2 ms·
I see a lot of reasons not to use these providers, but privacy and integrity is not one (and I find it a bad argument against them). Every traffic passes throu
by rmdoss 10y ago
I see a lot of reasons not to use these providers, but privacy and integrity is not one (and I find it a bad argument against them).
Every traffic passes through so many hops, routers and networks that adding a secure, well tested and privacy-paranoid provider, like CloudFlare will not affect the privacy or integrity of your connection.
Yes, they have to SSL terminate your connection, but does so every proxy that they decide to use (nginx, elb, whatever). Plus, the security that a company like CloudFlare has to protect that data is a lot higher and more strict than the majority of sites out there (including the Internet Archive).
It is also frustrating that people would downvote me above for suggesting to use them, when in fact it is the only way to handle a large scale DDoS uness you have an insane pipe with hundreds of G of uplink.
- pfg 10y agoHaving access to the plaintext traffic of 5% of all web sites on the internet makes them a huge target for anyone from hackers to nation states/intelligence agencies and what not. I have a lot of faith in their security team, but this level of concentration is not healthy for the internet as a whole. There's a huge difference between having access to the plaintext of encrypted connections and merely seeing connection metadata, as would be the case with "traditional" DDoS mitigation services that do not act as a proxy. Reverse proxies are certainly not the only way to handle large-scale DDoS attacks, though I would agree that, leaving aside the privacy concerns, those services are hardly competitive in comparison to CloudFlare, especially on price and UX.