18 ms·
Their main product is breaking end-to-end encryption. You could certainly argue that that's no different than relying on azure, aws, or gcp to issue your cert
by fjni 4y ago
Their main product is breaking end-to-end encryption.
You could certainly argue that that's no different than relying on azure, aws, or gcp to issue your cert and technically having the ability to decrypt traffic to your server for whatever reason they want to. And that all of this is just a matter of who to trust. It's just very very centralized for something so crucial.
Cloudflare so far hasn't been successful with its other product offerings, but they could go in a direction where they can blackmail you into being their customer: IF, for example, cloudflare were to succeed in making their 1.1.1.1 service (https://1.1.1.1 https://1.1.1.1) as popular as they have been able to with the DOS/DNS service, there is nothing that would stop them from either not serving a page to you as an end-user UNLESS you use (and pay for) 1.1.1.1, or stop them from serving your website as an operator UNLESS you use DOS/DNS service offered by them. As other commenters have pointed out their blanket rules on TOR traffic is both understandable practically, and a preview of this if it were to be used maliciously.
I am in no way insinuating that cloudflare builds their products with this motivation, or that their current team has any of these (In fact I do tend to agree with you that the people who work there mostly just want to build great products.) The issue is that I'd rather not have a company around that can be in a place to do any of that once the good people leave.
It'd just be a lot nicer if some of the fundamental things of the internet could follow some of the more original philosophies of building great concepts, and allowing anyone to implement them. I don't want to get to a place where there's a "cloudflare internet."
None of this is to say that cloudflare is the only or even most concerning actor to whom this criticism applies. But that is who you asked about.
- sophacles 4y agoHow would you make a CDN that doesn't require decryption?