CloudFlare CEO blasts Anonymous claims of ISIS terrorist support

Anons are our customers, and we don't censor them either, says Prince


Matthew Prince, CloudFlare's cofounder and CEO, has hit back at Anonymous, which claimed his firm backs ISIS by keeping terror websites up and running.

CloudFlare is a content-distribution network: it acts like a huge sponge, soaking up deluges of internet traffic that would otherwise overwhelm small to medium-sized websites, and dishes out pages and web stuff to visitors.

On Monday, Anonymous vowed to knock ISIS-linked sites offline, and hijack the terror group's social media accounts used to recruit sympathizers. Anonymous also said it was "shameful" CloudFlare was "providing services to pro-Islamic State websites."

Prince told us hosting any content on his network is not an endorsement – there are millions of pages cached in his company's servers. And he said it was a bit rich for Anonymous to be pressuring CloudFlare to drop websites.

"I did see a Twitter handle said that they were mad at us," Prince told The Register on Tuesday. "I'd suggest this was armchair analysis by kids – it's hard to take seriously. Anonymous uses us for some of its sites, despite pressure from some quarters for us to take Anonymous sites offline."

If the cops or Feds come to San Francisco-based CloudFlare about one of its customers, and they have all the proper legal documentation to take down a site, then the Silicon Valley upstart is happy to cooperate, Prince said.

But more often than not, investigators want him to keep sites up rather than take them down. Read into that what you will.

"Even if we were hosting sites for ISIS, it wouldn't be of any use to us," he continued. "I should imagine those kinds of people pay with stolen credit cards and so that's a negative for us."

With more than four million customers, it's inevitable that some clients may be dodgy, he said. On whether a website should be allowed onto his cloud platform, he said he'd rather take advice from the police or the US State Department (which is also a customer) than from some faceless Twitter user.

It's not in CloudFlare's philosophy to just take down sites because management doesn't agree with the content, Prince said. Some hosting companies exercise tight control about what can be served, but his firm doesn't want that kind of power.

He cited a personal case from a few years back, after a hacker used stolen information about Prince to access his tax files and posted the details on a CloudFlare-hosted site. Prince says he didn't take the site down, although the US authorities did shortly afterwards since the hacker had also posted personal data from Michelle Obama and the head of the FBI.

Prince said that he recognized that tempers were high in the wake of Friday's Paris atrocity, but explained that we'd been here before and it's important that Europeans learn from America's mistakes.

"My European friends were very quick to criticize the US post-9/11 because of the Patriot Act," he explained. "There were plenty of people who said that you can't trust any US tech firm because of it. I have a feeling now that Europe will have its own reactionary reaction, and then EU companies won't be trusted." ®

Full disclosure: The Register is a CloudFlare customer.

Similar topics


Other stories you might like

  • Google, EFF back Cloudflare in row over pirate streams
    Ban akin to 'ordering a telephone company to prevent a person from having conversations' over its lines

    Google, EFF, and the Computer and Communications Industry Association (CCIA) have filed court documents supporting Cloudflare after it was sued for refusing to block a streaming site.

    Earlier this year, a handful of Israel-based media companies took Israel.tv to court, accusing it of streaming TV and movie content it had no right to distribute. The corporations — United King Film Distribution, D.B.S. Satellite Services, HOT Communication Systems, Charlton, Reshet Media and Keshet Broadcasting — won the lawsuit after Israel.tv's creators failed to show up to their hearings, and the judge ordered Israel-tv.com, Israel.tv and Sdarot.tv each pay $7,650,000 in damages. 

    In a more surprising move, however, the media outfits also won an injunction [PDF] in the United States in April against a slew of internet companies, among others, banning them from aiding Israel.tv in its piracy.

    Continue reading
  • Cloudflare explains how it managed to break the internet
    'Network engineers walked over each other's changes'

    A large chunk of the web (including your own Vulture Central) fell off the internet this morning as content delivery network Cloudflare suffered a self-inflicted outage.

    The incident began at 0627 UTC (2327 Pacific Time) and it took until 0742 UTC (0042 Pacific) before the company managed to bring all its datacenters back online and verify they were working correctly. During this time a variety of sites and services relying on Cloudflare went dark while engineers frantically worked to undo the damage they had wrought short hours previously.

    "The outage," explained Cloudflare, "was caused by a change that was part of a long-running project to increase resilience in our busiest locations."

    Continue reading
  • Cloudflare says it thwarted record-breaking HTTPS DDoS flood
    26m requests a second? Not legit traffic, not even Bill Gates doing $1m giveaways could manage that

    Cloudflare said it this month staved off another record-breaking HTTPS-based distributed denial-of-service attack, this one significantly larger than the previous largest DDoS attack that occurred only two months ago.

    In April, the biz said it mitigated an HTTPS DDoS attack that reached a peak of 15.3 million requests-per-second (rps). The flood last week hit a peak of 26 million rps, with the target being the website of a company using Cloudflare's free plan, according to Omer Yoachimik, product manager at Cloudflare.

    Like the attack in April, the most recent one not only was unusual because of its size, but also because it involved using junk HTTPS requests to overwhelm a website, preventing it from servicing legit visitors and thus effectively falling off the 'net.

    Continue reading
  • Man gets two years in prison for selling 200,000 DDoS hits
    Over 2,000 customers with malice on their minds

    A 33-year-old Illinois man has been sentenced to two years in prison for running websites that paying customers used to launch more than 200,000 distributed denial-of-services (DDoS) attacks.

    A US California Central District jury found the Prairie State's Matthew Gatrel guilty of one count each of conspiracy to commit wire fraud, unauthorized impairment of a protected computer and conspiracy to commit unauthorized impairment of a protected computer. He was initially charged in 2018 after the Feds shut down 15 websites offering DDoS for hire.

    Gatrel, was convicted of owning and operating two websites – DownThem.org and AmpNode.com – that sold DDoS attacks. The FBI said that DownThem sold subscriptions that allowed the more than 2,000 customers to run the attacks while AmpNode provided customers with the server hosting. AmpNode spoofed servers that could be pre-configured with DDoS attack scripts and attack amplifiers to launch simultaneous attacks on victims.

    Continue reading
  • Big Tech shrank the internet while growing its own power
    Classic internet ideas matter less now that CDNs and private networks dominate traffic

    Comment The internet has become smaller, the result of a rethinking of when and where to use the 'net's intended architecture. In the process it may also have further concentrated power in the hands of giant technology companies.

    Given the ever-expanding content and resources available online, and proliferation of connected devices, the notion that the internet has shrunk is counter-intuitive. But shrunk it has – to the point at which some iPhones do not immediately connect to the open internet.

    Those phones are iPhones running the latest version of Apple's iOS and the opt-in service called Private Relay. The iGiant bills Private Relay as a privacy enhancement because it obscures users' DNS lookups and IP addresses by funneling traffic over networks operated by Cloudflare, according to specs set by Apple.

    Continue reading
  • Cloudflare stomps huge DDoS attack on crypto platform
    At 15.3 million requests per second, the assault was the largest HTTPS blitz on record lasting 15 seconds

    Cloudflare this month halted a massive distributed denial-of-service (DDoS) attack on a cryptocurrency platform that not only was unusual in its sheer size but also because it was launched over HTTPS and primarily originated from cloud datacenters rather than residential internet service providers (ISPs).

    At 15.3 million requests-per-second (rps), the DDoS bombardment was one of the largest that the internet infrastructure company has seen, and the largest HTTPS attack on record.

    It lasted less than 15 seconds and targeted a crypto launchpad, which Cloudflare analysts in a blog post said are "used to surface Decentralized Finance projects to potential investors."

    Continue reading

Biting the hand that feeds IT © 1998–2022