HN user

5ESS

101 karma
Posts9
Comments103
View on HN

It wasn’t a mistake it was a strategic cost benefit analysis. Many people myself included don’t even use the webcam at all and would rather keep it blocked with a sticker most of the time. If most people statistically don’t use webcam on their MacBook why would it make sense to increase the price to have it? The few times I opened FaceTime app on the MacBook 2020 it looked fine to me anyways. I certainly wouldn’t like paying say an extra $100 for a better webcam I don’t even use.

Why do they think they have the right to kill domains that people have entrusted them with their custodianship? I don't understand why they have to set any domain to pendingDelete status, short of a court order. It sounds like something ripe for abuse. I don't see what the benefit of overzealous deletion is. If they think a domain is malicious they want to stop it they can simply disable it via NS records without actually deleting it for the remainder of the contract payment cycle. People shouldn't have to live in fear that their domain might randomly be deleted with no recourse. Perhaps new legislation is necessary to protect people's domains from random registrar deletion.

The process wasn't described inaccurately in the OP post. What you said here doesn't contradict anything in the OP post and infact confirms that it happened.

domains determined to be malicious registrations/transfers may be deleted

The person in the story's domain was determined to be malicious and deleted for fraud. (however in reality it wasn't) and thus deleted, like you said.

Cloudflare allows transfers of domains out of Cloudflare’s registrar immediately, unless there are indications of potentially malicious or fraudulent activity.

This is what the OP post described has happened in the story. The person's domain was determined fraudulent and was thus disallowed from transfering out, like you said.

Cloudflare follows the standard industry practice followed by virtually all domain registrars of blocking the transfer out of domains deleted for what appears to be potentially malicious purposes.

The fact is, a serious mistake was made by Cloudflare and evidently the guy had no way to appeal the decision outside of Hacker News. It is clear that this industry practice needs reform. Perhaps instead of trying to dismiss/downplay this your time would be better spent improving the process or maybe implementing some form of due process/trial for these extremely important accounts. An accidental domain deletion seems to be no big deal to you. But in reality its a nightmare that can cause serious harm to a persons life and livelihood.

Try to imagine it yourself how it would feel. if one day all your important accounts stopped working. all your domains has been hijacked! Why? because your registrar set it to DELETED on short notice due to random false-positive-fraud and a sniper re-registers it elsewhere! there is nothing you can do about it, your registrar stonewalls you. You're completely screwed and theres nothing you can do about it. Your valuable domain is gone. All your important accounts tied to email on that domain get broken into. Your companies and brand are destroyed. No one ever suspects their properly secured domain name will randomly be DELETED in < than the time it was registered for. This is a really traumatic event for people and not something that should be minimized.

Not everyone shares your enthusiasm. Yes, this is good for foreigners and corporations but it comes at the expense of native workers. it suppresses wages(often times immigrants are willing to do the same jobs at lower salaries), as well as makes it more difficult for native workers to find a job due to increased competition.

That’s terrifying. By far the worst part of this. If they ban somebody for TOS violations that is fair, but preventing people from transferring out their domain and setting it to pendingdelete is really insidious. What they are doing is akin to stealing anyone domain name permanently with no recourse. This may be grounds for a lawsuit.

In the US, anyones company can be financially destroyed by wealthy competitors who abuse the corrupt legal system via bad faith lawsuits like this one. In this case, his $35 million business is being destroyed by Match because simply because the name contains the simple English word “match”—a common word associated with matchmaking-a common word associated with dating services for decades before match.com existed, and also because it briefly utilized a “swipe” left/right system for likes—a most basic UI interaction concept which should never have been allowed a copyright to begin with. I’ve heard many such stories of companies being destroyed by having to pay 6-7 figure sums defending themselves from frivolous lawsuits like this one. The courts here are so corrupt here that it saddens me and made me lose faith after hearing so many such stories.

Say that, despite your linked recommendations for hiding the public IP, thousands of customers were under the impression that as long as no one leaked the IP, no one would be able to discover the site. They’re paying you a lot of money for security, yet that security can be completely undermined by a teen with a scanner tool. If there’s thousands of clients paying for anti-DDOS services yet their IP is easily findable, then it’s like…what are they even paying for? On a scale of thousands this probably adds up to a large sum of money…Money paid for pointless services rendered.

Thanks for clarifying that it had to be Github. The post you replied to says Gitbub or Cloudflare take it down. Either way, this issue should be brought to customers attention more clearly. Most people probably don’t know that the entire internet can be scanned in a matter of hours or days which might uncover their site. I’m curious how many customers are paying for your anti-ddos service yet their sites are easily findable using such a tool effectively rendering the service useless. Do you scan the internet yourself and proactively warn customers when their real IP is findable in this way?

It’s a story in itself that a simple script which locates a site’s real IP was taken down for TOS violations. Cloudflare doesn’t own the real IPs or something so it’s really unclear why they (or GitHub) were entitled to take down this repository. Just because it threatens their million dollar buisness model they think they can take it down? That’s wrong my friend. And people need to know. Cloudflare or GitHub overstepped it’s boundaries to help a corporation enforce security by obscurity. Since this method is proven to be preventable, why take it down? Instead of taking it down from public knowledge (which does nothing to stop cybercriminals with private forks) why don’t they help their customers mitigate the impact instead?

Also, they stopped blocking the Tor IPs now but this wasn’t always the case. Many people remember a few years ago the IPs were blocked.

I don’t trust Shodan (a Corporation) not to hide / omit certain results or certain ranges. A self hosted scanner that could be deployed on a cheap VPS would be a better solution. having the ability to scan the entire internet is pretty fascinating honestly. Who knows what kind of sick and bizarre content dredging the entire internet with no filters might dig up.

Before CloudFlare sends the FBI to my house..I’m not actually going to code this. It’s just an idea that exposes a problem. The problem is there’s a lot of Cloudflare customers who don’t have their servers configured properly to defend from it. If my amateur self can conceptualize this idea it means cybercriminals already have similar tools and are using them already so If you’re a site operator you should use this post as a warning and fix your servers ahead of time. However, it was messed up they might try to take down the tool rather then help mitigate the flaw.

So there’s only 4.2 billion possible IPv4 addresses where a site can live. A lot are reserved or unused, leaving about 3.7 billion possibilities. Household internet speeds are fast enough that it is within the realm of possibility that a computer could sequentially connect to every single IPv4 host on the entire internet in search for the target website. Specialty network cards with datacenter connections can scan the entire Ipv4 space in a matter of mere hours.

Interesting and both are sold out. They seem kind of rare. Probably for a reason! I guess it would be bad if somebody like…had a trashbag’s worth of them with “You Won 1 Free Bitcoin” noted and sprinkled them around commercial and public properties a 100mi radius. Or sent out 1,000 in the mail for example.

Too bad kaspersky has been banned/cancelled in my country (USA). Any alternatives? I don’t necessarily use antivirus, thought it was unnecessary with Windows 11 built in Security. But now my mind is changing… anyways There should be a open source tool for Windows that only allows only 1 trusted keyboard/mouse to input and monitors for anything sketchy in USB firmware. Seems easy enough to create.

Nobody can give a disabled person a helping hand anymore because there have been too many instances of disabled people suing good samaritans into oblivion when they fall and hurt themselves. At the very least an employee could be written up by their employer for touching a patron and at the worst they could be sued civilaly and have their lives ruined.