4 ms·
While in most cases - Cloudflare is better then no Cloudlfare as discussed in the article. It seem however it's nontrivial for a user to determine whether or n
by YBMckUGrk4Pk 10y ago
While in most cases - Cloudflare is better then no Cloudlfare as discussed in the article. It seem however it's nontrivial for a user to determine whether or not a site is hosted on Cloudflare, because there is certain threats that it can't protect against. If people had a browser plugin to alert if the vendor is capable of doing such MITM, then it would be up to the user if they want to recieve content where it's capable of not being sent end-to-end. Sadly it's a bit hard to make that judgement call, since all CDN's do very similar things.
The only way to make this "less bad" would be if there was a way to determine if the backend infrastructure was in fact loaded end-to-end via TLS. Perhaps some non-cachable content? Not sure what the right answer is here.
- _-- 10y ago"it's nontrivial for a user to determine whether or not a site is hosted on Cloudflare" It's easy to detect when Cloudflare is being used. There are multiple ways.
- gkop 10y agoIs there a Chrome or Firefox plugin that can detect non-"Full (strict)" and alert me?
- johnp_ 10y agoYou could try Wappalyzer. Your comment just reminded me of that gem. No security state detection though. May be added if CloudFlare adds an x-cloudflare-crypto header. https://wappalyzer.com/applications https://wappalyzer.com/applications
- YBMckUGrk4Pk 10y agoThat might actually be what we're looking for, we assume that cloudflare is already trustworthy since they're performing the MITM - however there is no way for the client to distinguish whether the backend network is in the clear or not without such an indicator. Also this assumes we're OK with Cloudflare to report the backend status accurately and that can't be spoofed as well.
- anexprogrammer 10y agoJust use the net via a VPN when out and about. You'll rapidly find out who's running CF, and how incredibly annoying their constant captchas become. (Approx 25% of the time CF decide my VPN provider (PIA) needs captchas. This lasts a couple of days, then rest of week clear. Repeat) They're positively surfer hostile.
- 9248 10y agoI'm actually planning on renting a VPS soon to use as a personal VPN, dedicated IP, hopefully dedicated bandwidth etc. I don't have even the smallest idea how to configure one or what software I actually need, BUT, my greatest fear is that I'll end up with a pretty "broken internet" since I won't be using a residential IP anymore. Cloudflare will just think that I broke into some random wordpress site and started using the server to ddos (who? with 1-2 requests/minute?). It doesn't look that they implement any kind of serious IP reputation algorithm. I have a static residential address since I remember signing the contract, almost a decade ago, pretty paranoid about security with a clean PC and I never seem to stop getting captchas. Is PIA a paid only service? I doubt any "hackers" will be using it to break cloudflare sites. On the contrary, I'd argue its users are actually more civilized than the residential folks.
- anexprogrammer 10y agoNot sure I'd want a VPN via a VPS, as you'd lose the anonymity of being just one of a swarm using a particular IP point of presence. Though you'd probably get fewer CF captchas, but all traffic would be you. I've no idea how clever CF are (tempted to quip clearly not clever enough) to decide their sites or their network is under attack. I'd imagine there's going to be a lot of connections from PIA's users, from all the various regional exits. Same for all the other VPN companies. I can't believe they can't be distinguished from a real DDOS or whatever else they see as "bad traffic". Where Cloudflare start winding me up is they treat each domain alone. I get a captcha on blog a, 30 seconds later I'll get another at company b, 5s another at blog c. If CF gave me a 3 or 24 hour cookie I'd hate them so much less! (There's a couple of ways around captcha madness - If I switch to another exit I can usually get a captcha free one) PIA is paid, but good value - around $35 a year.