4 ms·
First of all, CF cannot see or alter anything that happens in the SSH tunnel (except killing the connection), because the handshake is done with our servers and
by T4cC0re 7y ago
First of all, CF cannot see or alter anything that happens in the SSH tunnel (except killing the connection), because the handshake is done with our servers and only those have the private keys that match our published fingerprints. This will not change.
> If CF (or anyone really) is in the middle, then couldn't we say that SSH and HTTPS are not (or less) secure?
I guess that depends on how you define 'secure'.
The confidentiality aspect of security is reduced, by letting a 3rd party (Cloudflare) inspect the traffic. However, as stated before, they do not log contents keep metadata briefly. And I have no reason to believe they do otherwise.
Utilizing CF's technology to help prevent a possible breach of GitLab's servers however, strengthens security in my book.
Speaking of breaches. IMO a breach (whether it be at Cloudflare or at GitLab) would be horrific in its own right. But, if an attacker manages to compromise TLS traffic by attacking Cloudflare, they would gain access to that traffic and thus any authentication credentials within it. The blast radius would be limited.
Breaching GitLab.com however, has the potential of putting all customer's data at risk.
As cruel as it sounds, but I'd rather have a potential breach in front of GitLab. Well, ideally none at all.
I do understand the concerns about having to trust a 3rd party. And as you have pointed out, it comes down to trust.
By publishing this information beforehand we want to make it easier for everyone to keep their trust in us, build new trust with Cloudflare, as well as to live up to our values (transparency specifically in this case).
And it is my firm belief, that speaking candidly in these matters is important.
- lioeters 7y agoThank you for your response. I suppose I'm coming to grips with the security (and maybe more about privacy) implications of Cloudflare's immense popularity. The fact that both Cloudflare and GitLab are so up front, open and transparent about the compromises and advantages involved does ease my worry somewhat. That's a good point about the upside for GitLab users, that a potentail breach at CF would be limited to that layer, and not GitLab itself. All in all, the article (and your explanation) has convinced me that this is a net positive. --- EDIT: To be honest, the point about Cloudflare being able to inspect HTTPS traffic still doesn't sit well with me. I suppose I'll need to study deeper how this works, before I'm persuaded.