NoGoolag
4.54K subscribers
13.1K photos
6.88K videos
587 files
14.1K links
Download Telegram
Cloudflare – The bad, the worse and the ugly?
What is
Cloudflare and why not to use Cloudflare!

Cloudflare, the operator of the probably best-known content delivery network, is not only very popular with black copiers. Credit card fraudsters, phishing site operators, blackmailers and terrorists also like to use the services of the Californian company. Volker Rieck takes a closer look.

In the USA, a large technology company is about to go public. Cloudflare from San Francisco wants to collect almost 3.5 billion dollars on the stock exchange in the first half of the year with the support of the investment bank Goldman Sachs. However, there are heavy shadows over Cloudflare. The spectrum of his customers ranges from credit card fraudsters and spammers to sites that operate copyright infringement as a business model and terrorist sites. Even US embargoes are undermined.

💡 What is Cloudflare?

The service of Cloudflare is the supply of a content Delivery network (CDN) - also content distribution network called. That is simplified said a type of turbo for web pages, so that these are delivered world-wide fast and surely. Cloudflare hangs itself thereby between the web page and/or the servers of its customers and the visitor of the side and/or user of a service and provides by purposeful control and distribution of the Traffics for a correspondingly high speed. In this way Cloudflare can offer also protection against overload attacks (DDoS) in the net.

💡 However, it offers a hidden feature:
the company anonymizes its customers.

By doing so, Cloudflare will put a screen over the original website or its server, making the operator of this site almost untraceable. If, for example, you want to know where a certain website is hosted, you only receive Cloudflare data, but you can neither identify the original computer center nor the IP address, which would be necessary, among other things, for prosecuting legal violations.

Civil law inquiries are useless, because Cloudflare only provides the naming of a computer center, which is worthless without the respective IP address. This would be roughly comparable to the information of an address in a high-rise building with thousands of residents, where there are no bell signs.

Read the full article inside TG (🇬🇧)
https://t.me/BlackBox_Archiv/163

Or the original (🇩🇪)
(TG)
https://t.me/BlackBox_Archiv/166
(Web) https://tarnkappe.info/cloudflare-the-bad-the-worse-and-the-ugly/

📡 @NoGoolag
#cloudflare #dns #truth #why
Why you shouldn't use Cloudflare

🔴 https://t.me/NoGoolag/887

🔴 https://t.me/BlackBox_Archiv/853

🔴 https://notabug.org/crimeflare/cloudflare-tor

🔴https://unixsheikh.com/articles/stay-away-from-cloudflare.html

🔴http://cryto.net/~joepie91/blog/2016/07/14/cloudflare-we-have-a-problem/
(P.S.: the parts about repos and ff/chrome add-ons are to be taken with a grain of salt, they are mostly crap.)

TL;DR - Cloudflare sucks.

#cloudflare
Is Cloudflare safe yet? No.

Cloudflare is one of the Content Delivery Networks on the Internet. It’s responsible for serving at least 10% websites, while also providing VPN and DNS resolver services.

Unfortunately, there are many issues with Cloudflare's services, which could have an impact on the stability and safety of the internet as a whole. There have been some major internet disruptions as a result.

💡 How is Cloudflare harmful?

Cloudflare is trying to centralize the internet

The internet was built upon foundations of decentralization. In a traditional scenario, many internet services are provided by completely different subjects.

👀 Cloudflare is:

‼️ Providing domain registration services
‼️ Providing DNS nameservers
‼️ Providing DNS resolvers
‼️ Proxing and decrypting website traffic
‼️ Providing NTP services
‼️ Providing VPN services

You might wonder, how exactly is this harmful? There are two main concerns - robustness and privacy.

Cloudflare's outages are impacting more and more services. Trusting a single company to do everything right and to have a 100% stability and availability is never a good idea. They actively discourage combining the use of their services with services of other companies as well.
For example, if you register a domain with Cloudflare, you cannot use your own nameservers unless you pay for a Business or an Enterprise plan.

Having vast amounts of data at their disposal, Cloudflare can aggregate information from all of their various services to accurately pinpoint individual users as well.

👉🏼 Read more:
https://iscloudflaresafeyet.com

#Cloudflare #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
Script for getting unlimited GB on Warp+ ( https://1.1.1.1/ )

With this script, you can recharge your account indefinitely.

About warp+
WARP+ uses Cloudflare’s virtual private backbone, known as Argo, to achieve higher speeds and ensure your connection is encrypted across the long haul of the Internet.

👉🏼 Read more:
https://github.com/ALIILAPRO/warp-plus-cloudflare

https://blog.cloudflare.com/announcing-warp-plus/

#cloudflare #warp #FuckCloudflare #script
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
Generate WireGuard profile from Cloudflare Warp account

wgcf is a utility for
Cloudflare Warp that allows you to create and manage accounts, assign license keys, and generate WireGuard profiles.

💡 Features
:

👉🏼 Register new Cloudflare Warp device and account

👉🏼 Update account to allow connection via WireGuard

👉🏼 Update account with new license key, sharing Warp+ status with up to 5 devices

👉🏼 Generate WireGuard profile

👉🏼 Check Cloudflare device status

👉🏼 Print trace information to debug Warp/Warp+ status

💻 Download:
You can find pre-compiled binaries on the releases page.
https://github.com/ViRb3/wgcf/releases

👉🏼 Read more:
https://github.com/ViRb3/wgcf

🚀 Try with:
Script for getting unlimited GB on Warp+ ( https://1.1.1.1/ )
https://t.me/BlackBox_Archiv/919

#cloudflare #warp #FuckCloudflare #script
📡@cRyPtHoN_INFOSEC_DE
📡@cRyPtHoN_INFOSEC_EN
📡@BlackBox_Archiv
Major Cloudflare outage takes down Discord, Postmates, and other sites

Internet service giant Cloudflare suffered an outage Friday afternoon, knocking out service to many websites and services, including popular chat app Discord.

According to the Cloudflare’s System Status page, the web services provider was suffering “network and resolver issues.”

“This afternoon we saw an outage across some parts of our network,” Cloudflare told Digital Trends in a statement. “It was not as a result of an attack. It appears a router on our global backbone announced bad routes and caused some portions of the network to not be available. We believe we have addressed the root cause and are monitoring systems for stability now.”

https://www.digitaltrends.com/news/cloudflare-is-down-outage/

#cloudflare
Pornhub Sister Company Wants to Expose Video Hosting Site ‘Pirates’

MG Premium has requested three new #DMCA subpoenas targeting the operators and uploaders of #video #hosting sites Tapecontent.net, Netu.tv and Gounlimited.to. Pornhub's sister company requests information from #Cloudflare in the hope of identfiying those who share its copyrighted material without permission.

The online porn industry is rather diverse but there is only one company leading the charge – #Mindgeek.

The company, formerly known as Manwin, owns one of the most visited adult websites, #Pornhub, and is also the driving force behind #YouPorn, #Redtube, #Tube8, #Xtube, and dozens of other sites.

Many of these tube sites became big by offering access to a wide variety of content, some of it posted without permission. However, that doesn’t mean that Mindgeek is turning a blind eye to pirates. On the contrary.

Mindgeek’s imperium also includes companies that create content. MG Premium, for example, which owns thousands of copyrighted adult videos, is the driving force behind popular brands such as Brazzers and Digital Playground. These videos are often pirated and shared through external sites, which is a problem for the company.

To address this issue, Mindgeek’s daughter company regularly goes to court. Last week, it requested three DMCA subpoenas targeting the video-hosting services Tapecontent.net, Netu.tv and Gounlimited.to.

👀 👉🏼 https://torrentfreak.com/pornhub-sister-company-wants-to-expose-video-hosting-site-pirates-200811/

📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Cloudflare says its Sunday morning problems were due to CenturyLink outage

According to CenturyLink, services have been restored

Cloudflare said its Sunday morning outage affecting numerous websites was due to an IP outage by internet service provider CenturyLink. According to a tweet from CenturyLink, all affected services have been restored as of 11:15AM ET.

“Today we saw a widespread Internet outage online that impacted many multiple providers,” a Cloudflare representative said in an email to The Verge. “This was not a Cloudflare-specific outage. Level 3/CenturyLink was responsible for an outage that affected many Internet services, including Cloudflare. Cloudflare’s automated systems detected the problem and routed around them, but the extent of the problem required manual intervention as well.”

https://www.theverge.com/2020/8/30/21407429/cloudflare-down-websites-hulu-feedly-discord

#Cloudflare #outage
Cloudflare Shared Personal Details of Hundreds of Customers in Response to DMCA Subpoenas

Cloudflare doesn't remove anything in response to DMCA takedown notices unless it stores the content permanently. However, the company will hand over personal details of customers to copyright holders who obtain a DMCA subpoena. Over the past 12 months, Cloudflare was ordered to share information regarding more than 400 accounts.

Popular CDN and DDoS protection service Cloudflare has come under a lot of pressure from copyright holders in recent years.

The company offers its services to millions of sites. This includes multinationals, governments, but also some of the world’s leading pirate sites.

Many rightsholders are not happy with the latter. They repeatedly accuse Cloudflare of facilitating copyright infringement by continuing to provide access to these platforms. At the same time, they call out the CDN service for masking the true hosting locations of these ‘bad actors’.

https://torrentfreak.com/cloudflare-shared-personal-details-of-hundreds-of-customers-in-response-to-dmca-subpoenas-200903

#Cloudflare #DMCA #subpoenas #personal #details #privacy
Cloudflare and Internet Archive team up to make sure websites never fully go offline

Websites that use
Cloudflare Always Online can have their URLs automatically archived with Wayback Machine.

Cloudflare and Internet Archive have joined forces to archive more of the public web, touting it would make the web more reliable.

As part of this joint effort, websites that use Cloudflare's Always Online service will be able to allow the web infrastructure company to share their hostname and URLs with Internet Archive's Wayback Machine so their website can be automatically archived.

When a site is down, Cloudflare will then be able to retrieve the most recently archived version from Internet Archive so that a site's content can be accessed by users.

"The Internet Archive's Wayback Machine has an impressive infrastructure that can archive the web at scale," Cloudflare CEO and co-founder Matthew Prince said.

"By working together, we can take another step toward making the internet more resilient by stopping server issues for our customers and in turn from interrupting businesses and users online."

According to Internet Archive, more than 468 billion web pages are available via the Wayback Machine to date.

"We archive URLs that are identified via a variety of different methods, such as 'crawling' from lists of millions of sites, as submitted by users via the Wayback Machine's 'Save Page Now' feature, added to Wikipedia articles, referenced in Tweets, and based on a number of other 'signals' and sources, such multiple feeds of 'news' stories. An additional source of URLs we will preserve now originates from customers of Cloudflare's Always Online service," Wayback Machine director Mark Graham wrote in a blog post.

👀 👉🏼 https://blog.archive.org/2020/09/17/internet-archive-partners-with-cloudflare-to-help-make-the-web-more-useful-and-reliable/

👀 👉🏼 https://www.zdnet.com/article/cloudflare-and-internet-archive-team-up-to-make-sure-websites-never-fully-go-offline

#cloudflare #internet #archive #wayback
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Don’t trust Cloudflare with your personal data

It has been over a year since I cancelled my Cloudflare account. They keep emailing me and haven’t taken me off their marketing lists despite repeated requests. Their CTO told me he would investigate, but nothing changed. Their Data Protection Office hasn’t respond to my requests.

Cloudflare do not appear to respect the GDPR.

I’ve escalated this to the highest levels of Cloudflare, but they just don’t seem to be able to take any action. This is concerning.

👀 👉🏼 https://shkspr.mobi/blog/2020/09/dont-trust-cloudflare-with-your-personal-data/

#cloudflare #personal #data #gdpr #thinkabout
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Anti-Piracy Alliance Wants .To Registry to Expose Streaming Piracy Giant S.to

Anti-piracy coalition ACE has obtained a subpoena to compel the Tonic domain registry to hand over all information it has on the owner of
S.to. With hundreds of thousands of registered users, S.to is the largest German-language pirate TV streaming community. These requests are a core part of the anti-piracy toolbox, a source informs us.

With hundreds of thousands of registered users and millions of regular visitors, the pirate TV-streaming community S.to is a force to be reckoned with.

The site targets a German-language audience and currently lists more than 750,000 streaming links to well over 5,000 TV-series.

This public display of piracy is a thorn in the side of major copyright holders. This includes the anti-piracy coalition ACE, which counts Netflix, Amazon, and several Hollywood studios among its members.

ACE wants Domain Registry to Identify S.to operator

In recent weeks, ACE has obtained several subpoenas to compel Cloudflare to hand over all information it has on dozens of pirate sites. This effort continued recently, but this time it’s directed at Tonic, the official registry of the .to domain name, with S.to as the single target.

Through the subpoena, the anti-piracy coalition asks Tonic to disclose information including names, physical addresses, IP addresses, telephone numbers, email addresses, payment information, account updates, and account history associated with the domain registrant.

While .to is the top-level domain of the island kingdom of Tonga, the Tonic registry operates through Tonic Domains Corp., which clearly has a U.S. presence with a California address. As such, it will generally fall under the jurisdiction of US courts.

👀 👉🏼 https://torrentfreak.com/anti-piracy-alliance-wants-to-registry-to-expose-streaming-piracy-giant-s-to-201018/

#antipiracy #ace #cloudflare #streaming #piracy
📡@cRyPtHoN_INFOSEC_DE
📡
@cRyPtHoN_INFOSEC_EN
📡
@BlackBox_Archiv
📡
@NoGoolag
Private Access Tokens: eliminating CAPTCHAs on iPhones and Macs with open standards

Today we’re announcing Private Access Tokens, a completely invisible, private way to validate that real users are visiting your site. Visitors using operating systems that support these tokens, including the upcoming versions of macOS or iOS, can now prove they’re human without completing a CAPTCHA or giving up personal data. This will eliminate nearly 100% of CAPTCHAs served to these users.

Over the past year, Cloudflare has collaborated with Apple, Google, and other industry leaders to extend the Privacy Pass protocol with support for a new cryptographic token. These tokens simplify application security for developers and security teams, and obsolete legacy, third-party SDK based approaches to determining if a human is using a device. They work for browsers, APIs called by browsers, and APIs called within apps. We call these new tokens Private Access Tokens (PATs). This morning, Apple announced that PATs will be incorporated into iOS 16, iPad 16, and macOS 13, and we expect additional vendors to announce support in the near future.

https://blog.cloudflare.com/eliminating-captchas-on-iphones-and-macs-using-new-standard/
#cloudflare
Human rights activists of the Foundation to Battle Injustice have appealed to the American technology company Cloudflare, which provides a secure connection to the Ukrainian nationalist website “Myrotvorets” and protects it from cyber attacks. Speaking on behalf of human rights defenders, journalists and public figures who care about the criminal activity of the website, the Foundation to Battle Injustice called on the company’s CEO Matthew Prince to block the “Myrotvorets”.

https://fondfbr.ru/en/letters-and-petitions/cloudflare-myrotvorets-en/
#cloudflare #terrorism #kiwifarms