logoalt Hacker News

embedding-shapelast Thursday at 3:49 PM4 repliesview on HN

Will you also do this for other spammers using Cloudflare infrastructure, or just specifically for this email product?

> For years, Spamhaus has observed abusive activity facilitated by Cloudflare’s various services. Cybercriminals have been exploiting these legitimate services to mask activities and enhance their malicious operations, a tactic referred to as living off trusted services (LOTS) [2].

> With 1201 unresolved Spamhaus Blocklist (SBL) listings [3], it is clear that the state of affairs at Cloudflare’s Connectivity Cloud looks less than optimal from an abuse-handling perspective. 10.05% of all domains listed on Spamhaus’s Domain Blocklist (DBL), which indicates signs of spam or malicious activity, are on Cloudflare nameservers

https://www.spamhaus.org/resource-hub/service-providers/too-...


Replies

Meekrolast Thursday at 4:19 PM

I would note that Cloudflare has been doing better-- the SBL listings page mentioned in that article[1] shows only 47 active complaints, down from 1201 when the article was written 2 years ago. Many of those complaints are stale, too: I spot-checked a few (referencing the domains fireplacecoffee.com and expansionus.com) and the domains are expired and not being hosted by anyone.

[1] https://check.spamhaus.org/sbl/listings/cloudflare.com/

show 1 reply
big-and-smalllast Friday at 6:15 AM

Spamhaus itself is a shady and non transparent organization and basically one of reasons why its been so hard to actually run email service for decades.

Cloudflare is not perfect, but at least it been consistent about not becoming censorship service with very few exceptions where they banned something.

Id rather let criminals freely buy and use kitchen knives than let shady organizations control who is allowed to buy one.

computershitlast Thursday at 11:19 PM

> 10.05% of all domains listed on Spamhaus’s Domain Blocklist...are on Cloudflare nameservers

Not defending spammers, but this comes across a smidge naive considering Cloudflare's overall footprint in the modern internet.