3 ms·
Am I misreading the architecture diagrams or is this going to be the largest MITM scenario in history?
by biomcgary 2y ago
Am I misreading the architecture diagrams or is this going to be the largest MITM scenario in history?
- creatonez 2y agoCloudflare's default is to MiTM all traffic and modify it on an HTTP level. If you opt out of this and configure it to connect directly, you are opting out of most of their products (DDoS protection, page rules, etc.) Is this a huge security problem? Yes, it probably will be, some day. But it is what it is, they don't mislead users about the fact that traffic gets decrypted and re-encrypted.
- xyzzy123 2y agoIt already happened once, remember this? https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug https://blog.cloudflare.com/incident-report-on-memory-leak-c... (Aka CloudBleed https://en.m.wikipedia.org/wiki/Cloudbleed https://en.m.wikipedia.org/wiki/Cloudbleed)
- r1ch 2y agoThe re-encrypted part isn't necessarily true though and you have no way of knowing. Users are misled because they see a nice secure lock icon in the browser, but that only protects the connection to the local Cloudflare POP, the rest of the way to the origin is all vulnerable to MITM. As a security company, anything less than "Full (Strict)" should not exist.
- telgareith 2y agoCloudflare publishes a certificate pair you can pin to your origin servers. They also offer CloudflareD (Tunnels, formerly Argo), which connects origin directly to their network- so no chance of interception or Bypassing their services. So, as long as it's set up correctly- theres no opportunity to MitM between Origin and Cloudflare. Do people set it up correctly? I doubt it. I've seen several companies think they were using CF's WAF product, when all they really setup was DNS.
- mxs_ 2y agoobligatory: https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQyItWMKn252Snfg5KKzvsteLkfFZaqaGoLpg&s https://encrypted-tbn0.gstatic.com/images?q=tbn:ANd9GcQyItWM...
- moralestapia 2y agoContext for that?
- aseipp 2y agoWhat exactly do you think CDNs do?