4 ms·
Why lol? Not being a douche - I'm genuinely curious why that is a laughable suggestion.
by ry_ry 9y ago
Why lol?
Not being a douche - I'm genuinely curious why that is a laughable suggestion.
- Animats 9y agoCloudflare MITMs your secure connections. If you get the cheaper Cloudflare options, it's really insecure.
- aeronautic 9y agoYes it does that and that will rule it out for some apps. An option for many sites is to configure CloudFlare in pass-through mode (no MITM) and then just switch it on when you are being DOS'd.
- corobo 9y agoIs that even an option? Where is that setting?
- aeronautic 9y agoThat is the cloud icon. Make it gray and it is just a DNS. i.e. DOS protection armed and ready, but not active until you need it. That is how we use it.
- corobo 9y agoAh I see, I thought there might be a setting I'd missed that just forwards your traffic through without cache etc
- aianus 9y agoBut then the attackers know your origin IP from before you turned on MITM and can just DDOS it directly.
- jgrahamc 9y agoWe offer free origin certificates on any plan level (yes, including FREE). It's not 'really insecure' and you seem to imply that encryption costs more with Cloudflare. That's not true. https://blog.cloudflare.com/cloudflare-ca-encryption-origin/ https://blog.cloudflare.com/cloudflare-ca-encryption-origin/
- Animats 9y agoYour data is in the clear within Cloudflare, and may even be in the clear between Cloudflare and the real host if you choose that option. You're trusting Cloudflare's security and Cloudflare's internal certificate authority. Hundreds or thousands of sites would be compromised if Cloudflare had a security breach. Like the one they had three months ago.[1] [1] https://techcrunch.com/2017/02/23/major-cloudflare-bug-leaked-sensitive-data-from-customers-websites/ https://techcrunch.com/2017/02/23/major-cloudflare-bug-leake...
- jgrahamc 9y agoData is only 'in the clear' inside a machine. All machine to machine communication in Cloudflare is encrypted with mutually authenticated TLS. If a user chooses to not encrypt the back haul from Cloudflare to their origin then, sure, that's not encrypted, but we offer free certificates for origin machines so there's no reason to use that option. If you don't like Cloudflare's Origin CA then use Let's Encrypt on the origin server.
- aeronautic 9y agoThanks so much for clarifying. We use your service - would recommend in a heartbeat.
- daxorid 9y agoEven so, there's nothing preventing a LE or court order from compromising the confidentiality of your customers, no matter how hard you work on minimizing the scope of your cleartext domains. I know that you, Prince, rdl, and others are serious about security and privacy, but let's be honest here: If the Feds come a-knocking, you will comply. It's not that we don't trust you or your competence. You're just not immune to the jackboot threat model.
- ezequiel-garzon 9y agoBeing a security-focused post, it probably refers to https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752