One of the few reasonable comments on this thread.
I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters.
Zero evidence that cloudflare actually enabled the attack itself from what I can tell.
Cloudflare enables this because their stance is that they are a neutral carrier who is not responsible for the data they carry. If I send an abuse report to github for content on their system, there is a chance that I will be annoyed by how they handle it.
Cloudflare's core thing OTOH is to hide who I could be sending an abuse report to,
Possibly they will forward it ( more likely not) , but they will include my personal information in a report to an entity that is unknown to me, who are likely criminals, exposing me to danger.
Do you think people in that space aren't going to go after the "million other" static site hosts for hosting their content though? Yeah it's a game a whack a mole but there are some motivated whackers out there because they really don't like DDoS for hire services.
I don’t see how cloudflare could have prevented this at all. Even if they took down the info site of the attackers they could just host it on GitHub pages, or a million other free static site hosters.
Zero evidence that cloudflare actually enabled the attack itself from what I can tell.