3 ms·
Thank you, it looks like you have your moral compass pointed to the right direction :-) While I applaud the things above I'm concerned about Cludflare's (growi
by hendi_ 8y ago
Thank you, it looks like you have your moral compass pointed to the right direction :-)
While I applaud the things above I'm concerned about Cludflare's (growing) size. If it handles so many websites' traffic it's an interesting target for NSA, hackers and other malicious actors. I assume that most of your users use the free SSL certs, meaning Cloudflare possesses their private keys.
The more Cloudflare grows, the faster and the more encrypted "the internet" becoems. But the more Cloudflare grows, the bigger the single point to attack gets (I'm even assuming Cloudflare is and always will be a good actor).
What's your stance on this? Could you comment on this?
- jgrahamc 8y agoI/we worry about hackers and malicious actors all the time. One of the reasons we're greatly expanding our infosec department and hired Joe Sullivan [1] is to help keep us safe. We're doing a lot of work with memory-safe languages (hello, Rust!) to help stop Cloudbleed from repeating itself. [2] We're doing stuff around physical location of private keys [3]. And so on and so on. We're open about government requests [4] and we've been pretty robust with stuff like NSLs; we went to court to be able to release NSLs [5] and were able to release two. [6] [1] https://blog.cloudflare.com/why-im-joining-cloudflare/ https://blog.cloudflare.com/why-im-joining-cloudflare/ [2] https://blog.cloudflare.com/writing-complex-macros-in-rust-reverse-polish-notation/ https://blog.cloudflare.com/writing-complex-macros-in-rust-r... [3] https://blog.cloudflare.com/geo-key-manager-how-it-works/ https://blog.cloudflare.com/geo-key-manager-how-it-works/ [4] https://www.cloudflare.com/transparency/ https://www.cloudflare.com/transparency/ [5] https://blog.cloudflare.com/ninth-circuit-rules-on-nsl-gag-orders/ https://blog.cloudflare.com/ninth-circuit-rules-on-nsl-gag-o... [6] https://blog.cloudflare.com/cloudflares-transparency-report-for-second-half-2016-and-an-additional-disclosure-for-2013-2/ https://blog.cloudflare.com/cloudflares-transparency-report-...
- bogomipz 8y ago>" One of the reasons we're greatly expanding our infosec department and hired Joe Sullivan [1] is to help keep us safe." I am assuming this is the same Joe Sullivan, the former CSO at Uber who was fired for failing to disclose the 2016 data breach to regulatory officials or notifying the 600K drivers and 57 million customers that were affected? [1][2][3] And keeping it secret for more than a year? I am not sure that association instills confidence. [1] https://www.darkreading.com/informationweek-home/ubers-response-to-2016-data-breach-was-legally-reprehensible-lawmaker-says/d/d-id/1330997 https://www.darkreading.com/informationweek-home/ubers-respo...? [2] https://www.engadget.com/2017/12/01/uber-but-for-toxic-techbro-culture/ https://www.engadget.com/2017/12/01/uber-but-for-toxic-techb... [3] https://www.technologyreview.com/s/609539/uber-paid-off-hackers-to-hide-massive-data-breach/ https://www.technologyreview.com/s/609539/uber-paid-off-hack...
- Operyl 8y agoFrom what I understood, it wasn’t his choice to keep it secret was it? I mean they lobotomized his team and everything it felt like.
- bogomipz 8y agoThen he should have blown the whistle no? I mean his title was CSO. Wasn't there a moral imperative there to notify millions of users who were affected? I don't think its a stretch to say by participating in a cover up you are complicit even if the original decision wasn't yours.
- davidsong 8y agoCall me a tinfoil hatter but I've always assumed that the likes of Cloudflare, knowingly or not, are a key part of the Internet surveillance state. It would be relatively easy for the likes of the NSA to infiltrate DDoS protection companies, then DDoS dark target sites until they choose cheap DDoS mitigation and bring their users' traffic into the clear.