This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
This whole article seems conflate hosting an informational site run by the attackers and hosting the attack itself.
DDOS protection services were provided by companies like Akamai; call for pricing, big companies only, absolutely no anonymous sign-ups.
Cloudflare revolutionised the industry by providing free DDOS protection to anyone, including DDOS-for-hire services. Preventing them from DDOSing one another offline really let the DDOS industry take flight.
Cloudflare should simply enforce basic rules, like "don't run a cybercrime storefront", rather than letting criminal operations like this proliferate.
Why care about them hosting an info page for anyone? Cyber criminals supposedly can host it a billion other ways so why care?
Or maybe not, I’d rather have more Tor sites that aren’t questionable content. It’s a great tool for hosting even personal sites if you appreciate privacy and resilient infrastructure.
(The great thing, though, is nobody can prevent you, or anyone, from hosting your site there.)
If you report the DDoS-for-hire actors that offer their services on forums where such things are offered openly, they reply with a template that freely interpreted say something along the lines that they can do nothing and who is a crimininal is .. like, just your opinion, man (checks notes) they say here they are a legit load tester operation, so nothing really we can do.
You can say they entered the scene because DDoS exploded in popularity, but you could just as easily make the argument it was the other way around. Make of that what you will but they sure made a lot of money from the same booters they protect their customers from.
Used for these attacks, dunno, used for some attacks, yes. (But CF still remains a much less frequent nuisance than pretty much any other infrastructure provider.)