I'm Jeff. I write code and ride a unicycle, among other things. #unicycle #ham #cycling #woodworking #selfhosting #homeserver #infosec #privacy #python #golang #dotnet #geocaching
I'm Jeff. I write code and ride a unicycle, among other things.
#unicycle #ham #cycling #woodworking #selfhosting #homeserver #infosec #privacy #python #golang #dotnet #geocaching
I'm Jeff. I write code and ride a unicycle, among other things. #unicycle #ham #cycling #woodworking #selfhosting #homeserver #infosec #privacy #python #golang #dotnet #geocaching
I'm Jeff. I write code and ride a unicycle, among other things. #unicycle #ham #cycling #woodworking #selfhosting #homeserver #infosec #privacy #python #golang #dotnet #geocaching
@tychotithonus@infosec.exchange @deepthoughts10@infosec.exchange After reading both your comments, I spent some time trying to understand both sides of the perpetual Cloudflare controversy. Lots of stuff I didn’t know (like yuck!).
Probably opening a can of worms here, but in general, I find Cloudflare’s core argument fairly persuasive. DNS, DDoS protection, WAF and CDN services are infrastructure, and should be treated more like utilities than publishing platforms.
I’m quite uncomfortable with a private company acting as the morality police for legal content, even content I find reprehensible. When Cloudflare withdraws DDoS protection, it effectively opens a site up to being smashed off the Internet by anyone with enough resources. That lets the Internet at large bypass legal and democratic processes and decide, through brute force, what is allowed to remain online. Governments pressuring Cloudflare to withdraw protection creates another obvious route to censorship.
Cloudflare’s policy of forwarding complaints to the company actually hosting the content seems reasonable, at least on paper. Whether that process is too onerous or ineffective in practice, I don’t know.
The distinction that matters to me is that Cloudflare’s policies appear to be quite different when it actually hosts the content through services such as Workers and Pages. Presumably Drop belongs in that category too. In those cases, “we’re just infrastructure” becomes a much weaker argument.
I also appreciate the uncomfortable reality that the things I love about Cloudflare are exactly what ne’er-do-wells love about it too. It is easy to set up, cheap, often free, and remarkably robust. Making those benefits available to ordinary people without also making them available to bad actors is an extremely difficult problem.
I don’t know how you mechanically and reliably distinguish malicious content from legitimate content. Is this copy of Bob’s Furnace Repair website part of a phishing attack, or is Bob’s nephew building a prototype of the company’s new site? Depends on how it's getting used?
Drop seems legitimately useful, but I can also see the risks:
So I guess where I land is that Cloudflare makes some legitimately useful tools. I use CF heavily for many of my own projects. Drop looks like a handy thing to have in my toolbox too, and I think I’m glad it exists.
Sure, it can be abused, just like Cloudflare’s other services can. But what sufficiently powerful system or tool can’t be?
My gut reaction is that it feels unfair to paint Drop as some new abomination when plenty of similar services already exist. Other than potentially being harder to block, because you certainly can’t block Cloudflare’s entire ASN, I’m not convinced it meaningfully changes the landscape.
At the corporate layer, perhaps the practical answer is, as you say, to block *.workers.dev, *.pages.dev, and other similar shared-hosting domains, then allow-list the specific services people actually need.
I'm Jeff. I write code and ride a unicycle, among other things. #unicycle #ham #cycling #woodworking #selfhosting #homeserver #infosec #privacy #python #golang #dotnet #geocaching