Spain's parliament will act against massive IP blockages by LaLiga
democrata.es
democrata.es
https://cybernews.com/news/spain-laliga-streaming-piracy-cam...
Accelerationism was always a terrible idea.
You have some medium-okay but clearly sub-optimal status quo and then a bunch of defenders resisting all change because "things are fine" even though they should be better than fine, or institutions that have been captured by corrupt interests but that situation is stable as long as they continue to provide bread and circuses. If it stays mediocre then everyone muddles along; if it gets worse then people stop ignoring the issue and actually address it so that it gets better.
The problem is, it's not just bread and circuses. People have been divided into camps for the purpose of directing their dissatisfaction against each other instead of the entities responsible.
So people get mad when things go wrong but the perpetrators convince them that the enemy is their neighbors and they need to direct their resources to defeating each other instead of working together to solve the actual problems.
For example, when SOPA/PIPA was defeated, it not only wasn't just along party lines, there was more opposition to it from Republicans than Democrats:
https://projects.propublica.org/sopa/pipa.html
So who we like here are e.g. Ron Wyden (D-OR) and Rand Paul (R-KY), because they both opposed it, even though they're in different parties. But then the "parties matter, not candidates" people would have you trying to oust everyone with the disfavored letter next to their name even if they did the right thing there. Which helps the baddies win by convincing you to oust good candidates from the "bad" party in favor of bad candidates from the "good" party, and over time makes both parties worse even as people become increasingly dissatisfied with the way things are going.
(Yes, the action described in the article is explictly not legally binding. That was also true of the Brexit vote.)
By affecting only Spain, the impact is too small for most websites to care.
Telefónica is nothing globally compared to Cloudflare. But in Spain it competes in some areas. Exactly where this ban is happening.
It is not hard to see a conflict of interest.
Just as trying to make social media be the arbiter of speech...
And even if there were I doubt the legal basis in EU law exists for such an injunction
The Spanish government is not the ones enforcing the ban here. La Liga and Telefonica went to the judges, who are the ones making ISPs to enforce these blocks, as an intermediate "fix" essentially.
Which are part of the Spanish government.
Judges in Spain are not part of the government ("Gobierno"). They are part of the Poder Judicial, the judiciary. The Spanish Constitution separates these clearly, give it a skim if you haven't already.
I guess broadly in English you'd say the judges are part of the state, but they're not a part of the Spanish Government.
Nothing here been a "gotcha" but basically Spanish-speaking people using English to communicate Spanish concepts to Americans who also speak English but have different understanding of those concepts. Nothing malicious here, just some good old misunderstandings :)
“The government” (what we would call “the executive”) being equated to the state as a whole is a uniquely American concept, likely because the word “state” already has a different meaning in the federalist sense.
La Liga wants to be able to point to a URL hosted by Cloudflare and demand it taken down that instant while the match is still on. It would require dedicated staff at Cloudflare to deal with La Liga stream takedowns.
This is a risk with shared IP addresses. I sold CF to many customers and I would say the risk in general is minimal. At least outside Spain. But people should stop whining and use a better service if needed.
A better service that the Spanish government will also block?
Cloudflare is not the bad actor here. The Spanish government is.
But I have been thinking about this quite a lot recently (mostly because I get angry at the power states sometimes have over individuals). Would the distinction really matter in this case?. I would think that in a "civil law" contry things could be even worse for the aggressor
The law is no stranger to "damned if you do, damned if you don't" scenarios.
Here's France, the Platonic embodiment of European civil law:
> To get damages, you must compile a file that gathers all the elements that make it possible to determine that your damage is compensable
> You must demonstrate that you are the victim of harm: [snip]
> In order for your damage to be repaired, you must also determine:
> - A fault, negligence or infringement committed by another person
> - And that your injury occurred as a result of that fault, negligence or breach.
> Example :
> A person walking down the street hits you because he is looking at his phone. You fall and you break your arm. So you are suffering bodily harm that was caused by the negligence of the person who shoved you. It was precisely this negligence that led to your damage, because if the person did not hit you, you would not have fallen. You can therefore ask him for damages.
( https://www.service-public.gouv.fr/particuliers/vosdroits/F1... ; note the banner saying "This page has been automatically translated. Please refer to the page in French if needed.")
What ISP? I'm using Vodafone and if I accept the insecure connection (because of mismatched certificate), I get served the notification. You don't get that?
If I recall correctly, if you try to access the IP directly you get the same notification. No football game on right now though so cannot check.
Edit: In fact, I'm not sure they do DNS filtering at all actually, it may be just based on IP, can't remember off-hand, considering the collateral damage, I'd say IP blocks mainly.
So whenever you see "Connection Refused" your instinct is to go to your ISPs website?
I also don't think it's "hijacking someone's website", then it'd be global, instead it is a man-in-the-middle attack, serving different traffic than the user intended.
Obviously I don't do my banking like that...
And how can a wrong certificate lead to local privilege escalation?
These IP blocks don't seem to come with a stopping principle. They were large and growing, and inevitably more and more entities were going to say "Hey, if that company is large enough to flip the switch to protect their assets then I'm large enough for that too!" and the obvious and inevitable stopping point was 100% blockage.
Taken to its logical conclusion, and I do mean "logical" and not "rhetorically overblown for effect", this comes perilously close to just declaring that the value of the Internet is so net negative due to piracy that it should just be shut down in Spain. If that's true during certain sports matches it's already not far from being true for lots of other things too. This was leading in an obviously-economically-untenable direction.
What you’ve described there is completely overblown for rhetoric.
The internet is still needed for delivering legal streams of matches. So there’s never going to be any pressure to turn off the entire internet.
Plus the likes of Amazon, and other online businesses would sue the hell out of La Liga for loss of trade.
So there’s no way in hell the situation would descend into your “logical conclusion”.
That’s not to say that the situation couldn’t get worse that it already is. Just that your logical conclusion isn’t very logical.
Cloudflare serves a whole bunch of legal and genuinely important services, and yet there was enough pressure to block them off.
> The complaints about the massive fall of web pages caused by LaLiga's fight against piracy reached Congress months ago. And the Chamber is now preparing to take measures.
But even ignoring the fact that TFA directly disproves your and the GP's argument, the point you're making that "x got approved so y also will" isn't how things work in the real world. People do have a pain threshold and just because CloudFlare was tolerated until now doesn't mean greater blockages would have been equally tolerated.
And yes, of course you're right, that people have a pain threshold, but it's also true that people will normalise behaviour over time. I'm not saying further blockages will happen, just that I don't take it for granted that they won't.
The argument I was disagreeing with was the statement that “a total internet block is the logical conclusion”
Which it isn’t. But, and as I said in my comment you claimed to disagree with, that doesn’t mean things can’t still get worse.
It's like saying there's some people who have been seen selling counterfeit made in China purses from a blanket in a street market in one particular neighborhood in a big city, so we're going to erect a roadblock to all vehicle and pedestrian traffic, and cut off metro train access to the area.
My point was just that Amazon is large enough to scare La Liga in ways that nearly no other online retailer is. Ergo La Liga wouldn’t ever push for a total internet block like the GP claimed.
But with copyright, everything is broken everywhere, so they don't have to.
Does it matter that it happens over IP or CSAM? It doesn't happen over CSAM because there is no dispute there, there is no desync there between spain,the us and cloudflare.
But the mechanisms around these court orders aren't much different than those that would be used for other illegal or contentious material.
If a vendor chooses to pool and encrypt connections in a way that it is impossible to filter by hosts, and that vendor doesn't comply with court orders, then a country should absolutely block that entire vendor.
The liability of an unrelated pooled service failing is either the responsibility of the vendor or the application that chooses that vendor, not on the courts for enforcing the law without a subjective 'stopping point'.
What these vendors do is very similar to pooling in the layering phase of money laundering, but with packets: get traffic from legitimate customers, mix it with traffic from unlawful customers, pool them, and send encrypted EHLO so that the origin domain is encrypted and the packet source /destination are replaced by the vendor's. If this were done with money it would instantly trip all AML flags, but the tech world is much younger and hasn't discovered that laundering isn't cool or free as in freedom, it's a tool that the baddies use.
I also got blocked from using RustDesk.
It's been crazy. As this happens intermittently. I had to set up a tailscale exit node in one of my servers to circumvent this crap. I lost several days and called Vodafone (ISP) to understand what was going on.
That's when I read Reddit and saw that crap.
So presumably the analogue to that in Spain.
Apparently they also block certain ports. As soon as I route the traffic through Tailscale through the same VPS I can connect without issues (My phone was affected as well)
Don't get me wrong, I hate getting blocked just because there is a La Liga game, but lets also take some responsibility for our own decisions here...
Who could have forseen, that LaLiga would end up abusing this system!?
Pornography is illegal in Spain now?
Why are Spain's courts allowing this injunction to stand? It's clearly being used to bring the court system itself into disrepute at this point.
> Google, Cloudflare, VPN providers, and other entities facilitating piracy are responsible for the illegal activities they enable and profit from.
Why wouldn't ISPs be responsible too? or the cable modem providers? or the computer providers? or your eyes. Let's just blame all those things and not the person that made it or the person that consumes it.
Cloudflare does.
That's not true. ISPs modify returned content. https://lukerodgers.ca/2023/12/09/optimum-isp-is-mitming-its... https://en.wikipedia.org/wiki/NebuAd
> Cloudflare has facilitated by knowingly protecting criminal organisations for profit
The propaganda is strong with these guys ...
However, my post was a tounge-in-cheek response.
I struggle with LaLiga's filter during matches, but I am more interested if it'll help with latency/speed. Have you noticed any different when using WARP vs. without it regarding Internet speed?
Thanks!
Right after this statement they could have permanently block all the IPs and let the outraged customers make enough noise that would have prompt the government to act sooner.
403 ERROR The request could not be satisfied. Generated by cloudfront (CloudFront)
(Disclaimer: I work for Cloudflare)
This is the bad guys.
403 ERROR The request could not be satisfied. Request blocked. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation. Generated by cloudfront (CloudFront)
Qui blockat blockodiodes? Cloudfare, it turns out....
It's the honest businesses who probably won't go through the effort of evading the block every time.
This is like blocking access to a street, a block of flats or even an estate because drug dealers and hookers operate from them.
The judicial, nation-wide blocks on CDN IPs is absurd and should have never been allowed.
I dislike what is happening but I kind of like that they don't care about the size of Cloudflare and hold them as accountable as they would a small hosting company in Belarus. Blocking entire ranges due to illegal content isn't exactly new, the scale is new.
Again though, I really dislike that it isn't going through the legal system
What do you expect cloudflare to actually do about these streams?
Maybe I'm being optimistic but I'm assuming the first action wasn't large scale IP blocks. Cloudflare likely didn't take action.
> What do you expect cloudflare to actually do about these streams?
I'm sorry but I'm not buying that the market leader in bot detection can't detect sport suddenly being streamed to an influx of people from a new IP at kick off. If this was the US banning them, I'm sure they'd have found a way around it by now
When there is phishing or pedo content, you think they wait for court order or react to abuse ?
They are distributing content through their servers, not just displaying it.
Every hosting and CDN companies has abuse department, it's a normal part of the process. Here, Cloudflare is aware, and chooses to ignore the abuse requests, then they have to take their responsibilities.
Cloudflare is a US-based company so they are realistically out of reach, or too late.
If there are abuse requests, and Cloudflare wants to comply but not block the website, they can downgrade to DNS only, and then the host IP would be blocked.
If Cloudflare doesn't comply and intentionally keeps distributing content -> block Cloudflare.
At some point for them, the cost of complying with the law will be cheaper than handling the complaints that they are blocked.
It's like YouTube, they shutdown content on request of rights holders.
It the same thing with social media and moderation. We don't have to let them off the hook just because doing the right thing would make them unprofitable.
Do we punish gun manufacturers for someone being shot? Kitchen utensil companies for someone being stabbed? Car manufacturers for car crashes? Road construction companies for human trafficking?
How deep does this go? Is a steel foundry responsible for the stabbing? Is a camera lens manufacturer responsible for illegal porn?
Banks are generally required to check that their customers are not laundering money. In a lot of countries it's illegal to buy or sell goods that you know are very likely stolen.
It don't think it's outrageous to expect more action from Cloudflare when they must know that their service is used for protecting criminal sites.
Relatedly I'd want the betting companies whose ads are shown on these illegal pages to have some amount of responsibility for where their ads are shown, and the same goes for well-renowned websites that show clearly deceiving ads.
To make the distinction the LaLiga would want they'd have to inspect every single packet, determine if this is a LaLiga game, determine if it's the current game, and determine if it's a licensed provider. There's a reason section 230 was created in the US.
Why make CloudFlare ultimately responsible though? There are lots of companies between users and the servers providing pirated content. Cloudflare is just one step in the whole chain. Why not eg block Google Chrome?
In any case, blocking Cloudflare was a stupid thing to do. Especially because it didn't anything to solve the actual problem.
Don't be disingenuous just because you like the company.
Furthermore, La Liga somehow convinced the courts they should be able to pick IPs for all ISPs to block in real-time without any oversight from the law. Considering this is a private company this is just absolutely insane.
I think you're not faithfully trying to adopt their perspective here, even if you don't agree with it (just like me).
They need (in their mind, again I don't agree) to block these sites somehow, as they see it as them "stealing" viewers, judges agree with this. Now, where can the block be done, and have the least amount of collateral?
Cloudflare is not playing ball and turning of the streams, and they appear too quickly to go through court orders all the time. Banning a web browser obviously has a huge scope, so you're effectively left with blocking based IP, DNS or both/either.
Considering they are breaking local laws, and judges feel like something should be done to stop that, the solution they arrived at, regardless of how shit it is, is probably the solution with the least collateral damage, even if it has quite a lot.
Again, I don't agree with the decision, but I can also see from their perspective that they don't have a ton of choices, if we adopt the perspective that it should be stopped somehow.
I think you're not seeing the bigger picture.
Somehow La Liga (a private company) was able to convince the courts that it should be able to ban IPs almost in real-time without any oversight from the law. This is just insane in a modern democracy and only benefitted La Liga. Certainly not the population of Spain for whom the courts work for.
Time has proven what anyone with two brain cells knew already. Blocking IPs was never going to do much to solve the issue. It's a wack-a-mole game. Cloudflare knew this and La Liga did too.
> where can the block be done, and have the least amount of collateral?
Blocking one of the biggest providers of internet infra was anything but "the least amount of collateral". Plenty of companies and services depend on Cloudflare.
But that in their mind is "solving the issue, at that time". Why do you think they want to expand it to other sports now, because "doesn't do anything" or because they actually see some effect from it?
> Blocking one of the biggest providers of internet infra was anything but "the least amount of collateral". Plenty of companies and services depend on Cloudflare.
Ok, so given their perspective is "something must be done" and Cloudflare are not blocking the users after requests, what is the alternative here? Turning off the entire internet connection for individual users? Turning off all the internet during games? I really don't know what alternative could be possible, that still satisfies their "something must be done".
Again, I agree that this is an massive overstep, wildly miscalculated and I'm personally affected by this every time a football is on, I don't like it either.
What are these "massive negative consequences" you're talking about? Some IPs blocks from Cloudflare are blocked for ~90 minutes, some times a week. As repeated so many times, I agree it sucks, but it's not "internet is unavailable most of the week", it's "some websites are unavailable for some hours of the week".
And also again, if you don't see "something must be done" you're not able to adopt their perspective, so of course you'll never understand this, because you're seemingly refusing to. Fine, you do what you want, but don't mislead others what the real situation is, just because you're unable to grasp it from the other side.
A good chunk of the internet goes through Cloudflare. Something like 40% of the top 1000 websites use it.
Services depend on it (CI etc). SaaS companies are shut down. Businesses can't sell. Etc. It's a disaster. It's amazing how oblivious you seem to the gravity of the situation.
I'm not, I don't know how I could, as every single time the blocks happen, I'm personally affected by it, since I live in Spain.
But, seemingly we have wildly different experiences. None of the companies I buy stuff from our down during those periods, it's not a disaster as far as I notice it, but clearly you do, so now I'm curious what exactly you're doing during these 2-3 hours a week when this happen that makes you so affected by this, while I'm not?
I'm genuinely curious, not a "gotcha" or anything, I just want to understand your situation better, since our experience differs so much. Which region are you in and with what ISP?
I can see their point of view. I understand they consider this a disaster. I understand they are insistent that something must be done. I am saying that the remedy they are proposing has too many negative consequences to the rest of society to be allowed. I am saying that their interests, sincerely held though they may be, do not trump the interests of the entire rest of the country, and therefore their injury is not satisfiable in the manner they wish it were. As the man once said, you can’t always get what you want, no matter how large an economic enterprise you’re running.
When I'm posting this message to Hacker News, I'm the "customer" of this website. I'm not customer of all the intermediate nodes in the chain. So if I were to write something illegal and HN would be irresponsive to takedown requests, the courts could order the IP of HN to be blocked, not some intermediate ISP.
The Digital Markets Act speaks of "conduits" instead of speaking of the specific form the conduits may take. It does not give special rights to someone who forwards IP packets unmodified or to someone who receives IP packets and reissues other IP packets or to someone who changes the IP addresses in the packets. It only cares about the net effect of the transmission, and the fact is that Cloudflare is a conduit with caching.