I hear that both CloudFlare is privacy respectful and that it spies on site visitors (with their CDN). What’s your thoughts on this matter?

  • @ajz
    link
    8
    edit-2
    2 years ago

    deleted by creator

    • @linkfix
      link
      0
      edit-2
      3 years ago

      deleted by creator

  • @j0ta
    cake
    link
    83 years ago

    Unprivacy service

  • GadgeteerZA
    link
    63 years ago

    Must say I get a few complaints from people about that aspect of Cloudflare when I link to articles on websites using it. I can’t control where others put good content though.

    The issue seems to be with Cloudflare acting as a man-in-the-middle, supposedly breaking the SSL and re-encrypting it with their SSL. For normal sites that may be OK but this is not a good idea at all if that SSL is expected to carry passwords or login info or other private info that should arrive intact at the destination site.

    So I’ll also be interested to hear what others think and what the solutions are.

    • @kevincox
      link
      53 years ago

      supposedly breaking the SSL and re-encrypting it with their SSL

      There is no doubt here, this is how basically all CDNs work. You need to see the plaintext request in order to perform caching and most other features that they provide.

      I agree, if the content is very sensitive then you shouldn’t trust a third party. However in practice most companies trust third parties whether that is a hosting provider, analytics or any number of functions that it is easier to outsource.

      I think the concern arises because Cloudflare is big. This has benefits and drawbacks.

      • Generally larger companies have more resources to invest in security.
      • Covering such a large portion of the web gives them a lot of possible tracking data if they want to use it maliciously (for whatever your personal definition of malicious is).
      • GadgeteerZA
        link
        13 years ago

        Isn’t Conifer more like The Internet Archive service? I was understanding Cloudflare was really being used to help manage massive volumes of web traffic ie. more the network management side?

    • [object Object]
      link
      7
      edit-2
      3 years ago

      It’s entirely on you. You brought some valid points about how awful Cloudflare is, but that’s not what got you banned. Your baseless claim of Cloudflare DoH somehow MITM SSL is. You are indeed spreading some FUD, even here by strawmanning what exactly you got banned for

      • @j0ta
        cake
        link
        13 years ago

        flare in the name says all

      • @TheAnonymouseJokerM
        link
        -63 years ago

        So you believe Cloudflare is a good company with a good intent? That seems like corporate apologia, since you want to twist my argument into muh FUD.

        • [object Object]
          link
          33 years ago

          So you believe Cloudflare is a good company with a good intent?

          Thanks for putting words in my mouth despite me explicitly agreeing that Cloudflare is awful.

          If that’s how you argue with everyone no wonder you are getting banned. The Mod that argued with you on Reddit had a patience of saint

        • Bilb!
          link
          33 years ago

          In this reply,

          • You imply that they believe something they never said
          • You say without evidence that it is likely corporate apologia, and
          • then accuse THEM off twisting YOUR words.

          Very impressive.

          • @TheAnonymouseJokerM
            link
            -53 years ago

            In their reply,

            • They implied that they think I believe a narrative that I never promoted
            • They imply without evidence that Cloudflare has good intentions when its basis of existence is as Project Honeypot
            • then create a FUD strawman and justify ban when the voting ratio on the comments and in the post indicate a different kind of dialogue
            • totally ignore that my job is privacy and security advocacy, and make it a point to leverage Cloudflare over all the historical and current concerns that loom around them

            Awesome. I can play these pony tricks all day.

      • @TheAnonymouseJokerM
        link
        -23 years ago

        I may not have used teddit in the past few weeks, they handle it correctly now. Thanks.

    • @YngvarSkjaldulfsson
      link
      -33 years ago

      Firefox dev team are jerks, I use Librewolf that is a more secure and private fork of firefox.