What (other than greed) can possibly justify blocking hundreds of different services, with little to no oversight?
The only saving grace here, is that premium broadcasts kinda succeeded in getting the fans, rather than corrupt politicians and the state, to mostly fund the entire scheme that is the sport.
Other than that, cry me a river with how much we allow football to bend (and break) so many of our laws and regulations (not to mention ethics and decency).
It could be that CloudFlare does absolutely nothing to aid any site, big or small, when asked to stop hosting & concealing blatantly malicious origins. I don't even care who it is at this point, at least someone is causing problems for CF who, frankly, behave as if they're untouchable.
Literally every scam site I've checked out in recent years, pretending to a government entity, or parcel delivery service, in order to defraud millions from those not blessed with much technological literacy, has been hidden behind CF. Their responses are excruciatingly slow, if they even do anything at all. Usually they don't.
“Every one of those scams” are also on the internet, use email, DNS, whatever.
The metric that matters is how much of Cloudflare is a scam, and can the rate of scamming on Cloudflare be reduced without significantly impacting legitimate uses of it, and how.
Let's get ISPs to instablock IPs shared by thousands of sites immediately, making the internet an excruciating experience on weekends, because we may be loosing some football euros on our way to charge as much as the market will bear is just indefensible. If for no other reason, because IPs are a scarce resource.
Yes, piracy will take advantage of privacy technology (EDNS in this case). If we're cautious of violating privacy to catch child abusers, again, cry me a river about LaLiga not being able to fund the next hundred million euro transfer.
I disagree, I think the metric that matters is what proportion of malicious sites use CloudFlare and their ilk. I have personally had reasonable success after reporting malicious sites to the abuse@ address for their IP range. CF breaks that.
I know it was heavy handed, but nothing less would even register on CF's radar. You have to make CF's customers angry with CF for them to do anything, yet their position is they still won't. CF would rather sue someone else than make it easy for the Internet to combat bullshit.
In this case? A court order: https://bandaancha.eu/articulos/esta-nueva-sentencia-autoriz... which is a pretty heavyweight oversight mechanism.
Personally I'm broadly pro-piracy and anti-big-sports-organisation. But alas the legal system disagrees.
(Unless your view of ethics/morality is that anything ordered by any court is automatically good, which I'm sure some people believe but I suspect many more do not have such a binary view.)
Both?-both.gif
Needless to say, companies should comply with the law of the place where they do business in.
> "LaLiga secured this blocking order without notifying cloud providers"
Cloudflare does not randomly block access to sites that don't deal with Cloudflare.
Cloudflare customers buy blocking service to their sites from Cloudflare. Any randomness there is just customer service issue.
If the customer specifically set a header match to block some Firefox variant, people wouldn't complain to cloudflare about it.
>... just customer service issue.
If your favorite website is blocking you, let them know. They can tweak a lot in their WAF settings. I don't think many websites care about obscure browsers, but it's something websites can control.
For instance they block me because I'm behind CGNAT and because some of the millions of machines also behind that CGNAT once did something unsavory.
I'm not a customer of Cloudflare, so I have no one to call, I just get blocked from endless websites or have to click a checkbox, solve puzzles and suffer other indignities because I'm using a reputable and popular ISP in my country.
Fuck Cloudflare. They're accelerating the utter shittiness of the web because of their indiscriminate solutions to web malfeasance, which are worse than the disease.
If Cloudflare is now taking a hit because it's become collateral damage to an over-generalised penalty system despite having done nothing wrong itself then it is difficult to find much sympathy. If this blocking exposes how much of the web we all use every day is now being routed via a single point of failure that has been operating largely as a law unto itself then that also seems like a positive step to me.
1. High genuine traffic
2. High bot traffic
3. Being DDoSed to death
Everyone else other than you get to enjoy a snappy and fast loading site. I think that’s a good trade off.
The core logic behind that sentence is that it's good to be in an unfair system, as long as you benefit from the system and don't get unfairly targeted.
Work camps are also a good thing, provided you're benefiting from the work rather than sent to the gulag.
Why can't everyone else suffer? What makes me the loser besides prejudice?
I'm hardly unique, there are many people who share an external IP.
Maybe the point is don't screw one half of the population to benefit the other half.
(In the end I think governments should finally hunt down and eliminate abusive netizens, but waiting for that to happen is pointless)
Add in their centralized panopticon of mass decrypted traffic and it becomes undeniable CF is an enormous net negative to the internet and society at large.
Private forums in my experience stopped being a thing around 2010-2015-ish. The first deathknell was metasploit which made 0wning a target so much more easy than it was before, the second and final blow were "ddos for hire" services, running on cryptocurrencies that promised (and delivered) true anonymity, and using mass hacked consumer devices as a botnet that was much harder to defeat against than an STRO in some datacenter where you (or your DC) could just block the IP address.
curl ipinfo.io/`dig +short news.ycombinator.com`
{
"ip": "209.216.230.207",
"hostname": "news.ycombinator.com",
"city": "San Diego",
"region": "California",
"country": "US",
"loc": "32.7157,-117.1647",
"org": "AS21581 M5 Computer Security",
"postal": "92101",
"timezone": "America/Los_Angeles",
"readme": "https://ipinfo.io/missingauth"
}
Impossible to survive on the internet...Did you know they have a workflow for you to sign up start using their protection in the middle of an attack? Costs money, of course. They don't get to EEE the Internet that way so they don't make it free.
This will happen to you if you use Cloudflare as well, _unless_ you enable (at least) the automatic captcha, which then annoys users and disallows privacy-focused people from visiting your site.
To effectively stop committed DDOS you'll need CF enterprise, which filters out private blogs etc by price. The WAF options definitely make it easier to fight simpler DDOS attacks, but even then you'll need to know what you're doing.
Anyway, read the rest of the responses here giving context; the issue has more nuance than you seem to realize.