Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers?
infosec.exchange
infosec.exchange
> Like a lot of people, we’ve felt angry at these hateful people for a long time but we have followed the law and remained content neutral as a network.
This is overall a very reasonable take and one I support from a player the size of Cloudflare: They should aim to remain as neutral as possible instead of enforcing arbitrary blocks on sites they disagree with.
Now, this post is from nearly 10 years go and I'm sure there have been many more cases that happened since then, their methodology likely did evolve, but I don't mind them protecting any site, regardless of their opinion towards its content.
[0] https://blog.cloudflare.com/why-we-terminated-daily-stormer/
"Our decision today was that the risk created by the content could not be dealt with in a timely enough matter by the traditional rule of law systems."
Reacting to public outcry by cutting off a legal stressor?
I just don't think it's that big a deal.
Being hosted on someone's private server is a privilege, not a right. As far as I know the host is legally responsible for the material they dispense.
In the abstract, I believe everybody should have access to web hosting. But upholding that mission is not the job of one private company.
Anyway, I guess "content-neutral" is an easier sell for most people than "We will 99 times out of 100 let you be even if you're pretty out-there, unless people start suing us about you and it's pretty plain to see you might be a degenerate force on the social internet, in which case yeah we'll tell you to beat it".
Like, it's not a power that should be exercised liberally. But be real. It's Kiwifarms. Businesses have a right to refuse service to recreational gangstalkers
I know they have added additional services and you could say that they offer a type of hosting and domain names and other such stuff.. but generally when place get kicked from cloudflare, it is not their web host.
I would also say that they know pretty well when they kick someone from the dns protection that they are going to be bombarded with ddos and other issues that will take them offline more than likely.
The article itself even says the tipping point for daily stormer was "the claim that we were secretly supporters of their ideology" which is hardly any sort of Due Process.
There is a use case for buying them for testing purposes to apply on yourself, so it's not as cut-and-dry as you would expect.
Conversely, this site proudly advertises that it has zero "Know Your Customer" restrictions, bypasses Cloudflare protections, etc.
Quoting the site directly: "Some popular use cases are taking down competitor websites, creating unfair advantages in games and personal agendas."
Even their CYA disclaimers are flimsy: "We simply ask to only use our tools on infrastructure that you own or are permitted to attack."
Not "Require", "ask".
This one is fairly obviously bad, but some will be more ambiguous, and I wouldn't expect Cloudflare to be the one policing them all.
To the outside world, Cloudflare acts as a host. Their servers serve the content fo whatever site is in their "network". It doesn't matter that some of those sites are being partially pulled from other backend servers that are outside their network again. Cloudflare is their service provider and they are their customer (free or not).
This is especially true with all their hosted stuff now like Workers, R2, etc., but don't let that muddy the discussion. Even without that they cache and serve the content.
i don't understand how ceasing to proxy their storefront would stop a ddos attack? it's not like CF infrastructure is being used for the DDOS, or is that actually the claim made?
i can get saying something like "they shouldn't be providing this service to them" but this isn't a critical service to their operation?
cloudflare hosts the attackers.
No, they provide DDoS protection, but the actual servers are likely hosted on some random VPS somewhere.
Edit: I now realize gruez meant the beamed.st site itself is behind Cloudflare DDoS, completing the loop to explaining what Cloudflare's involvement was :).
Am I missing something on how to see more of the original post perhaps? As a sanity check I did a ctrl+f on "hosts" on the page and didn't get a match but I suppose that wouldn't help if I'm not in the right place to see the rest of the content.
They do and they've done so in the past. They are just more okay with some illegal stuff than others.
It's policing their own customers attacking their own other customers in a way that opens themselves up to racketeering charges.
(Moreover since cloudflare has a free tier you could use their service while handing over only a single email)
CF not only protects them... they have real time intelligence on who is getting attacked, who is paying for it, and all the parameters of the attack (type, volume, duration, etc).
What would your sales team give for leads this hot?
This is credible as "amazon has real time intelligence on all their e-commerce competitors because they operate AWS".
Most enterprises aren't using AWS as a VPS provider. They're going to be using other products like API gateway, ELB, or WAF, all of which expose traffic for easy analysis. Even if for whatever reason they are, the pareto principle applies. They don't need to care about the long tail of e-commerece vendors out there, only the whales. For that, they can just get an intern (or nowadays, LLM) to dump out the disk and manually dissect whatever's on there.
(But if you are in the US, your government considers foreign human laborers doing useful work as "invaders".)