# curl http://104.21.16.1
<META HTTP-EQUIV="Pragma" CONTENT="no-cache"><META HTTP-EQUIV="Expires" CONTENT="-1"><html>Por causas ajenas a Vodafone, esta web no est� disponible</html>
# curl http://104.21.16.1 --header "Host: blockedsite.com"
error code: 1001
(1001 is the expected output from Cloudflare)Which is really useless, but I guess fulfills the court order (pandereta meets undefined specifications).
How so?
https://www.redes-sociales.com/bloqueo-cloudflare-parte-lali...
Then I guess the answer comes down to whether sharing IP address makes a party related.
And LaLiga’s response to their reporting? Sending false abuse notices to their hosting provider [1]
[1]: https://x.com/bandaanchaeu/status/1892992576069783825?s=46
Aaah, this explains some stuff. I'm on holiday in Spain right now, and a bunch of little blogs and similar sites just don't work at all for some reason. I bet they're hosted on Cloudflare Pages or using Cloudflare as a CDN layer.
I assumed it was just the hotel WiFi doing something weird!
I suspect a translator app? AI translator? The complain in silence makes me think the intent is "complain but not heard"?
I see in Spain it isn't a mistake.
Cloudflare does not randomly block access to sites that don't deal with Cloudflare.
Cloudflare customers buy blocking service to their sites from Cloudflare. Any randomness there is just customer service issue.
If the customer specifically set a header match to block some Firefox variant, people wouldn't complain to cloudflare about it.
>... just customer service issue.
If your favorite website is blocking you, let them know. They can tweak a lot in their WAF settings. I don't think many websites care about obscure browsers, but it's something websites can control.
For instance they block me because I'm behind CGNAT and because some of the millions of machines also behind that CGNAT once did something unsavory.
I'm not a customer of Cloudflare, so I have no one to call, I just get blocked from endless websites or have to click a checkbox, solve puzzles and suffer other indignities because I'm using a reputable and popular ISP in my country.
Fuck Cloudflare. They're accelerating the utter shittiness of the web because of their indiscriminate solutions to web malfeasance, which are worse than the disease.
If Cloudflare is now taking a hit because it's become collateral damage to an over-generalised penalty system despite having done nothing wrong itself then it is difficult to find much sympathy. If this blocking exposes how much of the web we all use every day is now being routed via a single point of failure that has been operating largely as a law unto itself then that also seems like a positive step to me.
1. High genuine traffic
2. High bot traffic
3. Being DDoSed to death
Everyone else other than you get to enjoy a snappy and fast loading site. I think that’s a good trade off.
The core logic behind that sentence is that it's good to be in an unfair system, as long as you benefit from the system and don't get unfairly targeted.
Work camps are also a good thing, provided you're benefiting from the work rather than sent to the gulag.
Why can't everyone else suffer? What makes me the loser besides prejudice?
I'm hardly unique, there are many people who share an external IP.
Maybe the point is don't screw one half of the population to benefit the other half.
What (other than greed) can possibly justify blocking hundreds of different services, with little to no oversight?
The only saving grace here, is that premium broadcasts kinda succeeded in getting the fans, rather than corrupt politicians and the state, to mostly fund the entire scheme that is the sport.
Other than that, cry me a river with how much we allow football to bend (and break) so many of our laws and regulations (not to mention ethics and decency).
It could be that CloudFlare does absolutely nothing to aid any site, big or small, when asked to stop hosting & concealing blatantly malicious origins. I don't even care who it is at this point, at least someone is causing problems for CF who, frankly, behave as if they're untouchable.
Literally every scam site I've checked out in recent years, pretending to a government entity, or parcel delivery service, in order to defraud millions from those not blessed with much technological literacy, has been hidden behind CF. Their responses are excruciatingly slow, if they even do anything at all. Usually they don't.
“Every one of those scams” are also on the internet, use email, DNS, whatever.
The metric that matters is how much of Cloudflare is a scam, and can the rate of scamming on Cloudflare be reduced without significantly impacting legitimate uses of it, and how.
Let's get ISPs to instablock IPs shared by thousands of sites immediately, making the internet an excruciating experience on weekends, because we may be loosing some football euros on our way to charge as much as the market will bear is just indefensible. If for no other reason, because IPs are a scarce resource.
Yes, piracy will take advantage of privacy technology (EDNS in this case). If we're cautious of violating privacy to catch child abusers, again, cry me a river about LaLiga not being able to fund the next hundred million euro transfer.
I disagree, I think the metric that matters is what proportion of malicious sites use CloudFlare and their ilk. I have personally had reasonable success after reporting malicious sites to the abuse@ address for their IP range. CF breaks that.
I know it was heavy handed, but nothing less would even register on CF's radar. You have to make CF's customers angry with CF for them to do anything, yet their position is they still won't. CF would rather sue someone else than make it easy for the Internet to combat bullshit.
In this case? A court order: https://bandaancha.eu/articulos/esta-nueva-sentencia-autoriz... which is a pretty heavyweight oversight mechanism.
Personally I'm broadly pro-piracy and anti-big-sports-organisation. But alas the legal system disagrees.
(Unless your view of ethics/morality is that anything ordered by any court is automatically good, which I'm sure some people believe but I suspect many more do not have such a binary view.)
Both?-both.gif
Needless to say, companies should comply with the law of the place where they do business in.
> "LaLiga secured this blocking order without notifying cloud providers"
(In the end I think governments should finally hunt down and eliminate abusive netizens, but waiting for that to happen is pointless)
Add in their centralized panopticon of mass decrypted traffic and it becomes undeniable CF is an enormous net negative to the internet and society at large.
Private forums in my experience stopped being a thing around 2010-2015-ish. The first deathknell was metasploit which made 0wning a target so much more easy than it was before, the second and final blow were "ddos for hire" services, running on cryptocurrencies that promised (and delivered) true anonymity, and using mass hacked consumer devices as a botnet that was much harder to defeat against than an STRO in some datacenter where you (or your DC) could just block the IP address.
curl ipinfo.io/`dig +short news.ycombinator.com`
{
"ip": "209.216.230.207",
"hostname": "news.ycombinator.com",
"city": "San Diego",
"region": "California",
"country": "US",
"loc": "32.7157,-117.1647",
"org": "AS21581 M5 Computer Security",
"postal": "92101",
"timezone": "America/Los_Angeles",
"readme": "https://ipinfo.io/missingauth"
}
Impossible to survive on the internet...Did you know they have a workflow for you to sign up start using their protection in the middle of an attack? Costs money, of course. They don't get to EEE the Internet that way so they don't make it free.
This will happen to you if you use Cloudflare as well, _unless_ you enable (at least) the automatic captcha, which then annoys users and disallows privacy-focused people from visiting your site.
To effectively stop committed DDOS you'll need CF enterprise, which filters out private blogs etc by price. The WAF options definitely make it easier to fight simpler DDOS attacks, but even then you'll need to know what you're doing.
Anyway, read the rest of the responses here giving context; the issue has more nuance than you seem to realize.
I think burns/jokes about Cloudflare are missing the point. It's not about Cloudflare, it's about the millions of people in Spain who couldn't access a plethora of legitimate, unrelated websites and services because of the block. The block included things like Redsys, a major payments processor used by tons of ecommerce sites in Spain.
Piracy or not, you shouldn't be able to get away with this kind of collateral damage, blocking an entire population from accessing a far greater number legitimate websites.
And while I do understand their problems with piracy, LaLiga's view on the matter has always been so over-the-top and reminiscent of the false logic the record companies did in the early 2000s: LaLiga believe (or at least say, all the time) that every euro's worth of football that is pirated is a euro that has been stolen from them; that if piracy didn't exist, they would have that much more money. It's simply not the case. It's a hugely outdated viewpoint, and they shouldn't be able to cause damage to the public because of their adherence to it.
I happen to agree that La Liga wildly overreaching is on brand. But I think this is partly about Cloudflare.
What's happening is a reminder of how centralised the internet is becoming. If blocking Cloudflare IPs brings down big chunks of the internet for Spain, that's a problem. Cloudflare could go down for a while, or collapse permanently, or get compromised.
Putting aside my opinions on La Liga overreach, it will also be a problem if companies get to say to courts "Oh, well, if you block those IPs the internet goes down for your country, so let us know what you want to block and maybe we'll get around to it."
Cloudflare might get a resolution from the court that suits them in the short-term. But drawing this to government attention might not suit them in the long run.
On the contrary, it would be an excellent outcome if the Internet became all-or-nothing, and countries could either choose to provide Internet access or block the entire Internet, with zero ability to selectively block things they don't like.
Doing that via a few centralized CDNs would be bad. Doing that at the protocol level would be excellent.
All things should exist in reasonable degrees. Arrests and blocks are legitimate tools that should be used to keep people safe, but their use should be accountable and subject to due criticism. You can't weasel out of absolutism by overloading alternative solutions unless you also explain why such tools are meaningfully different.
One of my controversial opinions is that I think the Tor network strikes a good balance. Occasional vulnerabilities and raids keep those perpetuating the most severe long-term abuse on their toes, while the scarcity of such exploits facilitates the short-term censorship resistance necessary to serve as a backup for censored communications during political turbulence.
Blocking can shape a whole society.
Also, arrest is the appropriate tool to stop something bad from happening, rather than just hiding it.
(And to be clear, this is all about things that a government is restricting, which should be few and far between. Private sites can block whatever users they wish.)
It is a heavier tool, but it's also a more severe tool, I'm not sure I understand this objection.
Blocks and arrests both serve to reduce the occurrence of bad things because bad things require delivery and arrests take time and are sometimes not possible. Disbanding the drug cartels in Brazil and Mexico would be the best solution to the flow of drugs into the U.S, but that's hard and even at best will take a long time, so in the meantime countries settle for trying to stop drugs at the border instead. The response to overseas distribution of child pornography should be similar.
(To be clear, I do also think it's important to go track down the sites hosting such content and take down the sites. But at the source, not blocking at the border, which is a capability that shouldn't exist.)
Also, at the risk of unrelated political commentary:
> Disbanding the drug cartels in Brazil and Mexico would be the best solution to the flow of drugs into the U.S,
Legalization would be the best solution to the association between drugs and organized crime.
I don't think you've justified that objection any other way than saying "stopping it at the source would be better" (which is unambiguously agreeable).
Teaching a man to fish is obviously better than just giving him a fish, but if tuition is not possible due to resource constraints, a fish distribution system isn't a terrible idea.
Yeah, CF has stepped in it from to time and yeah, maybe they have ego-ish proclivities. What Behemoth online service doesn't?
But at the core of this debate is about LaLiga and it's peripheral relationships dragging a lot of innocent folks along with the genuine targets of their focus. It's like those Drift Netters who have demonstrated they care not for the unindended species they catch. A bit of a labored metaphore but, there you have it.
Thousands?
It used to be one could access _any_ Cloudlfare customer website using appropriate Host header, SNI and a _single_ Cloudflare IP address, i.e., one address could be used to reach all CF customer websites. For whatever reason, that is no longer the case.
I think that's probably what they'll be doing in the end, so it's interesting to observe that they haven't done so already. Do they maybe have at least an internal domain reputation system so that long-time customers mostly share IPs with other long-time customers and are less likely to get caught in the crossfire?
They could. On the other hand, why should they? I would much rather see them fight this court order and make it stop across the board.
Finding abuse contacts is actually a M:N problem for the entire industry since we skimped on IPv6 (Had we gone to IPv6 providers like CF could've just assigned customers their own IP's and third-party fallout would've been minimal).
1) Cloudflare wins its lawsuit against LaLiga. 2) LaLiga appeals to Cloudflare to block these individual, infringing sites.
3) Cloudflare does nothing.
However, the last court order, removed the fine as they interpreted the AEPD (Spanish data protection agency, and the ones that fined LaLiga) did not showed any guidelines about this kind of stuff so it couldn't be fined retroactively. And that showing a "Mic in use" warning every time the app was using the microphone, as AEPD wanted, was "excessive". [1]
[0]: https://confilegal.com/20220505-la-an-ratifica-la-sancion-de... [1]: https://www.cuatrecasas.com/es/spain/propiedad-intelectual/a...
You can easily reproduce this by using a mainstream browser like Chrome and changing your user agent to e.g. a Firefox one (or the reverse). You'll be hit with captchas everywhere but unlike the cloudflare ones the google ones can at least be resolved.
I don't have issues passing these blocks in Firefox, though.
linux + firefox + less developed country ISP = endless captcha loop or straight up ban
But on the other hand, almost all of the requests from less developed countries in my logs seem to be malicious. I've blocked entire countries at times (through iptables, arguably better for privacy but worse for blocked people) when a dumb bot wave made it through the internet. I get why Cloudflare is so eager to ban some ISPs, those ISPs seem to be doing a terrible job protecting the rest of the internet from their hacked or abusive customers.
This is about messing with unrelated parties. Cloudflare is not doing that.
you <---> C <---> site
you <--X--> C <---> site
|
Court order
See the difference.Can Cloudflare demand that ISPs carry its traffic? Probably, due to net neutrality laws. That's what they are trying to do in court.
Can you demand that websites allow you in? Depends on the site, I can imagine certain kinds of sites, e.g., government websites or public utility websites, being compelled to do this by a court, if they use Cloudflare and block innocent users. But the blocked users will generally not have enough time or money to deal with a lawsuit.
Clearly there’s a balance to be had, but Cloudflare’s shadowbans are just mean.
Also the one time I reported abuse which was online banking phishing they just replied that they'd informed the upstream provider and nothing happened.