4 ms·
What if the site owners change their SSL settings to Full SSL though?
by tomklein 5y ago
What if the site owners change their SSL settings to Full SSL though?
- captn3m0 5y agoIt fixes the issue, and that has been the recommended fix I've been offering developers all this while.
- paco3346 5y agoSo really website owners are just misusing Cloudflare? How is this Cloudflare's fault?
- captn3m0 5y agoIn this case, it is not a random party in the CloudFlare--GitHub connection (say a network operator in UK). The snooping intermediary (Airtel) in this scenario is one that has a commercial relationship with CloudFlare and powers CloudFlare's network. CloudFlare has been aware of this issue for years, but it hasn't done anything to get its vendor to fix their network.
- celsoazevedo 5y agoIsn't the censorship applied by Airtel, Jio, etc, because of local laws? https://en.wikipedia.org/wiki/Internet_censorship_in_India https://en.wikipedia.org/wiki/Internet_censorship_in_India I don't see how Cloudflare or any other provider can make Airtel "fix" the snooping when Airtel is forced by law to block those sites. This seems to be a policy/government problem, not a Cloudflare or Airtel problem.
- captn3m0 5y agoThere is no court order to block neovim.io or teachyourselfcs.com. Airtel isn’t forced to block these sites. It is blocking these because of a mis-configuration somewhere.
- r1ch 5y ago2 of the 4 SSL options Cloudflare provides will give a nice lock icon in your address bar and HTTPS will all look like it's working fine, but the connection to the origin is still insecure. It's very misleading and IMO irresponsible of Cloudflare to offer these options.
- ameliaquining 5y agoWell, they're sending packets to an upstream ISP that then does the wrong thing with them. They certainly have more leverage to get that upstream ISP to clean up its act than their customers do. More broadly, if enabling a particular Cloudflare feature (in this case, Flexible SSL) constitutes "misusing Cloudflare", then Cloudflare should simply not offer that feature at all. There's a bit of a balance here; when they introduced it in 2011, a lot of hosts didn't offer HTTPS at all and none of them offered it for free. MITM is genuinely more likely to happen between the end user and Cloudflare than between Cloudflare and the origin server (because the former can involve things like unsecured coffee-shop wifi), so for webmasters who couldn't use end-to-end HTTPS, it provided a real security benefit—which had to be weighed against the cost of telling end users that their connection to the site is secure against interception, when that wasn't entirely true. I think there's a case to be made that this tradeoff was worth it in 2011 but is not worth it in 2022; today, end-to-end HTTPS can be had for free, and is easy enough that there's usually no excuse not to.
- captn3m0 5y agoEspecially when CloudFlare knows that their upstream is specifically targeting a certain class of users, they have a responsibility to fix this and notify their impacted customers.
- deleted 5y ago[deleted]
- r1ch 5y agoFull isn't actually enough to secure this - with their MITM position, Airtel could send an untrusted certificate and continue to intercept and modify traffic. Full (Strict) is the only safe option.