Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My main issue was this:

> Visitors to any of the Kiwifarms sites that use any of Cloudflare's services will see a Cloudflare block page and a link to this post.

Cloudflare was providing security from DDoS attacks. Then all the sudden they arbitrarily decided to hijack their domain. It would be one thing to stop providing protection. It’s another to say “no you see our content now”.

It would be like security at an event deciding to put in a band no one paid for. But still taking the money from the people hosting the event. The attendees are upset, the venue is upset, the original bands are upset.

Pretty sure that is a breach of contract. Feel free to drop them, but redirecting is wtf. Particularly, when they may be interfering with an investigation (as they said, cloudflare already took it upon themselves to involve law enforcement- who didn’t feel it necessary to shut it down).



I think it’s covered in their TOS:

“We may at our sole discretion suspend or terminate your access to the Websites and/or Online Services at any time, with or without notice for any reason or no reason at all. We also reserve the right to modify or discontinue the Websites and/or Online Services at any time (including, without limitation, by limiting or discontinuing certain features of the Websites and/or Online Services) without notice to you. We will have no liability whatsoever on account of any change to the Websites and/or Online Services or any suspension or termination of your access to or use of the Websites and/or Online Services.”

Kiwifarms controls their DNS; they can change NS records as needed, so I wouldn’t say the domain is hijacked.


> Kiwifarms controls their DNS; they can change NS records as needed, so I wouldn’t say the domain is hijacked.

While I agree in part, the DDoS protection isn’t meant to serve alternative pages per-se. It’s meant to mitigate hostile actors by making them check a box or something.

It would be one thing to take it down (terms clearly make that okay); but directing to alternative content I see as a possible breach.


IANAL and you could be right.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: