FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).
At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not.
The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large number of the abuse requests we receive turn out to be attackers trying to get the origin IP in order to circumvent our protection. As I've blogged about before (http://blog.cloudflare.com/thoughts-on-abuse), we've designed an abuse system that attempts to act as a proxy: passing abuse requests to the customer and their host without exposing the customer's origin to attack.
Malware is one of the situations where we'll actually take content down because it is, per se, harmful. However, we also don't think terminating the customer who has malware hosted on their site is a good solution. Since we're a proxy, terminating the customer doesn't remove the malware from the Internet but instead just kicks the problem down the road to the host. Instead, we developed a system that replaces the infected URLs with a warning page to protect users. This has the ancillary benefit when a site is being used for botnet command and control of allowing us to gather data on machines that make up the botnet. This data is fed back into our system in order to better protect our customers and we're talking other organizations about a way of responsibly sharing this data.
Our Trust & Safety team works with trusted malware reporters regularly, including the team at Microsoft that handled the no-ip.com takedown. We will continue to adjust our process to walk the careful line between ensuring our network isn't causing per se harm while, at the same time, avoiding the risk of becoming a censor.
Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well.
========
Why a Hunger Games-Like Vision for the Internet is Wrong
Earlier this afternoon Brian Krebs, a well-respected security writer, published a story which, in part, calls for CloudFlare to censor the websites of a handful of our users [http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...]. These websites are known as "booter" sites. The sites claim to offer point-and-click DDoS services. The thrust of Brian's argument is that CloudFlare is a hypocrite for allowing these sites that advertise DDoS services to be protected by our network while, at the same time, offering as a core feature the ability to stop DDoS attacks.
Brian acknowledges that there's a bit more nuance to the argument. He understands that CloudFlare is not a hosting provider and that terminating any customer wouldn't make the content of the booter sites go away, it would just make them slower and more vulnerable to attack. He also acknowledges that no attack traffic actually originates from CloudFlare's network. His assumption, which we discussed at length before he published the article, is that if CloudFlare weren't in the equation then the booter sites would simply DDoS each other into oblivion.
Stop for a second and think about that: Brian is arguing for a Hunger Games-like vision of the Internet. It's the functional equivalent of if the police stopped prosecuting crimes committed against people they suspected to be criminals.
Brian is not the first person to make this argument and he won't be the last. A few weeks ago Kayne West's attorneys contacted CloudFlare insisting that we terminate protection for a customer they said was causing irreparable harm to their client: the parody crypto currency called Coinye. Ken Carter, our legal counsel, explained to Mr. West's lawyers that terminating the Coinye CloudFlare account wouldn't make it go away, it would just make it more vulnerable to attack. They thought that would be terrific. Ken respectfully disagreed.
CloudFlare's mission is to build a better Internet. Inherently there is content on our network that I find distasteful or even harmful. In the past, we've been called to task by other journalists [http://blog.cloudflare.com/cloudflare-and-free-speech] for allowing controversial websites to use our network. There is currently a campaign that has gathered over 22,000 signatures [http://www.change.org/petitions/matthew-prince-remove-chimpm...] for us to terminate the account of what I consider a horribly racist and distasteful website.
While I, personally, agree that the site the petition was started over is truly awful, I don't believe my personal opinion of what is good or bad content should be what governs what is allowed online. If CloudFlare succeeds, even in small part, at building a better Internet, inherently we must honor and respect one of the Internet's greatest qualities: that it is a network open to anyone.
Note that this isn't everyone's policy. Amazon, for instance, terminated Wikileak's account after political pressure [http://www.theguardian.com/technology/2010/dec/11/wikileaks-...]. More recently an article circulated that they were censoring books where people fantasized about having sex with dinosaurs [http://observationdeck.io9.com/amazon-now-at-war-with-dinosa...]. Other CDN providers are notorious for taking content offline at the first hint of pressure. We don't do that, even when the pressure comes from someone we truly respect like Brian. Fundamentally, we won't play the role of the Internet's morality cops. It's above our pay grade.
Booter sites, you may argue, are different. But the key question is where do you draw the line. If a site says you can push a button and launch an attack should we take that down? What about one that has a phone number you can call? Or gives you instructions on launching the attack yourself? CloudFlare is many things, but one thing we are not is the Internet cops.
Don't get me wrong, we don't believe in a lawless frontier. While we believe deeply in principles of due process and will push back against what we deem abusive legal requests [http://blog.cloudflare.com/fighting-back-responsibly], ultimately if ordered by a court through valid legal process we will comply. While booter sites may be successful at using us to protect their content from being knocked offline by a DDoS attack, they will not be successful at using us to hide from law enforcement if they are breaking the law.
Brian and I have known each other for almost a decade. He left the Washington Post and started Krebs On Security around the same time as we were launching CloudFlare. I actually tried to hire him back then. Thankfully he didn't accept the offer because he has become one of the leading security journalists writing anywhere today. He breaks important stories, which is something we need in the security space.
On this issue, I respect Brian's opinion but think he's ultimately wrong, That said, I have no problem with him fostering the debate. I think the discussion is hard, but it is healthy and important. To that end, if there are any large security or technology conferences that would like to host such a debate between me and Brian on stage, just let me know when and where and I'm in.
First off, thankyou for a detailed and well laid out post.
I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more traffic. You might not have hit it - yet - but you will).
The internet - as you are aware - is based on protocols not designed with any significant security in mind. No-one in their right mind would today sit down and design something like BGP, for example. With that in mind, any large provider (or large consumer with capability to cause harm) has the responsibility to be a good citizen of the internet, and not to (by action or inaction) advance the agendas of those who would see its demise. As much as it might be convenient from an operational POV, and justifiable from a moral POV, washing your hands of responsibility and saying "It's not up to us, it's up to the courts" just doesn't work when the infrastrucure we're all building on is so very fragile.
I'd also like to note that there's a semi-hidden US bias here - what if the target of a botnet, who's admin interface is hosted by CF - is based in a country where there is no reasonable ability to recourse to the US courts? Iran, for example?
It's admirable that you do not censor content in response to political pressure, but there IS a difference between protecting freedom of speech and protecting malware, and saying that censoring the malware is a slippery slope is at least partly disingenuous - any vaguely controversial decision can be described as a slippery slope to something else.
Please at least consider making it easier for those of us who are trying to fight malware, botnets, etc, etc to get the original source of the content. I know this will involve some human judgement, and invetiably some mistakes and poor descions - but that would still in my view be far prefferable to what we have now. Thanks.
(Sorry I'm just responding to all this now, 15 hours later)
Malware and sites advertising so-called "booter" services are different discussions.
There's an important distinction here. You refer to "sites advertising so-called "booter" services." However, with the kind of sites I speak of, "sites providing so-called "booter" services" would be a better description. They aren't just advertising it; enter a valid username and password, enter an IP, click the "attack" button and an attack is launched, all from that single site.
Malware, phishing, and booters have two things in common: they have far-reaching effects (that is, they affect other, unrelated/unwilling people) and they are not in any way good for the target of the effort. Malware is only good for the operator who benefits from the keylogger, showing ads, or whatever; phishing is only good for the operator who benefits from the stolen information; booters are only good for the booter operator (who profits from selling it) and for the user who paid for it to attack a target. Based on that, it's difficult for me to see the difference between the harmfulness of any of these.
In your post, the standard you applied to malware and phishing was "harmfulness" (in your opinion). I agree with that standard, and I think you'll be hard-pressed to find a single person who agrees that any of these three issues are not harmful. So, in your opinion, what makes booters less harmful than malware and phishing sites, which you are willing to take offline?
Censorship is a slippery slope, indeed. But I think it is generally accepted that _some_ basic level of what is effectively censorship, is a necessary evil for the health of the Internet. For example, malware and phishing sites, as you mentioned; spam; DDoS attacks. That's why laws exist in so many jurisdictions to prohibit all of these, and why the AUP of every single reputable ISP in existence prohibits them. This isn't uncharted territory, this isn't something new CloudFlare is just getting into - the industry standard (and legal standard) is to prohibit all of these.
I find it interesting he never responded to this. He was on the site the next day, so he must have seen your comment.
His refusal to remove booter sites from CloudFlare is completely indefensible. Any attempt on his part to suggest otherwise can only be interpreted as evidence of guilt. There is no possible arrangement of words which can make it okay.
What makes a site hosting malware per se harmful, and how can you consider malware per se harmful while booters avoid being classified identically? Malware is illegal and obviously a detriment to the internet, as are booter services. Perhaps you're just willing to deal with malware so you don't end up in the same boat as No-IP did here.
Booter services are so incredibly common that the police aren't going waste their time on them, especially since once the cops get the real IP from your convenient obfuscation service, it's likely hosted in China, Russia, or some other country where no action will be taken.
Booter sites, you may argue, are different. But the key question is where do you draw the line. If a site says you can push a button and launch an attack should we take that down? What about one that has a phone number you can call? Or gives you instructions on launching the attack yourself? CloudFlare is many things, but one thing we are not is the Internet cops.
That is incredibly disingenuous. It's simple: if you knowingly facilitate an illegal service on your site, your service gets terminated. Every other reputable CDN and hosting provider can figure this out but somehow you can't? Give me a break.
He appears to choose to let the decision as to whether they 'knowingly facilitate an illegal service' be taken by law enforcement rather than by Cloudflare.
So I don't see anything disingenuous whether you disagree or not.
Trust & Safety maybe, but it's still impossible to use CloudFlare in Russia, due to harboring some drug-selling websites at your services. ISPs ban them by IP, and taking whole subnetworks of websites that reside on the same IP down with them too.
As much as I love your services, it's not possible to use them here, and ministry of communication even issued a recomendation not to use your services due to your unresponsiveness about takedown requests.
While I'm not familiar with the exact situation here, I suspect the real problem is that the malware domains are being automatically created en masse, and No-IP have been slow or reluctant to do anything to slow that down. Being responsive to complaints is good for small-scale problems involving individual domains, but basically useless for large-scale abuse.
what if a company like microsoft approach you and say "look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product"
granted, i'm not familiar with the matter. but I know what I would answer. also, removing noip or noip enabling whatever microsoft was bullying them to implement, would just delay it a few days until the worm creators rolled out their own service. heck that can even motivate them to get creative and encode IPs in a obfuscated pastebin, or stenographed in cat pictures in reddit, or noise mp3 in soundcloud... maybe having them rely on noip was good....
but again, i have no knowledge of the matter. maybe noip was being paid even after knowing it was for worms. who knows?
"look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product"
How can they patch it in their product without turning desktop Windows into something like iOS or Windows Phone/RT?
Even Android has a ton of malware so the notion that Windows is somehow more hole ridden than other platforms stopped being true starting about 10 years ago with their Secure computing initiative. If the user can install Firefox, they can install malware. If Firefox doesn't need to get permission from MS for their next version, Windows cannot distinguish between Firefox.exe and Codec_Flash_Shady.exe. Sandboxing will disable system level utilities.
MS is capable of making secure OSes. How many viruses and trojans do the 3 Xboxes, Windows Phone and RT have? Even Windows Server is pretty secure(atleast as secure as Linux) unless the admins start browsing on it. Malware is a real threat to any popular OS unless third party apps are entirely blocked or restricted by the use of a approval based App Store. Windows gives much more control to the user, which is why many users are able to stay away from infections. And it's ironic that you're blaming MS here instead of the folks that propagate it(including a YC company https://www.techdirt.com/articles/20130115/17343321692/why-a...) and people who install it(users).
Remember the shitstorm that was raised against MS on here and elsewhere when they tried to secure users by preventing undetectable rootkits by enabling Secure Boot?
Linux solved this problem almost twenty years ago. You have a package manager that does not contain malware and does contain 95% of the software any user would install on a regular basis, and you make the process of installing software outside of the package manager possible but not trivial. You download a binary and it doesn't have the execute bit set, and you don't get any kind of friendly thing that pops up to ask you if you want to set it. So the sort of person who can't distinguish between legitimate software and malware also can't figure out how to install the malware, but you don't prevent people who know what they're doing from doing what they want.
The problem with Windows is that it has no package manager, so the default method of installing legitimate software is identical to the method of installing malware. The problem with Android is that the malware is in the app store. All you need is a known-good repository where you can get almost everything safely and people can spend most of their time. You don't then need to build a prison around it and trap everyone inside because most people will want to stay in the safe place. The people who want to (and can figure out how to) wander outside are the people who know what they're doing, and know to be suspicious of the things that conspicuously haven't been vetted by anyone else.
If Linux were to get as popular as Windows, the problem is going to way worse.
Also, there's lot of Android malware that's installed from outside the app store, typically for piracy reasons which is another big malware vector on Windows.
If Linux were to get as popular as Windows, the problem is going to way worse.
Everybody says this but it doesn't make any sense. Are the repositories going to get more malware when there are more people and funding available to notice and report it?
Also, there's lot of Android malware that's installed from outside the app store, typically for piracy reasons which is another big malware vector on Windows.
All the more reason why it wouldn't happen on Linux. Nobody really pirates LibreOffice or gcc.
Hey pktgen: I'm new at CloudFlare, but I'd be really interested in chatting with you (or grabbing a beer) to hear if there's something we could do better. Contact info in my profile. I'll be at Defcon and HOPE too if that's easier.
(Free speech vs. keeping the overall network safe is a hard decision. I think all pro-privacy and pro-liberty services have had to answer this question -- same thing happened with cypherpunks list, HavenCo, Freenet, various payment systems, etc.)
(Offer is open to anyone who ever has security/privacy/etc. issues w.r.t. CloudFlare. I like talking to people about security and "Internet politics", either at conferences or at home.)
I have multiple horror stories from my days at Malwarebytes about CloudFlare. They absolutely refuse to take down people who abuse their network- at best they'll block a single file from being distributed, but then the malware authors simply change the name of the file (or, more commonly, dynamically name the file something completely random). Their network is fantastic for malicious activity, not only because of the technology but because of their policies around it.
They will do everything to keep bad sites up, even flat out lying. Here's Matt Prince, their CEO, claiming that Malwarebytes was blocking their CDN because of "political" reasons, even though we had emailed him actual PCAP files showing that their network was distributing malware-
Despite the fact that Malwarebytes actively engages with communities and groups that teach people who to manage malware removal, and have always stood for free speech and only removes harmful software, Matt Prince tried to deflect front the truth of the situation by claiming this was about censorship. Really all it was about was that multiple clients of theirs were hosting pages that were actively infecting thousands of computers.
To make matters worse they put these customers who are hosting active exploits and malware right next to their small business customers, so any time someone threatens to block them they hide behind the innocent victims who are caught in the cross fire.
I should point out that I no longer work at Malwarebytes, and this all took place several years ago. I am only speaking about the portions of this that were public, and you can find all of that in the Malwarebytes forums and other places online.
As a security analyst, Cloudflare is a great friend and a terrible enemy. I've had numerous scenarios where I request information or takedowns of websites hosting blatantly malicious content, and not only do they refuse to cancel service, but they won't even give you the real IP address of the domain even if you have considerable evidence that abusive content is hosted there.
The most they'll do is give you the name of the hosting company, and even then getting that is like pulling a tooth. And of course, once you contact the hosting company, it can become like a chicken-and-egg problem "you'll need to contact the DNS provider so I know what server this is being hosted on." A hosting provider that issues thousands of VPSs and has a big IP space may not be able to find the offending user just given a domain name.
On the plus side, I use Cloudflare on many of my sites for the free DDoS protection, IP anonymizing, and anti-bot features. So far it's been great.
In all 3 links this is the only relevant part I've been able to find regarding them being malicious:
Heck, if the DDoS for hire services protect themselves against DDoS attacks by using CloudFlare then CloudFlare must be damn good!
So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a village and then have them perform criminal activity on each other.
The link to Kreb's is basically the same: people protecting themselves. Should CloudFlare play for judge and ban people that do not violate their terms? Because I'm sure they boot people that perform illegal activities on their network or otherwise harm their network from within, but I can see why they don't proactively take down any website mentioning "we offer DDoS attacks". Like I said before, that person A kills another person doesn't mean that another person may kill person A, at least not within our current laws. Even if it did, is CloudFlare the one who should be calling the shots?
Finally your first link is someone complaining to CloudFlare about LOIC (or related perl scripts launched from VPSes) and cloudflare responds that they see no harmful traffic and that logs or other details should be attached. Merely saying "hey I'm having trouble" has never gotten anyone further in resolving issues. That's why we have logs so that CloudFlare can check their own logs to see what happened. Perfectly reasonable.
So yeah elaboration is necessary. I do not see why CloudFlare is harmful.
The point being made above is that Cloudflare charges users to protect them from attacks, but they're also providing protection (from attacks and identification) to the people performing the attacks. To many, it appears that they're helping to allow malicious activity because it benefits the sale of their services.
Should CloudFlare play for judge and ban people that do not violate their terms? Because I'm sure they boot people that perform illegal activities on their network or otherwise harm their network from within, but I can see why they don't proactively take down any website mentioning "we offer DDoS attacks".
DDoS attacks are illegal in most countries, including the US where CloudFlare operates. It would be reasonable for them to include something in their terms about not allowing illegal activities. Then, if it's brought to their attention via a verifiable abuse complaint, yes, they should cease providing service to that user. They are a private company and do not have the obligation to provide service to any particular person; there is no "rights" issue here.
Proactively, as in proactively monitoring and reviewing each site they provide service to, would no doubt be a huge burden and difficult or impossible, but I don't think anyone has suggested that. The only thing they need to be doing is the same as any responsible ISP, have an abuse@ mailbox (which they do), review and take the appropriate action on complaints.
If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.
1. Websites hosting services that have no other purpose but to DDoS other computers are absolutely illegal. Many such sites have been taken down by the FBI before, and both users and owners of the sites have been arrested. The problem is that there are many hundreds of such sites and tens of thousands of users, and law enforcement simply can't take down each and every one. Cloudflare is relying on the fact that most people won't be able to get a subpoena or file a lawsuit.
2. You could apply that same argument to any hosting provider. They're just letting people see content that you yourself have uploaded; why should they act as Internet police? And yet every hosting provider has a legal responsibility to take action if someone is using their services to spread malware, launch DDoS attacks, or hack other websites.
Cloudflare is able to weasel itself out of it because it is not actually a hosting provider. However, they won't even let you discover the real hosting provider after showing proof of extremely blatant criminal activity. This is why many criminals flock to them: they know they will be harbored and their botnet command & control / DDoS service / malware distribution network can stay up for longer than it would normally.
I work in the information security field and we're definitely seeing more and more malicious network operators moving to Cloudflare and staying there for a long time.
The legal system simply cannot process every single civil or criminal complaint everyone in the US may have. If a security researcher had to go through a court, and/or law enforcement, every single time they wanted a malicious domain taken down then their work would be nigh impossible.
Legal due process should be required when there are legal penalties or punishments. In this case, the bot herders and malware distributors are not subject to any criminal or civil penalties in response to abuse complaints: they do not go to jail and are not fined. Some of them will be fined or imprisoned, many years later, but everyone's better off if their botnets are shut down immediately instead of in 2-5 years.
It's a dealing between private entities: private entity X agrees to stop providing server or domain hosting for the bot herder after seeing a good faith report. A provider has every right to stop offering you service.
Without this sort of cooperation between entities, the Internet would be even more of a mess right now.
I agree they should not be policing. Instead they should allow you to contact the people who are hosting the actual content. Which is where DMCA notices have to go to, for example. Since they do not host the content, they claim the DMCA should not be sent to them, but they won't tell you who to contact instead.
So what? It's not their job to help copyright holders, their job is to protect their clients' privacy. Even the cops have to get a court order to find someone's private data from a business, but since it's copyright every man and his dog claiming to be the copyright holder should be handed private information willy nilly?
So, would you consider a site where you can click a button and have a DDOS attack launched for you to be illegal? Because that's exactly what's being referred to here, "DDOS-as-a-service".
Have fun filing lawsuits and sending out subpoenas when you're just trying to host a game server as a hobby and not making money off it. Cross-jurisdictional issues will also make this very difficult, even if you know who the attacker is.
Sure. I made a post a few weeks ago at https://news.ycombinator.com/item?id=7880514. There's other relevant posts in the same thread as well, but that's probably the best overview.
I use their service and am a bit concerned that I've not heard about this until now and taking a look at their blog/website I see no information about this.
Comments
FWIW, in my experience, No-IP is very, very responsive and helpful to abuse complaints. Though that is the extent of my experience with them, I've never thought them to be actively harboring malicious activity (unlike, say, CloudFlare).
At CloudFlare, we have a Trust & Safety team dedicated to dealing with the abuse of our network. We sit in front of more than 2 million sites. The vast majority of them are not controversial (the site you're reading this on, for instance), but some are not.
The majority of the abuse requests we receive are DMCA requests, but we get other reports as well. Dealing with these requests is a hard problem because a large number of the abuse requests we receive turn out to be attackers trying to get the origin IP in order to circumvent our protection. As I've blogged about before (http://blog.cloudflare.com/thoughts-on-abuse), we've designed an abuse system that attempts to act as a proxy: passing abuse requests to the customer and their host without exposing the customer's origin to attack.
Malware is one of the situations where we'll actually take content down because it is, per se, harmful. However, we also don't think terminating the customer who has malware hosted on their site is a good solution. Since we're a proxy, terminating the customer doesn't remove the malware from the Internet but instead just kicks the problem down the road to the host. Instead, we developed a system that replaces the infected URLs with a warning page to protect users. This has the ancillary benefit when a site is being used for botnet command and control of allowing us to gather data on machines that make up the botnet. This data is fed back into our system in order to better protect our customers and we're talking other organizations about a way of responsibly sharing this data.
Our Trust & Safety team works with trusted malware reporters regularly, including the team at Microsoft that handled the no-ip.com takedown. We will continue to adjust our process to walk the careful line between ensuring our network isn't causing per se harm while, at the same time, avoiding the risk of becoming a censor.
Matthew Prince / Co-founder & CEO, CloudFlare
My own comments about your company are based on what I described in https://news.ycombinator.com/item?id=7880514. Would you care to respond to my statements in that post?
And without your usual comment of "the attack traffic is not from our network, so it's not our problem".
Sure. Pardon the copy-and-paste reply, but it's a perfect opportunity for me to publish up a draft blog post I wrote half a year ago in anticipation of a Brian Krebs post on the topic of Booter sites. Brian's article didn't turn out nasty enough to warrant a response, but I've had the post sitting around in by drafts folder for a while and it addresses your points as well.
========
Why a Hunger Games-Like Vision for the Internet is Wrong
Earlier this afternoon Brian Krebs, a well-respected security writer, published a story which, in part, calls for CloudFlare to censor the websites of a handful of our users [http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...]. These websites are known as "booter" sites. The sites claim to offer point-and-click DDoS services. The thrust of Brian's argument is that CloudFlare is a hypocrite for allowing these sites that advertise DDoS services to be protected by our network while, at the same time, offering as a core feature the ability to stop DDoS attacks.
Brian acknowledges that there's a bit more nuance to the argument. He understands that CloudFlare is not a hosting provider and that terminating any customer wouldn't make the content of the booter sites go away, it would just make them slower and more vulnerable to attack. He also acknowledges that no attack traffic actually originates from CloudFlare's network. His assumption, which we discussed at length before he published the article, is that if CloudFlare weren't in the equation then the booter sites would simply DDoS each other into oblivion.
Stop for a second and think about that: Brian is arguing for a Hunger Games-like vision of the Internet. It's the functional equivalent of if the police stopped prosecuting crimes committed against people they suspected to be criminals.
Brian is not the first person to make this argument and he won't be the last. A few weeks ago Kayne West's attorneys contacted CloudFlare insisting that we terminate protection for a customer they said was causing irreparable harm to their client: the parody crypto currency called Coinye. Ken Carter, our legal counsel, explained to Mr. West's lawyers that terminating the Coinye CloudFlare account wouldn't make it go away, it would just make it more vulnerable to attack. They thought that would be terrific. Ken respectfully disagreed.
CloudFlare's mission is to build a better Internet. Inherently there is content on our network that I find distasteful or even harmful. In the past, we've been called to task by other journalists [http://blog.cloudflare.com/cloudflare-and-free-speech] for allowing controversial websites to use our network. There is currently a campaign that has gathered over 22,000 signatures [http://www.change.org/petitions/matthew-prince-remove-chimpm...] for us to terminate the account of what I consider a horribly racist and distasteful website.
While I, personally, agree that the site the petition was started over is truly awful, I don't believe my personal opinion of what is good or bad content should be what governs what is allowed online. If CloudFlare succeeds, even in small part, at building a better Internet, inherently we must honor and respect one of the Internet's greatest qualities: that it is a network open to anyone.
Note that this isn't everyone's policy. Amazon, for instance, terminated Wikileak's account after political pressure [http://www.theguardian.com/technology/2010/dec/11/wikileaks-...]. More recently an article circulated that they were censoring books where people fantasized about having sex with dinosaurs [http://observationdeck.io9.com/amazon-now-at-war-with-dinosa...]. Other CDN providers are notorious for taking content offline at the first hint of pressure. We don't do that, even when the pressure comes from someone we truly respect like Brian. Fundamentally, we won't play the role of the Internet's morality cops. It's above our pay grade.
Booter sites, you may argue, are different. But the key question is where do you draw the line. If a site says you can push a button and launch an attack should we take that down? What about one that has a phone number you can call? Or gives you instructions on launching the attack yourself? CloudFlare is many things, but one thing we are not is the Internet cops.
Don't get me wrong, we don't believe in a lawless frontier. While we believe deeply in principles of due process and will push back against what we deem abusive legal requests [http://blog.cloudflare.com/fighting-back-responsibly], ultimately if ordered by a court through valid legal process we will comply. While booter sites may be successful at using us to protect their content from being knocked offline by a DDoS attack, they will not be successful at using us to hide from law enforcement if they are breaking the law.
Brian and I have known each other for almost a decade. He left the Washington Post and started Krebs On Security around the same time as we were launching CloudFlare. I actually tried to hire him back then. Thankfully he didn't accept the offer because he has become one of the leading security journalists writing anywhere today. He breaks important stories, which is something we need in the security space.
On this issue, I respect Brian's opinion but think he's ultimately wrong, That said, I have no problem with him fostering the debate. I think the discussion is hard, but it is healthy and important. To that end, if there are any large security or technology conferences that would like to host such a debate between me and Brian on stage, just let me know when and where and I'm in.
First off, thankyou for a detailed and well laid out post.
I do however think that there is a material difference between hosting unpleasant speech (to which the counter is speech pointing out that the speaker is wrong/idiotic/etc) and hosting malware/botnet sites (to which the counter is... what? what IS the counter to a sufficiently large botnet? ultimately we all have a limit at which point we can receive no more traffic. You might not have hit it - yet - but you will).
The internet - as you are aware - is based on protocols not designed with any significant security in mind. No-one in their right mind would today sit down and design something like BGP, for example. With that in mind, any large provider (or large consumer with capability to cause harm) has the responsibility to be a good citizen of the internet, and not to (by action or inaction) advance the agendas of those who would see its demise. As much as it might be convenient from an operational POV, and justifiable from a moral POV, washing your hands of responsibility and saying "It's not up to us, it's up to the courts" just doesn't work when the infrastrucure we're all building on is so very fragile. I'd also like to note that there's a semi-hidden US bias here - what if the target of a botnet, who's admin interface is hosted by CF - is based in a country where there is no reasonable ability to recourse to the US courts? Iran, for example?
It's admirable that you do not censor content in response to political pressure, but there IS a difference between protecting freedom of speech and protecting malware, and saying that censoring the malware is a slippery slope is at least partly disingenuous - any vaguely controversial decision can be described as a slippery slope to something else. Please at least consider making it easier for those of us who are trying to fight malware, botnets, etc, etc to get the original source of the content. I know this will involve some human judgement, and invetiably some mistakes and poor descions - but that would still in my view be far prefferable to what we have now. Thanks.
Agree, which is why we do take malware and phishing sites, which we can judge as per se harmful, offline. Read more here:
http://blog.cloudflare.com/thoughts-on-abuse
Malware and sites advertising so-called "booter" services are different discussions.
(Sorry I'm just responding to all this now, 15 hours later)
There's an important distinction here. You refer to "sites advertising so-called "booter" services." However, with the kind of sites I speak of, "sites providing so-called "booter" services" would be a better description. They aren't just advertising it; enter a valid username and password, enter an IP, click the "attack" button and an attack is launched, all from that single site.
Malware, phishing, and booters have two things in common: they have far-reaching effects (that is, they affect other, unrelated/unwilling people) and they are not in any way good for the target of the effort. Malware is only good for the operator who benefits from the keylogger, showing ads, or whatever; phishing is only good for the operator who benefits from the stolen information; booters are only good for the booter operator (who profits from selling it) and for the user who paid for it to attack a target. Based on that, it's difficult for me to see the difference between the harmfulness of any of these.
In your post, the standard you applied to malware and phishing was "harmfulness" (in your opinion). I agree with that standard, and I think you'll be hard-pressed to find a single person who agrees that any of these three issues are not harmful. So, in your opinion, what makes booters less harmful than malware and phishing sites, which you are willing to take offline?
Censorship is a slippery slope, indeed. But I think it is generally accepted that _some_ basic level of what is effectively censorship, is a necessary evil for the health of the Internet. For example, malware and phishing sites, as you mentioned; spam; DDoS attacks. That's why laws exist in so many jurisdictions to prohibit all of these, and why the AUP of every single reputable ISP in existence prohibits them. This isn't uncharted territory, this isn't something new CloudFlare is just getting into - the industry standard (and legal standard) is to prohibit all of these.
I find it interesting he never responded to this. He was on the site the next day, so he must have seen your comment.
His refusal to remove booter sites from CloudFlare is completely indefensible. Any attempt on his part to suggest otherwise can only be interpreted as evidence of guilt. There is no possible arrangement of words which can make it okay.
What makes a site hosting malware per se harmful, and how can you consider malware per se harmful while booters avoid being classified identically? Malware is illegal and obviously a detriment to the internet, as are booter services. Perhaps you're just willing to deal with malware so you don't end up in the same boat as No-IP did here.
Booter services are so incredibly common that the police aren't going waste their time on them, especially since once the cops get the real IP from your convenient obfuscation service, it's likely hosted in China, Russia, or some other country where no action will be taken.
That is incredibly disingenuous. It's simple: if you knowingly facilitate an illegal service on your site, your service gets terminated. Every other reputable CDN and hosting provider can figure this out but somehow you can't? Give me a break.
He appears to choose to let the decision as to whether they 'knowingly facilitate an illegal service' be taken by law enforcement rather than by Cloudflare.
So I don't see anything disingenuous whether you disagree or not.
Trust & Safety maybe, but it's still impossible to use CloudFlare in Russia, due to harboring some drug-selling websites at your services. ISPs ban them by IP, and taking whole subnetworks of websites that reside on the same IP down with them too.
As much as I love your services, it's not possible to use them here, and ministry of communication even issued a recomendation not to use your services due to your unresponsiveness about takedown requests.
spam?
While I'm not familiar with the exact situation here, I suspect the real problem is that the malware domains are being automatically created en masse, and No-IP have been slow or reluctant to do anything to slow that down. Being responsive to complaints is good for small-scale problems involving individual domains, but basically useless for large-scale abuse.
what if a company like microsoft approach you and say "look, i make billions while you make a few thousands, but please, go ahead and change your service because it is impacting my billion dollar windows sales and i can't be bothered to patching it on my product"
granted, i'm not familiar with the matter. but I know what I would answer. also, removing noip or noip enabling whatever microsoft was bullying them to implement, would just delay it a few days until the worm creators rolled out their own service. heck that can even motivate them to get creative and encode IPs in a obfuscated pastebin, or stenographed in cat pictures in reddit, or noise mp3 in soundcloud... maybe having them rely on noip was good....
but again, i have no knowledge of the matter. maybe noip was being paid even after knowing it was for worms. who knows?
How can they patch it in their product without turning desktop Windows into something like iOS or Windows Phone/RT?
Even Android has a ton of malware so the notion that Windows is somehow more hole ridden than other platforms stopped being true starting about 10 years ago with their Secure computing initiative. If the user can install Firefox, they can install malware. If Firefox doesn't need to get permission from MS for their next version, Windows cannot distinguish between Firefox.exe and Codec_Flash_Shady.exe. Sandboxing will disable system level utilities.
MS is capable of making secure OSes. How many viruses and trojans do the 3 Xboxes, Windows Phone and RT have? Even Windows Server is pretty secure(atleast as secure as Linux) unless the admins start browsing on it. Malware is a real threat to any popular OS unless third party apps are entirely blocked or restricted by the use of a approval based App Store. Windows gives much more control to the user, which is why many users are able to stay away from infections. And it's ironic that you're blaming MS here instead of the folks that propagate it(including a YC company https://www.techdirt.com/articles/20130115/17343321692/why-a...) and people who install it(users).
Remember the shitstorm that was raised against MS on here and elsewhere when they tried to secure users by preventing undetectable rootkits by enabling Secure Boot?
Linux solved this problem almost twenty years ago. You have a package manager that does not contain malware and does contain 95% of the software any user would install on a regular basis, and you make the process of installing software outside of the package manager possible but not trivial. You download a binary and it doesn't have the execute bit set, and you don't get any kind of friendly thing that pops up to ask you if you want to set it. So the sort of person who can't distinguish between legitimate software and malware also can't figure out how to install the malware, but you don't prevent people who know what they're doing from doing what they want.
The problem with Windows is that it has no package manager, so the default method of installing legitimate software is identical to the method of installing malware. The problem with Android is that the malware is in the app store. All you need is a known-good repository where you can get almost everything safely and people can spend most of their time. You don't then need to build a prison around it and trap everyone inside because most people will want to stay in the safe place. The people who want to (and can figure out how to) wander outside are the people who know what they're doing, and know to be suspicious of the things that conspicuously haven't been vetted by anyone else.
Package manager and repositories are not completely foolproof.
http://www.zdnet.com/blog/hardware/how-much-more-malware-is-...
If Linux were to get as popular as Windows, the problem is going to way worse.
Also, there's lot of Android malware that's installed from outside the app store, typically for piracy reasons which is another big malware vector on Windows.
Nothing is completely foolproof.
http://www.theguardian.com/technology/appsblog/2013/aug/19/i...
Everybody says this but it doesn't make any sense. Are the repositories going to get more malware when there are more people and funding available to notice and report it?
All the more reason why it wouldn't happen on Linux. Nobody really pirates LibreOffice or gcc.
Hey pktgen: I'm new at CloudFlare, but I'd be really interested in chatting with you (or grabbing a beer) to hear if there's something we could do better. Contact info in my profile. I'll be at Defcon and HOPE too if that's easier.
(Free speech vs. keeping the overall network safe is a hard decision. I think all pro-privacy and pro-liberty services have had to answer this question -- same thing happened with cypherpunks list, HavenCo, Freenet, various payment systems, etc.)
Thanks, I'm also interested in having a chat with you about it, so I'll take you up on that offer in a bit. :)
(Offer is open to anyone who ever has security/privacy/etc. issues w.r.t. CloudFlare. I like talking to people about security and "Internet politics", either at conferences or at home.)
Care to elaborate?
I have multiple horror stories from my days at Malwarebytes about CloudFlare. They absolutely refuse to take down people who abuse their network- at best they'll block a single file from being distributed, but then the malware authors simply change the name of the file (or, more commonly, dynamically name the file something completely random). Their network is fantastic for malicious activity, not only because of the technology but because of their policies around it.
They will do everything to keep bad sites up, even flat out lying. Here's Matt Prince, their CEO, claiming that Malwarebytes was blocking their CDN because of "political" reasons, even though we had emailed him actual PCAP files showing that their network was distributing malware-
https://forums.malwarebytes.org/index.php?/topic/108447-my-s...
Despite the fact that Malwarebytes actively engages with communities and groups that teach people who to manage malware removal, and have always stood for free speech and only removes harmful software, Matt Prince tried to deflect front the truth of the situation by claiming this was about censorship. Really all it was about was that multiple clients of theirs were hosting pages that were actively infecting thousands of computers.
To make matters worse they put these customers who are hosting active exploits and malware right next to their small business customers, so any time someone threatens to block them they hide behind the innocent victims who are caught in the cross fire.
I should point out that I no longer work at Malwarebytes, and this all took place several years ago. I am only speaking about the portions of this that were public, and you can find all of that in the Malwarebytes forums and other places online.
Where exactly does Matt accuse Malwarebytes of blocking their CDN because of "political" reasons? Your whole post looks like blatant lies.
As a security analyst, Cloudflare is a great friend and a terrible enemy. I've had numerous scenarios where I request information or takedowns of websites hosting blatantly malicious content, and not only do they refuse to cancel service, but they won't even give you the real IP address of the domain even if you have considerable evidence that abusive content is hosted there.
The most they'll do is give you the name of the hosting company, and even then getting that is like pulling a tooth. And of course, once you contact the hosting company, it can become like a chicken-and-egg problem "you'll need to contact the DNS provider so I know what server this is being hosted on." A hosting provider that issues thousands of VPSs and has a big IP space may not be able to find the offending user just given a domain name.
On the plus side, I use Cloudflare on many of my sites for the free DDoS protection, IP anonymizing, and anti-bot features. So far it's been great.
A quick search shows exactly what he means. No elaboration necessary.
http://www.webhostingtalk.com/showthread.php?t=1235995
http://www.organicweb.com.au/17240/internet/cloudflare-secur...
http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...
In all 3 links this is the only relevant part I've been able to find regarding them being malicious:
So they protect their customers from DDoS attacks. All of them. I see nothing bad in this. Saying they shouldn't is like saying a government should put all criminals together in a village and then have them perform criminal activity on each other.
The link to Kreb's is basically the same: people protecting themselves. Should CloudFlare play for judge and ban people that do not violate their terms? Because I'm sure they boot people that perform illegal activities on their network or otherwise harm their network from within, but I can see why they don't proactively take down any website mentioning "we offer DDoS attacks". Like I said before, that person A kills another person doesn't mean that another person may kill person A, at least not within our current laws. Even if it did, is CloudFlare the one who should be calling the shots?
Finally your first link is someone complaining to CloudFlare about LOIC (or related perl scripts launched from VPSes) and cloudflare responds that they see no harmful traffic and that logs or other details should be attached. Merely saying "hey I'm having trouble" has never gotten anyone further in resolving issues. That's why we have logs so that CloudFlare can check their own logs to see what happened. Perfectly reasonable.
So yeah elaboration is necessary. I do not see why CloudFlare is harmful.
The point being made above is that Cloudflare charges users to protect them from attacks, but they're also providing protection (from attacks and identification) to the people performing the attacks. To many, it appears that they're helping to allow malicious activity because it benefits the sale of their services.
This sounds like the same argument would apply to selling bullet proof jackets to people who also own guns.
DDoS attacks are illegal in most countries, including the US where CloudFlare operates. It would be reasonable for them to include something in their terms about not allowing illegal activities. Then, if it's brought to their attention via a verifiable abuse complaint, yes, they should cease providing service to that user. They are a private company and do not have the obligation to provide service to any particular person; there is no "rights" issue here.
Proactively, as in proactively monitoring and reviewing each site they provide service to, would no doubt be a huge burden and difficult or impossible, but I don't think anyone has suggested that. The only thing they need to be doing is the same as any responsible ISP, have an abuse@ mailbox (which they do), review and take the appropriate action on complaints.
As far as I understand it the problem is as follows:
1. Bad guys get a site behind cloudflare, and host illegal content
2. You want to report said bad guys to their host, for whatever reason.
3. You discover they use cloudflare. You now do not know where they are hosted.
4. Cloudflare will not tell you their actual IP addresses.
If it's illegal and you're harmed I'm sure you can sue the people who did it and CloudFlare will have to hand over IP addresses. But is it CloudFlare's duty to police the Internet? Like ISPs, I think they should be content neutral unless illegal content like child porn is being hosted. Merely talking about services is not illegal as far as I know; only performing the DDoS attacks is.
1. Websites hosting services that have no other purpose but to DDoS other computers are absolutely illegal. Many such sites have been taken down by the FBI before, and both users and owners of the sites have been arrested. The problem is that there are many hundreds of such sites and tens of thousands of users, and law enforcement simply can't take down each and every one. Cloudflare is relying on the fact that most people won't be able to get a subpoena or file a lawsuit.
2. You could apply that same argument to any hosting provider. They're just letting people see content that you yourself have uploaded; why should they act as Internet police? And yet every hosting provider has a legal responsibility to take action if someone is using their services to spread malware, launch DDoS attacks, or hack other websites.
Cloudflare is able to weasel itself out of it because it is not actually a hosting provider. However, they won't even let you discover the real hosting provider after showing proof of extremely blatant criminal activity. This is why many criminals flock to them: they know they will be harbored and their botnet command & control / DDoS service / malware distribution network can stay up for longer than it would normally.
I work in the information security field and we're definitely seeing more and more malicious network operators moving to Cloudflare and staying there for a long time.
Is requiring legal due process such a bad thing?
In some cases? Yes.
The legal system simply cannot process every single civil or criminal complaint everyone in the US may have. If a security researcher had to go through a court, and/or law enforcement, every single time they wanted a malicious domain taken down then their work would be nigh impossible.
Legal due process should be required when there are legal penalties or punishments. In this case, the bot herders and malware distributors are not subject to any criminal or civil penalties in response to abuse complaints: they do not go to jail and are not fined. Some of them will be fined or imprisoned, many years later, but everyone's better off if their botnets are shut down immediately instead of in 2-5 years.
It's a dealing between private entities: private entity X agrees to stop providing server or domain hosting for the bot herder after seeing a good faith report. A provider has every right to stop offering you service.
Without this sort of cooperation between entities, the Internet would be even more of a mess right now.
I agree they should not be policing. Instead they should allow you to contact the people who are hosting the actual content. Which is where DMCA notices have to go to, for example. Since they do not host the content, they claim the DMCA should not be sent to them, but they won't tell you who to contact instead.
So what? It's not their job to help copyright holders, their job is to protect their clients' privacy. Even the cops have to get a court order to find someone's private data from a business, but since it's copyright every man and his dog claiming to be the copyright holder should be handed private information willy nilly?
So, would you consider a site where you can click a button and have a DDOS attack launched for you to be illegal? Because that's exactly what's being referred to here, "DDOS-as-a-service".
Have fun filing lawsuits and sending out subpoenas when you're just trying to host a game server as a hobby and not making money off it. Cross-jurisdictional issues will also make this very difficult, even if you know who the attacker is.
Fair trials are hard, let's go shopping!
Thanks, what I searched for didn't really bring anything up.
Sure. I made a post a few weeks ago at https://news.ycombinator.com/item?id=7880514. There's other relevant posts in the same thread as well, but that's probably the best overview.
I use their service and am a bit concerned that I've not heard about this until now and taking a look at their blog/website I see no information about this.
Why would you expect them to be talking about this?
i believe everything I see in uncited hacker news comment threads too.
Which part of this is un-cited? The article linked is fairly conclusive evidence that this is in fact a real thing.