6 ms·
Every time I see a post by Cloudflare, I get more and more nervous. Why? Because each time they introduce something, they end up at the controls. What if, if,
by cremp 8y ago
Every time I see a post by Cloudflare, I get more and more nervous.
Why? Because each time they introduce something, they end up at the controls.
What if, if, their internal network is breached; or an unhappy employee is at the wheel?
Not only would it be possible for them to use everything at their disposal, but they can start to sell user data; internal ports exposed.
Considering bugs are a fact of life for developers; how long will it be until there is a big hole? Heartbleed was one; what's the next?
- m_b 8y agoCentralization is of course the problem here, I don't want to give more power to these corp.
- MrEldritch 8y agoI'm expecting Cloudflare, or something like them, to eventually become The Internet Company.
- cagenut 8y agothe only reason it feels like this on HN is because cloudflare is much more focused on "retail" level marketing than the competitors. fastly is roughly the same size, akamai and edgecast are bigger than both. all of them are gnats compared to the big three cloud providers. (not counting the verizon factor w/EC)
- blattimwind 8y ago> Considering bugs are a fact of life for developers; how long will it be until there is a big hole? Cloudflare already had one (cloudbleed).
- jasonvorhe 8y agoCome on, everyone was affected by that.
- mikeash 8y agoAre you thinking of Heartbleed, which was an OpenSSL bug? Cloudbleed was specific to Cloudflare. https://en.wikipedia.org/wiki/Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed
- deleted 8y ago[deleted]
- matthewaveryusa 8y agoWhat's going over the tunnel can still be encrypted.
- zackbloom 8y agoOne of the fundamental truths or the move to the cloud has been large organizations which can focus on security tend to do it better than each of us doing our best alone. It just takes too many people to keep a modern system secure, that's unfortunate, but it seems true. All of the security failures we hear about tend to be in bespoke systems, not GCP or AWS.
- deleted 8y ago[deleted]
- zAy0LfpBZLC8mAC 8y agoThat is wrong on so many levels. For one, the idea of "delegate security to a central authority because they know what they are doing" is one that has failed so catastrophically in history it's surprising anyone still considers it a convincing argument. If there is one thing humanity should have learned, it's that centralizion of power is itself a major security problem. Electing dictators to solve security problems does not work. Then, "we have to give all power to cloudflare or we are on our own" is obviously a false dichotomy. No, people can work together on fixing security problems without the need to delegate power to a central authority. Also, it isn't hard to keep "a modern system" secure. It's just that noone cares, in part because they think they can just buy security as a product that they somehow plug into their system to make it secure. But that is just a completely mistaken approach. You can buy "IT security" as much as you can buy "car safety". If the engineering of your car is shoddy, no add-on will make if safe, and it's exactly the same for IT systems--and if the engineering is solid, there is no need for "safety add-ons". BTW, one particular kind of "security" that large organizations are good at is controlling PR. It's just that that is not in your interest as their customer. It's just one of many conflicts of interest.
- cronix 8y agoI've thought about this as well, but in a different sense. Think if cloudfare were actually the NSA. Seeing as how ssl terminates at their edge server before they pass it off to your actual server (whether they re-encrypt it or not), they have access to all of the decrypted traffic in transit before it reaches your server, don't they? > When you use Cloudflare, we must decrypt the data at our edge in order to cache and filter any bad traffic. Depending on the SSL setting from the options above, we may re-encrypt or send it as plain text. (full vs. flex) Since each certificate needs a dedicated IP address, we add your domain name and wildcard (*.domain.com) domain in the SAN (Subject Alternative Name) to the certificate.[1] [1] https://support.cloudflare.com/hc/en-us/articles/204144518-SSL-FAQ https://support.cloudflare.com/hc/en-us/articles/204144518-S...
- ezekg 8y agoI think it’s highly likely that Cloudflare is at least associated with the NSA/CIA, maybe more. Also Google, Facebook. One of the reasons I don’t own a Home/Alexa/etc. I value privacy.
- cronix 8y agoIt would be perfect for them. Instead of having to hack, just get them to come to you under the guise of DDoS protection. "Hey, everyone's starting to encrypt and we can't get the data as easy as we used to." "Well, DDoS is a big problem out there. What if we offered a DDoS protection service because very few companies can afford the huge pipes needed to mitigate those attacks." "Perfect! We can offer it to free for most sites, and offer "free" SSL encryption that terminates on our end." "Yes! We'd gain their trust by offering such a service and they'd COME TO US begging for help." I've wondered about LetsEncrypt as well. Since they're they ones generating these "free ssl certs", don't they then have the means to the decrypt the data? Yes, I'm cynical, but I think we need to be. Same scenario as above. "Hey, we can just offer free certs and they will just give us the keys."
- unilynx 8y agoLetsEncrypt, no. they don't ask you for your private key when you get a certificate, so they can't decrypt anything.
- zenlot 8y agoThey have recently released Android app for DNS 1.1.1.1 requiring microphone access, then silently removed it after users noticed.
- dknecht 8y agoThis was a bug in the way we were using a third party tool called Instabug. We removed it as soon as it was pointed out.
- lingrino 8y agoOne interesting benefit of using such a large provider is that if a breach or bad behavior were to happen large portions of the internet would suffer, and you'll receive a much smaller portion of the blame. The S3 outage last year was terrible for my employer, but hardly anyone noticed because much more significant sites were similarly suffering.
- eeZah7Ux 8y agoThe usual "nobody get fired for $groupthink_based_behavior" creates systemic risk. A level of diversity is necessary for resiliency and security. This is true for biological systems, social organizations, complex technologies and of course software as well.