7 ms·
The costs of using cloudflare are well understood. We get something for free but lose some control over our site, domain and data. CF gains insight into potent
by devsda 2y ago
The costs of using cloudflare are well understood.
We get something for free but lose some control over our site, domain and data. CF gains insight into potentially valuable data like client information, traffic, attack and request patterns.
The costs and risks should be applicable as long as they enjoy the benefits but anything beyond a certain grace period doesn't sound reasonable.
I can understand if CF didn't prioritize it enough to spend development resources on revoking a cert
but I don't see an upside for CF to continue keeping the certificate after a customer exits. They are unnecessarily taking on extra (reputation) risk if the still valid cert is compromised and used by someone else.
- bawolff 2y ago> I can understand if CF didn't prioritize it enough to spend development resources on revoking a cert but I don't see an upside for CF to continue keeping the certificate after a customer exits. We have no idea if cloudflare retained the cert. The blog post is just claiming that cloudflare did not revoke the certificate and instead is just letting it expire naturally. (That said, i wouldn't be surprised if they retained it) Potential upside for cloudflare is that if the client disabled ddos protection just temporarily to test something but intends to reenable it, this allows the reenable to happen instantly (assuming they kept the cert).
- cchance 2y agoNo one says that CF is retaining the cert lol, the article can't even show that they just know it hasn't been revoked, chances are CF just drops the certificate and deletes it when the user drops their usage, they don't go through the steps to also REVOKE the cert that used to be in use. Which would be nice but honestly most browsers don't even do revocation checks so... ya