3 ms·
> utterly unconvincing Why?
by fredsted 6y ago
> utterly unconvincing
Why?
- zymhan 6y agoThey provide no source for the "DDOS for Hire" claim. Sure, Cloudflare can decrypt SSL traffic and send it to the origin server unencrypted, but that can be (and is) done without Cloudflare involved at all, and you aren't any safer that way. The VPN claim is just basic facts about how a VPN works, but they're wrong in saying it won't protect you. It will, if your local network or ISP is untrustworthy. And then it just ends with them complaining about the BGP vulns they were called out on.
- detaro 6y agonews article about it (with statement from Cloudflare, TL;DR "yes we get paid by such services but we don't want to be in the business of deciding if they are bad or not"): https://www.secureworldexpo.com/industry-news/does-cloudflare-protect-ddos-sites https://www.secureworldexpo.com/industry-news/does-cloudflar... > Sure, Cloudflare can decrypt SSL traffic and send it to the origin server unencrypted, but that can be (and is) done without Cloudflare involved at all, and you aren't any safer that way. So because you could run an unsafe configuration without Cloudflare, it's ok for Cloudflare to offer it? I think criticism of Cloudflare is often overblown, but it's not like they are perfect. Run agressive marketing, expect to get called out for your failings. EDIT: apparently their own route validation also isn't that strict? https://twitter.com/Benjojo12/status/1251538757595148291 https://twitter.com/Benjojo12/status/1251538757595148291