9 ms·
CloudFlare’s last Warrant Canary was published over a year ago
- ck2 3y agoIt's weird to me people think warrants are still used. No warrant is needed by any government agent to read your email that is over six months old and the major providers just give them a backdoor so as not to waste any time/money with requests. Who is going to stop them from doing that with anything else? The supreme court? Good luck with that belief system. You think the NSA ever stopped just because they were discovered? Or did they just switch to "try to stop us".
- djur 3y agoTheir "canaries" don't make any reference to warrants, and two of them explicitly rule out providing a backdoor for governments ("Cloudflare has never installed any law enforcement software or equipment anywhere on our network" and "Cloudflare has never provided any law enforcement organization a feed of our customers' content transiting our network").
- barrysteve 3y agoSo.. what? Endless despair?
- soared 3y agoSource?
- adamgamble 3y agoI love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.
- adamgamble 3y agoWhy wouldn’t they fund the worlds largest MITM attack?
- charcircuit 3y agoCloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.
- adamgamble 3y agoWhat am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.
- powersnail 3y agoDoes CloudFlare proxy your website without your permission?
- dns_snek 3y agoYou're being needlessly pedantic. It might not be an attack in the usual sense, but it's a MITM "access point" and agencies like CIA/NSA/FBI would definitely have that kind of access. This access transforms Cloudflare's role into a de facto MITM "attack" on their customers and end users who didn't intend to share unencrypted data with 3-letter agencies.
- powersnail 3y agoI don’t think I’m being pedantic. In practical, the parent comment’s description is not that of MITM attack, but how a proxy works. Proxy is everywhere, useful, and voluntary. I just don’t understand how a voluntary use of proxy can be called MITM attack. I’m not saying I like the fact that CF is part of so much of the Internet, or that CF isn’t on some level a security risk. But that has nothing to do with being an MITM attack.
- cassianoleal 3y agoIt doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.
- eastdakota 3y agoThese threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this silly speculation would end. But guess not. Beyond that, if you think about it, it's a way better business to run Cloudflare and serve the world than serve some US intelligence entity. That's just per se true. So if that's the case why would we ever do anything that would remotely compromise the trust necessary to, you know, be Cloudflare? Lastly, here's a funny story. Early in our history one of our investors suggested that we talk to In-Q-Tel. Here's how naive Michelle and I were: we had no idea it was the CIA's venture capital arm. So we showed up in their office on Sand Hill Road. It was weirdly austere compared with other VCs we'd visited. And lots of security cameras. The partner at some point came out and greeted us. As he was walking us back he looked back right before we crossed the threshold back to the inner offices, "You're both American citizens, right?" "No," Michelle said. "I'm Canadian." "Oh." the VC said. Then you can't come back here.” "I'm not going back there without her," I said. "Ok, well, I guess we'll have to do the meeting in the reception area," decided the In-Q-Tel VC. We had a very cordial meeting and then left. As we were driving away Michelle said, "Those guys were weird." And that was the end of that. Never talked to In-Q-Tel again. But maybe it's the Canadian equivalent of the CIA/FBI/NSA we're beholden to??! ;-)
- TechTechTech 3y agoHi, kind of hijacking this conversation but as Cloudflare is unfortunately routing the majority of websites I visit I have to ask this: Can you guarantee my Firefox browser will keep on working on 'the open internet' now Chrome moves towards "Web Environment Integrity" and Safari towards "Private Access Tokens" and Cloudflare is supporting and implementing such technologies on scale? I intent to not participate in these DRM APIs with my Firefox browser and would like to keep browsing the internet.
- valianteffort 3y agoHeh, he posted the GP comment and went to bed. Good luck getting a response.
- tamimio 3y ago[flagged]
- burnished 3y agoWhat is the language around the non-disclosure order? There seems to be speculation that a warrant canary would be construed the same as a disclosure, but are you required to not inform the concerned party, or required to not disclose law enforcement contacting you at all? From a practical perspective I don't imagine that cloudflare removing a canary could give any one organization a signal - I don't know what the bar for a 'disclosure' is but informally I would not consider it a targeted specific warning. EDIT: the other component I am curious about is duration, there is still utility in the canary even if it comes late, future users will know that there was a compromise and that further ones are likely, right?
- benreesman 3y agoMaybe I’m just getting old and distracted, but I feel like CloudFlare went from “whoa some HN pros are doing great CDN work with some serious chops and an underdog work ethic” to “is it possible to never connect to them” like, really fast.
- tmpX7dMeXU 3y agoI think there was 10 or so years in the middle there :)
- probably_a_gpt 3y agoI think we’d all be pleased to build something out of passion and have it survive a decade without corruption, probably harder than it sounds
- lallysingh 3y agoSo they got a warrant that they can't talk about. That seems obvious.
- JHorse 3y agoTheir Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enforcement organization a feed of our customers' content transiting our network. 4. Cloudflare has never modified customer content at the request of law enforcement or another third party. 5. Cloudflare has never modified the intended destination of DNS responses at the request of law enforcement or another third party. 6. Cloudflare has never weakened, compromised, or subverted any of its encryption at the request of law enforcement or another third party.
- eastdakota 3y agoI'll state right here: all these are still true. We'll get the canary updated. Checking with legal and trust & safety why it hasn't been for so long. Likely just slipped someone's mind. Will make sure that doesn't happen again.
- greatfilter251 3y ago[dead]
- Manouchehri 3y agoHow about make `https://www.cloudflare.com/.well-known/warrant-canary.txt https://www.cloudflare.com/.well-known/warrant-canary.txt`, and use a Cloudflare Worker with a Cron Trigger to trigger an email to legal if it's approaching expiry?
- james_in_the_uk 3y agoBear in mind that there are multiple ways for Cloudflare to give law enforcement or intelligence agencies customer information that do not breach one of these six statements. It doesn’t mean that they are not helpful. Just that - as warrant canaries go - they are not complete.
- tsujamin 3y agoThe glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report (https://www.cloudflare.com/en-au/transparency/ https://www.cloudflare.com/en-au/transparency/) with the same 6 items in it. Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something
- richij 3y agoalso on that page: "Confirmed: July 31, 2023"
- JHorse 3y agoH2 2022 and H1 2023
- deleted 3y ago[deleted]
- tsujamin 3y agoGive H1 2023 has only just wrapped up I optimistically presumed it would be in production now, but I’ve got no idea what the lead time on these reports historically has been
- sulam 3y agoWarrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."
- LorenPechtel 3y agoYes and no. They can say "don't do anything". They can't say "don't avoid doing something." That's the point if the age of the warrant canary notification--they stopped updating it. This is in effect a dead canary, they're saying they are subject to an order they can't disclose.
- 93po 3y agoIs there a precedent for compelling speech, even with something like an NSL?
- EGreg 3y agohttps://en.m.wikipedia.org/wiki/Compelled_speech#:~:text=Peterson%20argued%20that%20the%20law,criminalize%20using%20non%2Dpreferred%20pronouns https://en.m.wikipedia.org/wiki/Compelled_speech#:~:text=Pet....
- zaksoup 3y agoWhy is the commentary of far-right reactionary, who is not a legal expert, commenting on a canadian law, that has nothing to do with warrants, with a citation pointing out that legal experts disagree with him, at all relevant to this conversation?
- TylerE 3y agoProbably the giant “United States” section with dozens of examples?
- Dylan16807 3y ago
- causality0 3y agoIs there a point to a company as large as Cloudflare even having a warrant canary? Half the internet goes through their servers. Of course the US government had or has hooks in them for something or other.
- eastdakota 3y agoNo they don't.
- jvanderbot 3y agoTo legitimize the suspicion. That's always been the point.
- nathanaldensr 3y agoAnd, it's not like there are really alternatives. So what if they were served a warrant? What are they, and the people, going to do about it?
- DANmode 3y ago> Is there a point to a company as large as Cloudflare even having a warrant canary? There was, is. There likely won't be, going forward.
- cj 3y agoRemember, Cloudflare CEO/CTO is active on HN. Their lack of reply (if that turns out to be the case) on this post would be telling.
- eastdakota 3y agoHmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.
- eastdakota 3y agoSorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.
- JHorse 3y ago[dead]
- jgrahamc 3y agoMorning.
- eastdakota 3y agoThink you’re supposed to be on vacation.
- rkagerer 3y agoTime to muster, HackerNews community decided to make a PR event this morning. Thanks for the comments and clarifications in this thread.
- EGreg 3y agoWell, it’s been 4 minutes. I’m calling it!
- tedunangst 3y agoWhat action do I need to take in response? Please advise.
- BillyTheMage 3y agoI'm not an expert, but my course of action is to stop using cloudflare. I never used them for whatever that other thing they do is, but I switched my upstream DNS to quad9 (9.9.9.9).
- edandersen 3y agoChrome should starting warning users if Cloudflare is used to protect a website, due to the risk of MITM.
- ocdtrekkie 3y agoThe biggest MITMer should complain about another service being an MITM? How much has Google now routed to go through themselves or be checked by them prior to serving your destination? Bear in mind Google doesn't have a warrant canary because it is served literally hundreds or thousands of warrants per year, to the tune it's just called a transparency report to count them.
- edandersen 3y agoOkay, Firefox should start warning users.
- tick_tock_tick 3y agoHow do you think any CDN works?
- edandersen 3y agoBy MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?
- jlbooker 3y agoI guess you like those cookie warnings that pollute the Internet these days? Because this would be cookie warnings all over again. Any site that's reasonably popular uses a CDN to increase scalability, improve performance, and add reliability. Half the Internet would need a new pop-up warning that a CDN is in use. The last thing we need is yet another pop-up when a page loads....
- 3y ago
- entriesfull 3y agoSo what's stopping these people that claim to be so righteous by using canaries from lying to you? Anyhow the ISPs and internet backbones are all tapped as many whistle-blowers have already revealed.
- stubish 3y agoNothing stops anyone from lying to you. In this case it would be considered fraud if the lie was discovered or leaked. Which is one of the rationales on why courts cannot compel a company to lie and post false warrant canaries, because it would incriminate them.
- flangola7 3y agoCourts absolutely can and do compel companies to maintain warrant canaries. Fraud? Fraud against who? For what damages?
- greyface- 3y ago> Courts absolutely can and do compel companies to maintain warrant canaries. Can you please cite one example of a court compelling the maintenance of a warrant canary?
- stubish 3y agoFraud against paying customers, if they can demonstrate they wouldn't have paid if the company didn't lie. Also competitors if they can demonstrate they lost business due to the lie.
- JHorse 3y agoNothing is stopping them from lying. Signaling that their infrastructure has been compromised is kind of a weird lie for them to make though...
- eastdakota 3y agoThe SEC could throw me in jail. And, sure, you could believe that the FBI or whoever could tell the SEC what to do. We have European and Asian investors too, so their financial regulators could also sue me personally for lying. Perhaps the FBI/CIA/NSA control them too? Gets tricky to believe: the bigger the conspiracy the faster it falls apart. It's really, really hard to be part of some grand conspiracy as a public company.