3 ms·
Cloudflare gets a lot of hate for the core concept of their business model, but I still just don't see it as nefarious or even weak in terms of security if you
by deftnerd 10y ago
Cloudflare gets a lot of hate for the core concept of their business model, but I still just don't see it as nefarious or even weak in terms of security if you set it up correctly.
I always configure my Nginx instances to only respond to Cloudflare's IP ranges.
I tell Cloudflare to sign all communications with my origin server and I configure Nginx to validate those signatures.
I encrypt the communications between my origin and their system.
How can this be man-in-the-middle attacked even by a state actor? I'm ensuring that not only is the data encrypted between Cloudflare and my origin server, but that I'm verifying that nobody is able to impersonate Cloudflare.
- jgrahamc 10y agoNice to see you using our authenicated origin pulls feature: https://blog.cloudflare.com/protecting-the-origin-with-tls-authenticated-origin-pulls/ https://blog.cloudflare.com/protecting-the-origin-with-tls-a... I think we get a lot of criticism because we explain clearly what we are doing and people pick over it. There are always going to be criticisms but I'd rather we be transparent and take some heat than say little and clients not fully understanding how we operate.
- lmm 10y ago> I still just don't see it as nefarious or even weak in terms of security if you set it up correctly. Sure. With the correct settings it's fine. The problem is their "Flexible SSL" setting, which should be labelled something like "My site is not secure, but I want to lie to my users and pretend that it is." Yes, clients still have to choose the bad option, but CloudFlare should not be offering it to them.