7 ms·
It is deeply concerning that regular employees at cloudflare have access to analyze the content of user traffic like this.
by zylepe 8y ago
It is deeply concerning that regular employees at cloudflare have access to analyze the content of user traffic like this.
- li_am 8y agoI thought so too - though I note that the request included 'HTTP/1.1', which I presume means this is solely non-encrypted traffic? Can anyone clarify?
- r1ch 8y agoI would hope that requests to "POST /store/checkout" are encrypted. Cloudflare is a MITM so they can of course see this (and the associated personal / payment data...) regardless of encryption.
- joking 8y agocloudfare also does ssl termination, so it will have access to the traffic between their edge servers and the origin ones.
- zylepe 8y agoYes, as soon as you use the "orange cloud" they have access to traffic, which lets them insert their value-added services for content delivery - and apparently also store and analyze the content of your traffic.
- paxys 8y agoWhat makes you think regular employees have this access?
- zylepe 8y agoThe fact that they can analyze this data for a blog post on Black Friday as opposed to limiting its use to security, network improvements, etc.
- snek 8y agoperhaps an employee was given access to analyse how their network performed across that week, and afterwards was asked by marketing to make a blog post. you're jumping to a lot of conclusions. FUD.
- danpalmer 8y agoMuch of this would be semi-public anyway, they could be analysing HTTPS traffic to find most if not all of these conclusions. Most of it seems to be domain and user-agent based. I'd suspect you could even guess the device type based on IP with reasonable accuracy. It wouldn't be entirely correct, but with the kind of scale Cloudflare deal with it doesn't have to be to be useful. The domain (which is public) gives you the info about whether users are browsing or checking out (if a browser hits api.stripe.com, worldpay, PayPal, some checkout API domain for Amazon, etc, then you can infer).
- zylepe 8y agoThe particular part that is concerning: If you imagine a typical ecommerce application makes a purchase with a HTTP request like “POST /store/checkout HTTP/1.1” we can look for requests similar to this to understand the activity.
- danpalmer 8y agoYep that is more concerning. They might be using unencrypted HTTP to get an idea of the breakdown and then inferring volumes based on HTTPS traffic and known differences between the two. I basically wouldn't jump to "Cloudflare have a bunch of sensitive data and will use it in bad ways", I suspect they have less data than we might assume from the article, and in general their security/privacy stance is great.
- Waterluvian 8y agoHow do you guess the device type based on IP? Do we have any sense how often a mobile device is on wifi? For my brother it's 0%. For me it's 90%.
- danpalmer 8y agoI'd guess based on the owner of the IP range. Mobile carriers are an easy case, business ISPs will likely have far fewer mobile devices, residential ISPs will be a mix. I'm sure if anyone has an idea of the breakdowns and averages it would be Cloudfront.
- depr 8y agoPredictable HN jumping-to-conclusions paranoia. You have no clue who the employee is, you have no idea what exact data they have access to and whether it is anonymized, or what's in the CF terms of service etc.
- zaroth 8y agoIt’s self evident they have full access to the network requests as they are a MITM, and from the article you can see they are in fact logging at least the URLs being accessed, the IPs, and User-Agent for trillions of requests. And they are cavalier enough with the data to use it for writing a random “Black Friday Analytics” blog post that is only tangentially related to their core value proposition.
- mosselman 8y agoThat is my first thought. It makes you wonder who they think they are. I am sure this is all covered pretty well in the TOS, but that doesn't mean it is alright. If this is the stuff they make public about what they can do with all their data, you can only imagine the type of thing that they wouldn't share with the public.
- deleted 8y ago[deleted]