[HN Gopher] Cloudflare reports almost 7% of internet traffic is ...
       ___________________________________________________________________
        
       Cloudflare reports almost 7% of internet traffic is malicious
        
       Author : isaacfrond
       Score  : 35 points
       Date   : 2024-07-17 12:47 UTC (10 hours ago)
        
 (HTM) web link (www.zdnet.com)
 (TXT) w3m dump (www.zdnet.com)
        
       | freedomben wrote:
       | It's a shame that the actual report is buried behind the
       | marketing BS "give me your email to get the report" stuff.
        
       | jsheard wrote:
       | The call is coming from inside the house, the majority of DDoS-
       | for-hire services are hiding behind Cloudflare.
        
         | which wrote:
         | This talking point is tired. They would just pay $100/month for
         | ddos-guard. I don't understand why Cloudflare should be forced
         | to screen customers by default or held to a standard that no
         | other Internet business is. Why not go up the chain and start
         | protesting outside Verisign HQ?
        
           | tiffanyh wrote:
           | > I don't understand why Cloudflare should be forced to
           | screen customers by default
           | 
           | It's very common for reputable hosting company's to KYC/KYB.
           | 
           | It's good for them & also good for their legit customers.
        
             | which wrote:
             | Yes but there's no law requiring this and it raises their
             | bounce rate. I don't see any evidence that if law
             | enforcement asked them to shut down a domain that they
             | wouldn't. DDoS as a service existed long before Cloudflare
             | and in its simplest form just requires messaging someone on
             | a forum with a target.
        
             | metalcrow wrote:
             | It's not good for their legit customers that are
             | politically unpopular. Porn/Adult hosting services get a
             | lot of trouble for this exact reason.
        
       | bdcravens wrote:
       | That's all?
        
       | ChrisArchitect wrote:
       | Actual article: https://blog.cloudflare.com/application-security-
       | report-2024...
        
       | eduction wrote:
       | Crime is up in your neighborhood, says company that sells burglar
       | alarms.
        
         | robertlagrant wrote:
         | Crime exists, says company that sells burglar alarms.
        
       | solardev wrote:
       | That seems... really low? I would've expected way, WAY more than
       | that.
       | 
       | Even later on in the report, they say:
       | 
       | > 31.2% of all application traffic processed by Cloudflare is bot
       | traffic. [...] 93% of bots we identified were unverified bots,
       | and potentially malicious.
       | 
       | So I guess there's a wide range there, from 7% verified at the
       | low end, up to maybe 30% at the higher, hypothetical end?
        
         | wkat4242 wrote:
         | I would personally consider ad tracking networks malicious too
         | so i think that's pretty low yeah :)
        
       | netsharc wrote:
       | > In one case, attackers attempted to exploit a JetBrains
       | TeamCity DevOps authentication bypass a mere 22 minutes after the
       | proof-of-concept code was published.
       | 
       | Ha, I wonder if an LLM can be told to "code an exploit from this
       | proof-of-concept, find hosts where this app is running and give
       | me admin access"...
        
       ___________________________________________________________________
       (page generated 2024-07-17 23:14 UTC)