6 ms·
Of course, but that's his point. Most of the time people don't go through the effort of putting their mailservers/nameservers/etc. behind a proxy. I'm pretty
by ZoF 10y ago
Of course, but that's his point.
Most of the time people don't go through the effort of putting their mailservers/nameservers/etc. behind a proxy.
I'm pretty comfortable guessing that 95% of CPanel/Plesk users that use cloudflare(or another CDN) _and_ host their own mail/name-servers don't put the latter behind a proxy; and they often are on the same box as the webserver.
Edit: Which is to say that this doesn't effect someone doing it 'right', but almost everyone is sloppy(most people just don't care as they're not actively being DDOS'd).
In reality even using this to find the webserver they will eventually get wise to how you're finding the IP(likely) and swap to a new one(depending on their hosting situation) this time putting all other DNS resources 'behind proxies'.
- manigandham 10y ago> Most of the time people don't go through the effort If people don't put in the effort for the security they need, then they won't have that security. This applies to any concept and I dont see how this has anything to do with a single vendor who just provides the tools and service.
- joepie91_ 10y agoBecause the whole selling point of CloudFlare is that the customer supposedly doesn't need to invest effort into security, because CloudFlare will handle it all for them. Which is obviously not the case, but that's what the marketing says.
- manigandham 10y agoThey do handle a lot, doesn't mean you're not responsible for the settings you choose. Lack of understanding or effort on your part doesn't mean you get to just blame the vendor.
- joepie91_ 10y agoThis is almost literally how they are marketing their product: https://www.cloudflare.com/overview/ https://www.cloudflare.com/overview/ Either you invest effort into security anyway and you don't need CloudFlare, or you don't invest effort into security and CloudFlare won't save you either. In neither case is CloudFlare the solution.
- manigandham 10y agoOr the logical way to think about this is that CloudFlare is another vendor that you can use (amongst many) to create the security you need with the trade-offs that are acceptable. Marketing does not absolve you from proper configuration... clearly you have it out for this company for some reason.
- ZoF 10y agoYes, I personally wasn't trying to convey anti-CloudFlare sentiment, I even said "and other CDN providers" I don't think this is a 'CloudFlare vuln' or the responsibility of CloudFlare to resolve etc... I maintain that it is sloppy work that leaks the underlying webserver IP, but also that few people care about doing so.