4 ms·
It can be less conspiratorial than that. It is a legal and diplomatic challenge for the US to get permission or to install infrastructure to monitor traffic in
by oskapt 7y ago
It can be less conspiratorial than that. It is a legal and diplomatic challenge for the US to get permission or to install infrastructure to monitor traffic in foreign countries. It is much easier for Cloudflare to drop an ingress server there, and they decrypt all TLS traffic that lands on their systems before possibly re-encrypting it and forwarding it over their private network.
Cloudflare is a US company and subject to US coercion. It would be trivial for the US to force Cloudflare to give them access to that data, and with Cloudflare currently decrypting ~10% of all Internet traffic, why wouldn't they?
How about the fact that Cloudflare-issued certificates are for dozens of domains? If the US wants to snoop on foreign domain X, a US order for US domain Y, also on the same cert, would give them the private key.
It's not possible to detect abuse in this system. It requires that we trust the state to not abuse their power, and we've seen them lie about that already.
The mere fact that the Cloudflare system _can_ be abused is, in my opinion, enough reason to go nowhere near it for anything.
- judge2020 7y agoValid concern, just addressing this: > How about the fact that Cloudflare-issued certificates are for dozens of domains? If the US wants to snoop on foreign domain X, a US order for US domain Y, also on the same cert, would give them the private key. Caveat 1 is that they've started to issue 1 cert per domain (I believe only for ECDSA certificates, aka ones that use their own CA), and caveat 2 is that you don't get the actual browser-trusted private key (of course the NSA could demand they turn it over).
- oskapt 7y agoThanks for clarifying. My research there is a couple years old, but before posting I did some spot checking on CF-hosted domains and did see several using 1:1 certificates. They were all financial institutions, so I figured that there was a way to get Cloudflare to not lump them in with the unwashed masses. I did also still see domains secured by certs for dozens of domains. I'm not sure I understand the 2nd caveat that you list. If Cloudflare issues a cert for a dozen different domains, there's one private key, right? Anyone with that private key could decrypt traffic going to any endpoint secured by that certificate?
- tialaramex 7y agoNope. Assuming you're using a modern client that's never how it works. Let's take TLS 1.3 where it's designed from the outset for this use case rather than retro-fitted. The effects are similar even in TLS 1.2 (with a modern client) but it's easier to follow in TLS 1.3 1. Client says "Hi, I'm guessing you are willing to use this elliptic curve key agreement method X, I picked a random number and so now I need to tell you a number I got based on that choice which is A" 2. Server says "OK method X works for me, I also picked a random number and I tell you B" 3. At this moment, Server knows an Ephemeral Secret Key for this TLS session, and as soon as it receives message (2) the Client will also know this key, but an eavesdropper won't know this key. Notice that nothing happened with any Private Keys or Certificates or anything yet! 4. Using the now Encrypted Channel with the Ephemeral Secret Key, the Server can present a Certificate, and prove its identity using the corresponding Private Key (optionally the client can do likewise). Now, an _Active_ attacker can use the Private Key to impersonate a server and then proxy everything. But that's quite a step up from passively decrypting traffic. In Channel Binding scenarios the attacker would need to proxy the binding too, which will get out of hand pretty fast, since in TLS both parties have a per-channel secret and that secret won't match between the proxied and real channels.