3 ms·
Ultimately Cloudflare is just another provider you have to trust if you decide to rely on them, just like your web host and anything else you use. For any non-t
by nsgi 8y ago
Ultimately Cloudflare is just another provider you have to trust if you decide to rely on them, just like your web host and anything else you use. For any non-trivial site you should do a risk assessment of the service providers, external javascript and other software you are using to determine whether the benefits outweigh the risks, and for the most sensitive use cases they should be kept to an absolute minimum. As you say, for a static site HTTPS terminated by Cloudflare is more secure than plain HTTP so it makes the most sense in that situation.
- 0942v8653 8y agoHmm I guess you are right, I was just thinking of the simple case (run on your own metal, no external JS, etc...). I am just uncomfortable with the amount of data that passes through Cloudflare and especially the idea of depending on them just to gain HTTPS support (which you could do almost as easily in other ways). Cloudflare as proxy seems at odds with a decentralized view of the web.