• originalucifer@moist.catsweat.com
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      cloudflare has a known habit of taking heavy users and forcibly converting companies from a $250/m plan to a $12,000/month plan.

      some people would be happy for that to happen to bad entities like an online casino, but really, to cloudflare the business use is irrelevant and it could happen to any of us.

      the lesson is to minimize your cloudflare dependencies. if you have to use it, use it in an agile method where you can move to something else quickly should you need to.

      • Evotech@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        12000 a month is probably chump change for a casino and money well spent at that for the features cloudflare provides

        At my job, a reasonably sized it customer generates about 100-500k a month.

        • Rai@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          The casino has like millions of folks at $300/month according to a comment on another topic about this.

          Based cloudflare.

        • You999@sh.itjust.works
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          For 12k a month just the DDoS protection would be worth it for a site of that nature and size but they also get CDN access with full control over the caching, and a web application firewall.

          The way I see it the casino was trying to plate share at a buffet and got caught so now they are complaining about having to pay the correct amount.

  • qwerty@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Why are online casinos bad? I don’t understand this pervasive need some people have to force their way of life on others and take away their agency over their own lives. It comes off to me as some kind of superiority complex. “They’re too stupid to make their own decisions, I know better what’s best for them, I must protect them from themselves”.

    • Makhno@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      “They’re too stupid to make their own decisions, I know better what’s best for them, I must protect them from themselves”.

      I’ve never been given a reason to not think most people are morons

      • qwerty@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        I presume you don’t consider yourself to be a part of the aforementioned majority? Do you believe it makes you superior? Do you believe you know better what’s best for them? Do you believe you must protect them from themselves, even at the cost of their self-determination?

        • zea@lemmy.blahaj.zone
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          I’m not the person you’re replying to, but I am stupid enough to occasionally get close to falling for a scam. Rather than test my luck, I’d rather they didn’t exist.

    • stanleytweedle@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Is meth bad? Would a company that specifically targets meth sales to the most likely drug using demographics be bad? Would a company that sold meth in shiny, futuristic containers that said “Lucky Dreams!” be bad?

    • Knock_Knock_Lemmy_In@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Why are online casinos bad?

      How can players be sure they are honest?

      I must protect them from themselves.

      People should be protected from scammers with fake (always lose) casinos.

      • qwerty@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        There are ways to cryptographically verify bet integrity, but that’s not important. The point I was trying to make is that people should have the right to make their own decisions, even if you disagree with them, even if they’re objectively wrong.

        • Knock_Knock_Lemmy_In@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          If you are objecting about one person’s morals being forced on another then I totally agree.

          Your delivery of that argument needs work because it comes across as wanting to defend scammers.

              • ji17br@lemmy.ml
                link
                fedilink
                arrow-up
                0
                ·
                1 month ago

                Yes. He’s asking a question? Why is an online casino bad?

                If the casino follows all rules and regulations, then that is not bad.

                If talking about sites that steal your money and don’t pay out when you “win”, then yes, that is bad, and a scam. But that’s not an online casino…that’s a scam. And also incredibly rare.

                An online casino can make a shit ton of money by just following the rules. Why would they need to break the rules?

      • sudneo@lemm.ee
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        How can players be sure they are honest?

        At the bottom of each gambling sites usually there are the banners for the license(s) the company holds. Complying with licenses (e.g., Maltese) ensures that the due paperwork (i.e., proving that Casino games are functioning according to their certification) is taken care of. So yes, national gambling authorities usually are the ones who protect people from scammers.

        • Knock_Knock_Lemmy_In@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          “functioning according to their certification” doesn’t prove to me that they aren’t shaving the odds or injecting sneaky code into the process. I have to trust in the technical ability of the regulators.

          Also, I could write “regulated by the Maltese” on the bottom of any website, it doesn’t make it true.

          • sudneo@lemm.ee
            link
            fedilink
            arrow-up
            0
            ·
            1 month ago

            They can’t add sneaky code to the process (without getting caught). For sensitive game code every single change needs to be tracked and reviewed by the authority. You get audited at least once a year, and then all the changes are reviewed. Authorities outsource the job for the technical reviews to specialized companies.

            Also, what’s the point? The games already provide a margin to the host, why risking to go out of business for such an irrelevant gain (a few more %)? Add to this that usually casino games writers do just that, write games and sell those to N casinos. So the incentive for the casino games writers are even smaller.

            Finally, yes you can write “license X”, but you can cross-check that information from the regulator itself, you don’t need to trust just the line on the site. The point is you as a customer can choose a trustworthy site, ideally one who is licensed in countries where regulations are quite tight (in Europe I would say Denmark), before putting your money somewhere.

            At some point you need to trust “someone”, that’s how the whole world works. The gambling authorities are no different than the authorities that enforce the safety certifications for electrict equipment, or cars, or whatever.

            If your concern is that you would lose money on casino games because the site rigged it, it’s a relatively silly concern. You will lose because the casino games are designed to make you lose in the long term, on average.

            • Knock_Knock_Lemmy_In@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              They can’t add sneaky code to the process (without getting caught).

              That means that people have to check

              For sensitive game code every single change needs to be tracked and reviewed by the authority. You get audited at least once a year, and then all the changes are reviewed. Authorities outsource the job for the technical reviews to specialized companies.

              Or just ignore that and publish whatever you like.

              why risking to go out of business for such an irrelevant gain

              Why spend money to meet regulations?

              Finally, yes you can write “license X”, but you can cross-check that information from the regulator itself, you don’t need to trust just the line on the site.

              How many users actually do this? A very low percentage.

              point is you as a customer can choose a trustworthy site,

              The point is that many don’t.

              If your concern is that you would lose money on casino games because the site rigged it, it’s a relatively silly concern.

              Not really. It’s one of the reasons why online casinos can be bad.

              The question was what is “wrong with online casinos”. So I gave an example. Others include money laundering, exploitation of addiction, exploitation of stupidity, waste of resources, tax evasion etc .

              • sudneo@lemm.ee
                link
                fedilink
                arrow-up
                0
                ·
                1 month ago

                Have you ever made a single transaction online paying with your credit or debit card? How do you know the site didn’t steal or misuse your information?

                The answer is that storing, transmitting or processing card data requires you to be PCI-DSS compliant, which is a very strict standard. If you get caught violating that you are out of business and fined in the abyss, which is a much bigger risk than stealing john doe’s pennies.

                Sorry but from what you are saying it seems you simply don’t understand how compliance works.

                That means that people have to check

                And that is why you have at least annual audits (for each license, plus AML, plus other stuff), and why you need to present the whole chain of changes that happened to sensitive code.

                Why spend money to meet regulations?

                Because if you get caught not doing that you lose access to whole markets at once and get fined. There is no economic incentive as complying doesn’t cost nearly as much. Specifically, I told you that casino game makers are generally not casinos, they are software houses. So they can’t care less about rigging the games, their revenue comes from companies paying for using their games. Casinos also don’t care of rigging games because games are designed to leave them a certain margin anyway, so why doing it?

                The point is that many don’t.

                And that’s why national regulations are generally a safe umbrella. If you see a website (through advertisements) that means that website is allowed locally and already met the national regulations.

                If you are in a non regulated country then you will need to do a tiny bit of research. You are putting money on a site, after all (you should do the same for everything you do online).

                The question was what is “wrong with online casinos”. So I gave an example. Others include money laundering, exploitation of addiction, exploitation of stupidity, waste of resources, tax evasion etc

                Yes, you gave examples based on your own speculations. It’s clear you have no idea how the industry works. Money laundering is something international law covers and is extremely tightly controlled, tax evasion is also completely insane for online businesses, because every transaction has a trail and there are tight regulations about what you need to report for every country where you operate. Exploitation of stupidity, sure. Some also exploit addiction, regulations exist for that too, and for some businesses addicts are terrible customers.

                Question: what exactly is your experience with the gambling business?

                Because to me it seems you are making stuff up or basing your statements on movies about gambling and oeganised crime, while the reality is much simpler: companies get money simply by having active users on their sites. Quantity is the name of the game.

                • Knock_Knock_Lemmy_In@lemmy.world
                  link
                  fedilink
                  arrow-up
                  0
                  ·
                  1 month ago

                  How do you know the site didn’t steal or misuse your information?

                  Exactly. Scam websites can be casinos or shops or anything.

                  You are vehemently defending the “legitimate” casino industry whereas I am saying it’s easy to create scam casinos.

                  Yes, you gave examples based on your own speculations. It’s clear you have no idea how the industry works.

                  I know well how it works.

                  Money laundering is something international law covers and is extremely tightly controlled, tax evasion is also completely insane for online businesses, because every transaction has a trail and there are tight regulations about what you need to report for every country where you operate.

                  Casinos, on and offline, are excellent ways to launder. The amount of regulations trying to mitigate this risk proves my point.

                  Exploitation of stupidity, sure.

                  Glad we agree here.

                  Some also exploit addiction, regulations exist for that too, and for some businesses addicts are terrible customers.

                  Not for casinos. Gambling addiction is a casino’s main business. Why are there no windows in Vegas?

                  Question: what exactly is your experience with the gambling business?

                  Betfair, betfred, bet356, Ladbrokes etc.

                  Exchanges for sports and real life events I have little problem with.

                  I only have probems with sites that scam people with flashing lights and random number generators.

                  Quantity is the name of the game.

                  Yes. Online you can scam many more people with fake roulette tables.

    • PoliticalAgitator@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Sounds more like you just don’t know anything about the gambling industry. They run rigged games in predatory ways. They happily let organised crime launder money for a cut. They fight regulations designed to reduce problem gambling.

      Nevertheless, nobody here is “forcing their way of life on others and taking away their agency over their own lives”. They’re just acknowledging that casinos have a long history of being absolute cunts.

      • sudneo@lemm.ee
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        They run rigged games in predatory ways.

        I don’t know what you mean by this. Games have a fixed margin which is usually disclosed or can be computed (exactly like the 0 and 00 in the roulette skews the odds in the house’s favor if you want to do just black/red). There are then whole chapters in national regulations about random number generators to ensure the odds are correct and the games are not rigged (i.e., a game certified for 98% should have that outcome). Are games designed to have the house win a 2,5,7,9% margin? Sure, but this is out there in the open, there is nothing to “rig” in the same way having 0 or 00 is not “rigging” a game of roulette.

        They happily let organised crime launder money for a cut.

        At least in Europe, you get audited quite often and AML regulations are very tight. Laundering money via online gambling companies with their cooperation seems quite unlikely to me (and inefficient, possibly, but I don’t know).

        They fight regulations designed to reduce problem gambling.

        Some do, but not all, and not in all cases. Addicts are bad for business for gambling companies, or at least for some of them, moderate long-term customers are generally better (and require way less effort).

        I don’t know what you know about gambling, I definitely think that the ethics are questionable, and I left the industry when I could also for those reasons, but the company I worked for was not very bad in this regards. Maybe you worked/had experience with some of the shady ones (like those who operate in illegal markets using a single license from a random tiny country)?

      • qwerty@discuss.tchncs.de
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        Who’s “they”? I don’t know much about the gambling industry but if it’s anything like any other industry then it’s not a centralized monolith but many independent business. As long as the founding principles aren’t inherently corrupt (and in the case of casinos they aren’t. Nobody is forced to play and everyone knows the house has an advantage and in the long term is guaranteed to win. Because of this it doesn’t make sense for the house to cheat and risk getting caught, it will win anyway.) there is no reason to think that the majority of the industry engages in criminal activity. This is a massive generalization.

        • PoliticalAgitator@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          I don’t know much about the gambling industry

          You can stop there. You don’t know much about the gambling industry, defending them was just an opportunity to tell us your opinions on “some people”, none of whom are actually here.

          • qwerty@discuss.tchncs.de
            link
            fedilink
            arrow-up
            0
            ·
            1 month ago

            Yes, my comment wasn’t about online casinos but about the people who think they have a right to tell others how to live their lives. I’m not defending the gambling industry, I think gambling is stupid. I’m defending the right of the people to make their own decisions.

            My “defense of the gambling industry” was just me pointing out that as long as something isn’t inherently nonconsensual and the terms and conditions are clear there is no reason to forbid other people from doing it just because you disagree with it.

            • CileTheSane@lemmy.ca
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              Yes, my comment wasn’t about online casinos but about the people who think they have a right to tell others how to live their lives.

              Who’s “they the people”? I don’t know much about the gambling industry the internet but if it’s anything like any other industry place then it’s not a centralized monolith but many independent business people.

            • PoliticalAgitator@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              Nobody in this thread has forbidden anyone from doing anything. If you want a soapbox for your irrelevant opinions, start a blog.

  • radicalautonomy@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    I won five grand from an online casino in 2001, and they not only paid me my winnings, they also included an extra $262 in comps for having bet aggregately over a quarter of a million dollars. That money went a long way for my early-20s ass. Paid off a credit card and bought a new mattress for me and my new wife.

    When Full Tilt Poker got shut down by the DOJ, though, I was sort of okay with it. There were waaaaay too many action flops for those hands to have been truly randomized.

    • Draedron@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Gambling ruines lifes. Just because people can get their win does not mean it should be defended in any case. These casinos intentionally make people addicted, causing so much suffering and death.

      • thermal_shock@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        edit-2
        1 month ago

        you can defend casinos as long as you treat it as entertainment and don’t bet your entire life savings on it and cry about it

        I set my initial bet amount, once that’s gone my game is done. on the other side if I double it my game is done

      • radicalautonomy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        These casinos intentionally make people addicted, causing so much suffering and death.

        Noted, but so does alcohol and you can find it almost everywhere. Most people have the capacity to exercise caution when engaging in potentially addictive behaviors. Unless we intend to ban everything that could cause addiction and lead to destruction of a person’s life (gambling, alcohol, tobacco, food, sex…), then we have to let people make their own choices and be responsible for their own decisions. When it becomes apparent to a person that they have an addiction, it is their own responsibility to tend to it.

        • Jtotheb@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          Sure was nice of the state to require your 2001 online casino to list in writing the odds of winning and enforce payment. But sure, they did you a favor and the state is bad, people are solo acts and you should be free to prey on the less powerful

            • Jtotheb@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              1 month ago

              Sorry, I’ll extrapolate more precisely.

              Casinos spend unfathomable resources on learning exactly how to wedge their ads deep into your mind and get you hooked on their satisfying little dopamine loops, but it’s your personal failure if you, an ordinary person who is statistically speaking living paycheck to paycheck raising a kid with no savings, succumb to them. And your responsibility to fix it.

              Correct?

    • PrettyFlyForAFatGuy@feddit.uk
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      1 month ago

      they also included an extra $262 in comps for having bet aggregately over a quarter of a million dollars.

      Why do you have credit card debt that had to wait for a 5k gambling “windfall” if you can afford to slowly spunk 250k up the wall at the same gambling sites?

      you have a problem… you are an addict…

      I can’t figure out if this is a joke post or not

      • radicalautonomy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        Because I was 24 years old and I put $50 on a debit card and managed to pump it up to $5000 and it was a one-off occurrence more than two decades ago? Relax.

      • dyc3@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        I think what he means is that he bet some money, won, and then used that to bet again, repeat and eventually the aggregate bets made totalled to be 250k.

        • radicalautonomy@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          This. Granted I was 24 and not great with money as my wife and I had about $1500 in credit card debt, but once or twice a year I’d put down $50 for a little fun money and play at an online casino for no more than a week or until the $50 was gone. The first time I tried, I managed to use a modified Martingale system for several days and worked it up to five grand before cashing out. Was never successful at making anything close to that again, but I never played with or lost more than I could afford.

          Today, apart from a car note I took on two weeks ago after a car I drove 200,000 miles over the past 14 years finally gave out, I am debt free and have been since 2016, and I genuinely can’t remember the last time I went to the casino. But, when I did, I brought $200, lost it but had my fun, and went home. No addiction whatsoever.

  • cloud_herder@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Where does online sports “betting” fit into this meme? Genuine ask because I have no experience or awareness of online casinos. Thanks.

  • katy ✨@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    reminder that cloudflare routinely works with white supremacist and other hate sites to protect them and have most recently refused to stop hosting kiwi farms, as they were doxxing and threatening trans people

    • You have it wrong, which really shows what you stand for:

      Cloudflare refused to block KiwiFarms as there was no evidence of criminal activity or violation of their policies, and doing so would tarnish their reputation in regards to free speech. They did stop hosting KiwiFarms, in September of 2022 (you can find their statement here) in response to a libelous pressure campaign ran by Keffals when she/they/it found out users were pulling out receipts of it engaging in lewd conversation with minors and providing them with DIY hormone replacement therapy kits without any medical oversight or parental consent.

      And KF did not attack Keffals out of nowhere, it was only after she started engaging with Chris-chan as she was attempting to use him to boost her own reputation at a time when he was already in a perilous mind.

      I’m not sure exactly where you got the “threatening trans people” from, that is the first I’ve heard of it. I know of one incident that is much more grave and potentially what you are referring to, but your reference leaves out almost the entire context of that one particular incident and there have been no repeats of it to my knowledge.

      I’m not a fan of KiwiFarms, but they did not earn their censorship. It was the result of a successful attempt by a revisionist career troll to cover their tracks when they realized their goose was about to get cooked, nothing more. If you truly stand for free speech, you would realize just how dangerous the precedent set by such an unreliable source as Keffals is.

      And yes, I realize that if my comment gains enough traction, it and its army will be at my throat and by no doubt have doxxed me in no time if they so choose. But that’s not going to keep me from preventing people like you from twisting the narrative.

      • Clbull@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        The same place that regularly bullies and bear-baits ‘lulcows’ for entertainment? The same people who bullied an autistic adult over a shitty Sonic fan character webcomic?

    • Kilgore Trout@feddit.it
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      They don’t “work with white supremacists”. They try to self-polish the tremendous power the have, seeking neutrality in most cases.

    • uis@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      1 month ago

      THIS MESSAGE (MATERIAL) CREATED AND (OR) DISTRIBUTED WITH PURPOSE OF HATE AND (OR) ENCOURAGING HATE.

      You forgot to put it.

      I heavilt dislike cloudflare, but this is not valid reason to hate them.

  • drathvedro@lemm.ee
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Both of course, but if I had to choose, Cloudflare. Definitely Cloudflare. That company must be purged by fire and magnets. Sure, casinos are evil, but they mostly stay in their lane doing their thing of preying on the vulnerable. When Cloudflare just straight up breaks half the internet for lunch and there’s, by design, no way around it.

    • nova_ad_vitum@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      In this particular story, if there’s any truth to it then it’s basically extortion. They could have just said that due to their usage profile they will need to switch to an enterprise license for the next billing period . Instead they tried to extort it within 24h lol.

      And of course you have to buy a whole year of service (lol). This last thing is a symptom of a degenerate market with few competitors. No company that fears competition would try to pull that stunt.

  • CanadaPlus@lemmy.sdf.org
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    1 month ago

    What’s the problem with CloudFlare? They’re trying to make a profit, and so in the long run are the same as anybody, but every interaction I’ve had with them recently has left me impressed.

    • Dessalines@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      They’re a giant middleman getting everything you put into html forms unencrypted.

      That includes all your usernames, passwords, and everything you submit via text boxes. Do not trust any site that uses cloudflare.

    • redcalcium@lemmy.institute
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Remember when google was beloved by everyone back then when they’re still have “don’t be evil” motto? Cloudflare right now is like google back then: super useful, provides a lot of free services that would be expensive on other providers. But unlike google, if cloudflare go full evil in the future, the impact will be much larger because they’re an mitm proxy capable of seeing unencrypted traffics across all websites under their wing. Right now they’re serving ~30% of top 10,000 websites and growing.

      • Dessalines@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        There’s no proof they aren’t doing anything nefarious with that data right now, other than company statements saying, “trust us”.

        People default to trusting giant corporations first it seems.

          • Dessalines@lemmy.ml
            link
            fedilink
            arrow-up
            0
            ·
            1 month ago

            I’m not sure if this is ironic bc I’ve been exposed to too many irony-poisoned comments lately, but cloudflare exists to profit off your data. They’re not there to help you, your data and its trends are the product.

      • CanadaPlus@lemmy.sdf.org
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        Oh, okay, so I’m not wrong that they’re good right now.

        I’m a little unclear on how it works. Do they strip off HTTPS somehow? Otherwise, there’s not too much unencrypted traffic around anymore.

        • Dessalines@lemmy.ml
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          1 month ago

          You have no proof that they’re “good right now”. The big five corporations were forwarding data to the NSA for years before the surveillance leaks exposed them.

          Your privacy default should not be to trust an MITM, ever.

        • markstos@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          One of the services they provide is free SSL certificates. As part of that, they have the private key to decrypt the traffic. They aren’t trying to hide that— this is true of any service that hosts the SSL cert for your site.

          • SugarSnack@lemm.ee
            link
            fedilink
            arrow-up
            0
            ·
            1 month ago

            Does that mean it wouldn’t be an issue if you bring an SSL cert from say ZeroSSL but use Cloudflare for DNS, caching, DDoS protection etc?

            • markstos@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              It’s not who issues the cert that matters, it is who hosts it. Hosting it includes having the private key. You always have to trust your website host, full stop.

            • SirQuackTheDuck@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              For DNS and DDoS protection that wouldn’t directly be an issue.

              For caching it would be breaking. You cannot cache what you cannot read (encrypted traffic can only be cached by the decrypting party).

            • markstos@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              1 month ago

              With what? HTTPS has to terminate the encryption somewhere and that place has to have the private key to do so.

              CloudFlare is providing the same service here as all other hosts of HTTPS websites do.

              • CanadaPlus@lemmy.sdf.org
                link
                fedilink
                arrow-up
                0
                ·
                edit-2
                1 month ago

                Well, depends. If it’s hosted on AWS and HTTPS terminates there like it’s supposed to, Amazon could look inside, but a human being would have to personally hack your container and extract the data, so that’s a bit better. If it’s something more like Wix, though, sure. (Is Wix still a thing?)

                • markstos@lemmy.world
                  link
                  fedilink
                  arrow-up
                  0
                  ·
                  1 month ago

                  If you use the AWS load balancer product or their certificates, they have access to the private key, regardless of whether you forward traffic from the LB to the container over HTTPS or not.

                  If you terminate the SSL with your own certificate yourself, Amazon still installs the SSM agent by default on Linux boxes. That runs as root and they control it.

                  If you disable the SSM agent and terminate SSL within Linux boxes you control at AWS, then I don’t think they can access inside your host as long as you are using encrypted EBS volumes encrypted with your key.

        • redcalcium@lemmy.institute
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          1 month ago

          Do they strip off HTTPS somehow?

          Well yes, how else they can provide their services such as page caching, image optimizing, email address obfuscation, js minifications, ddos mitigation, etc unless they can see all data flowing between your server and your visitors in the clear?

          Cloudflare is basically an MITM proxy. This blog post might be helpful if you want to know how mitm proxy works in general: https://vinodpattanshetti49.medium.com/how-the-mitm-proxy-works-8a329cc53fb

    • uis@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago
      1. They seem to hate my devices. Lots of captchas.
      2. They seem to hate when people bypass their country’s censorship. Using sites behind cloudflare through tor is pain without end.
      • zalgotext@sh.itjust.works
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        I get so many cloudflare captchas browsing on Firefox. They mostly go away when I change my user agent string to Chrome. Making the Internet more hostile for a particular group of users is pretty shitty behavior in my book.

      • CanadaPlus@lemmy.sdf.org
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        They’ve gotten a lot better over Tor - that’s the main thing I’m thinking of, actually. I used to give up most of the time when captcha’d, but now with the JavaScript based verification I pretty much always can get in, even on mobile.

        Most providers don’t give a shit about Tor, or actively try to block it. They actually went out of their way to make it easier.

    • Schadrach@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      What’s the problem with CloudFlare?

      So far, not much other than being “too” content neutral for a lot of people. They have potential to be immensely horrible whenever they decide to engage in enshittification to maximize profits.

      • refalo@programming.dev
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        they’re called crimeflare for a reason. besides being a government goldmine having access to everyone’s encrypted TLS traffic, they selectively enforce censorship in unethical ways.

        why block kiwifarms when you still allow hosting monkey torture sites? or sites for sourcing bathtub HRT secretly sent to minors? they shouldn’t be policing the internet in the first place. this is dangerously close to invalidating Section 230 protections as well.

        there’s so many more reasons it’s not even funny.

        • Schadrach@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          They see everything because they have to for some of the services they offer which gives them a huge potential to do terrible things that they have not actually pursued yet to date, hence the “so far” in my comment.

            • Schadrach@lemmy.sdf.org
              link
              fedilink
              English
              arrow-up
              0
              ·
              1 month ago

              True. But that just falls back on the “not yet” part of things. They’re likely sitting on a massively valuable pile of user data and when they get greedy enough it’s going to be ugly.

  • Trarmp@feddit.nl
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    I was reading the blog post by the casino’s tech person and kept thinking to myself, “this is a casino; they may not be the most reliable narrator”. That said, CF was also stupid slow on taking down kiwi and stormfront, so they’re not great either.

    Both of them suck and this whole thing is amusing to me. Hopefully this will serve to improve CF’s behaviour.

      • SqueakyBeaver@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        A website similar to 4chan, but much much worse. They’d dox pretty much anyone they didn’t like, often LGBTQ+ people and allies

      • Telorand@reddthat.com
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        KiwiFarms, a forum dedicated to doxxing and IRL harassing of LGBTQ people, women, and anyone else they didn’t like. It was a breeding ground for Nazis and other Conservative bigots and their ideologies, and they successfully harassed people into moving and hiding (or worse).

        • Tartas1995@discuss.tchncs.de
          link
          fedilink
          arrow-up
          0
          ·
          1 month ago

          For those horrible enough to like this.

          Sometimes each other too if my information is correct. So even if you are a bad person and want to harass innocent people, kiwi farms isn’t the place to be.

          Bad people are bad people towards you too if you give them the chance. Just don’t be bad, much better. Don’t hate!

        • Schadrach@lemmy.sdf.org
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Specifically, it started out to track, dox, and harass Chris-Chan (originally just for being a weirdo though they eventually came out as trans and made news in 2021 for being arrested for incest). The nearly two decade old (since 2007) ongoing campaign against them means they are probably the single most documented human being in history.

          They don’t often target women just for being women, but much like with trans people and furries they also hate a hate-on for crowdfunded youtube personalities and fat acceptance and all of those groups do have their share of women (especially the last one - fat acceptance is primarily about women). They even target fundamentalist Christians and Quiverfull families sometimes (which tend to be very Conservative).

          Also, there’s no “was” - they still exist are are operating.

    • lud@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      It isn’t clodflare’s job to take down or in any way take a stance on what websites they are providing most likely only DDOS and DNS services for.

      That’s for example why privacy sites can use them.

      It’s the police or maybe hosting provider that should decide when/if to take down sites.

      If cloudflare were hosting the site I think they have more responsibility.

      • trashgirlfriend@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        1 month ago

        I feel like if you’re protecting a site that has caused as much harm as kf, it might be morally correct to stop doing so.

  • suction@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    What exactly has Cloudflare done to those poor casino thugs, they were only trying to extract more money from gambling addicts?!?