5 ms·
Hate to ask if this is obvious, but what are said red flags from the past couple years IYO?
by HollowMan 4y ago
Hate to ask if this is obvious, but what are said red flags from the past couple years IYO?
- alwayslikethis 4y agoThey essentially have MITM capabilities over a significant portion of the web, undermining TLS security. They have a tendency to deny access to normal users using privacy-friendly setups (Tor, without Javascript, etc), and them operating in net loss (implying that the shareholders value growth, i.e. gobbling up even more of the internet infrastructure). Some people are also concerned about their emerging ability as a powerful force for censorship and surveillance, but they seem to have maintained a good stance on free speech so far (not sure about surveillance). Cloudflare threatens the nature of the web as a somewhat decentralized system, although it is not the only one doing that.
- dx034 4y agoAs a website owner, pretty much all traffic I see from Tor is malicious. I also block it outright now, it decreased bad traffic by a lot. So I can understand the decision of CF here. The problem is not Cloudflare or Tor, it's the people abusing Tor.
- alwayslikethis 4y agoIt happens even when you don't use Tor. It gradually creeps up in frequency the more privacy-friendly settings you use. You get stopped on a bunch of websites nowadays forcing you to run their proprietary JavaScript just to identify and track you to ensure you are not a robot.
- vntok 4y ago> websites nowadays forcing you to run their proprietary JavaScript just to identify and track you to ensure you are not a robot. Well yes, this is a good thing. The vast majority of human-made websites aim at serving humans, not unverified bots.
- swyx 4y ago> they seem to have maintained a good stance on free speech so far good by who's definition? because there are plenty of people who hate cloudflare for flip flopping on nazi sites and will also heap that hate on just regular SWEs who join cloudflare who dont really have anything to do with those decisions.
- charcircuit 4y agoThey essentially have MITM capabilities over a significant portion of the web, undermining TLS security Cloudflare is on them edge of your infrastructure. It's not in the middle of your service's infra and the user. It's not undermining TLS security because you are explicitly sharing the decrypted data with cloudflare to let them cache and protect your site. >They have a tendency to deny access to normal users using privacy-friendly setups (Tor, without Javascript, etc) To protect yourself against a bad actor you will need to fingerprint them and then imposes restrictions on them. People who are using privacy friendly setups look like they are trying not to be fingerprinted or have a shady fingerprint. By getting rid of a unique fingerprint that Cloudflare can learn to trust you end up always looking suspicious. Cloudflare did develop privacy pass to give these people a better experience when accessing websites protected by Cloudflare. >and them operating in net loss (implying that the shareholders value growth, i.e. gobbling up even more of the internet infrastructure). There are many competing CDNs. Most web traffic doesn't even use Cloudflare. There is still plenty of room for Cloudflare to grow. >Some people are also concerned about their emerging ability as a powerful force for censorship and surveillance This is a problem in general with internet service providers. ISPs can just decided not to peer with you or just null route your IPs. Cloudflare is less of a problem compared to major consumer facing ISPs. >Cloudflare threatens the nature of the web as a somewhat decentralized system So do DDoS attacks. If the small guy can't keep a site online like the big guys can that leads to a less decentralized web.
- yencabulator 4y ago> They essentially have MITM capabilities over a significant portion of the web, undermining TLS security. There's actually some work being done to make CDNs not able to MITM the origin. https://web.dev/signed-exchanges/ https://web.dev/signed-exchanges/ https://developer.chrome.com/blog/signed-exchanges/ https://developer.chrome.com/blog/signed-exchanges/ Also, it's pretty common to use cloud X's load balancing service(/serverless product/etc) when hosting on cloud X, thus giving AWS/GoogleCloud/Azure similar MITM capabilities.
- berkle4455 4y agoThey’re a backdoor access point for the US government.