4 ms·
Cloudflare is a threat to privacy and security with their "Flexible" SSL/TLS option. With the click of a button, Cloudflare will happily strip the TLS connectio
by RKearney 6y ago
Cloudflare is a threat to privacy and security with their "Flexible" SSL/TLS option. With the click of a button, Cloudflare will happily strip the TLS connection off your visitors requests and proxy it over plain-text back across the internet to your origin.
When I reached out to Cloudflare on this 3 and a half years ago, asking if they could at least inject a header like X-CF-SSL: Flexible or something to indicate to the end-user that their connection was in fact not secure. Extension developers could then use this header to inform the user that this was happening. I was told that they would "pass it along", but of course nothing has changed.
CloudFlare will give you a privately signed, 15 year certificate to use to secure communication between Cloudflare and your origin in the event you can't get a publicly signed certificate, so there's really no excuse to continue to allow this terrible feature.
- omnimus 6y agoSo i just migrated some domains there recently just for DNS for first time and i was really confused about that feature (some of it was turned on automatically). Ux wise it seems they want you to have it on. Not sure why.
- nahtnam 6y agoWhile I agree with you, I'm guessing that the vast majority of the users of this feature wouldn't have SSL without it, so it's better in some sense?
- amenod 6y agoOf course they would, soon after they would start getting questions about that red lock next to their domain name. CloudFlare is here preventing browsers to do the right thing.
- r1ch 6y agoI'd argue it's worse than no SSL, at least then I have a signal from my browser that I shouldn't be submitting sensitive information.
- saagarjha 6y agoFlexible SSL/TLS is useful as it truly does provide some of the benefits of a secure connection–it certainly prevents ISP ad injection and casual coffee shop network sniffing–but its major problem is the one you've identified, which is that it's difficult to distinguish from a "true" SSL connection. I suspect the people who are using this feature are doing so because they won't be using a secure connection at all otherwise, not because they are somehow unable to set up Let's Encrypt.
- r1ch 6y agoI've had Flexible SSL default on several times when setting up domains, it's not always a conscious choice. For small businesses who perhaps don't know any better, they move their site to CF, see the green lock in the browser and think everything is fine. It's an extremely dangerous feature and for a security company CF should really be doing better.
- Kalium 6y agoHow would you go about helping small businesses who don't know any better do things correctly in a way that would be easy for those with sharply limited technical resources to implement?
- 0xy 6y agoFlexible SSL is a measurable security improvement over no SSL at all. I'd argue that end ISPs are far more likely to tamper with or inspect packets than the tier 1 providers between CF and your infra. So, it's better than nothing. It doesn't make HTTP sites worse.