3 ms·
My favorite: https://cloudflare.com/cdn-cgi/trace https://cloudflare.com/cdn-cgi/trace
by gaudat 3y ago
My favorite: https://cloudflare.com/cdn-cgi/trace https://cloudflare.com/cdn-cgi/trace
- matthberg 3y ago/cdn-cgi/trace isn't available on just cloudflare.com, it's on every site they proxy too (there might be a setting somewhere to disable it yet it's on by default). I've yet to figure out what happens if your site also serves something there, yet it was surprising to see on a barebones site I had routed through them. I learned this from: https://news.ycombinator.com/item?id=36383258 https://news.ycombinator.com/item?id=36383258
- e28eta 3y agoTIL. Looks like they have it documented (since Apr 2022, based on the github history), it cannot be modified or customized, and that it sometimes causes problems with SEO crawlers! https://developers.cloudflare.com/fundamentals/get-started/reference/cdn-cgi-endpoint/ https://developers.cloudflare.com/fundamentals/get-started/r...
- 1vuio0pswjnm7 3y agosni=plaintext There was a great trial CF ran for a long period with a previous version of encrypted SNI (now ECH). One could get encrypted SNI with any site using CF via modified OpenSSL. But they stopped this experiment. Meanwhile ECH was still not ready. If anyone is getting something other than "sni=plaintext" for a CF domain besides crypto.cloudflare.com, then please let us know how.
- progbits 3y agoIsn't ECH still off by default in most browsers? The latest info I could find has it implemented but opt-in behind experimental flag in both Firefox and Chrome, and not supported at all in Safari.
- 1vuio0pswjnm7 3y agoAnd only enabled by CF in certain regions. Not sure.
- zie 3y agoThat's neat, but that's the opposite of what I'm suggesting. I'm saying if you are hosting web content anyway, then just host a /ip endpoint that returns the IP address. That way you aren't forcing other people to carry your load.