3 ms·
Different responder, but I imagine they are referring to CloudFlare's stated ability to: Provide command logs and session recordings to allow administrators to
by jdbernard 2y ago
Different responder, but I imagine they are referring to CloudFlare's stated ability to:
Provide command logs and session recordings to allow administrators to audit and replay their developers’ interactions with the organization’s infrastructure.
The only way they can do this is if they record and store the session text, effectively a keylogger between you and the machine you are SSH'ing into.
- acdha 2y agoKeylogger has a specific meaning which doesn’t refer to audit logging. Trying to scare people by misusing loaded terms has the opposite effect from what you intend.
- michaelt 2y ago"mitm keylogger" has a specific meaning and refers to a party in the middle of a connection, logging the keystrokes.
- acdha 2y agoBoth terms are used to refer to attacks, not oversight of your own systems.
- hiatus 2y agoNo, here's a counter example: https://www.interguardsoftware.com/keylogger-software/ https://www.interguardsoftware.com/keylogger-software/
- acdha 2y agoI’ll concede that keylogger is sometimes used in a corporate workstation monitoring context but it isn’t really the same as session monitoring on servers. The main thrust of my comment was simply that using loaded language to make common needs sound scary is distracting from rather than helping matters.
- jdbernard 2y agoI think the original poster's intention was to be somewhat inflammatory as a way to draw attention to the very high level of trust you are granting to CloudFlare in this model. You are effectively giving them whatever privileges you yourself have on those boxes. Of course, CloudFlare is making it their business to be and convince others that they are that trusted third-party.
- be_erik 2y agoKeyloggers are absolutely used for audit logging. I've implemented these MiTM patterns specifically so we could log all keystrokes. The addition of a keylogger is only an issue if you don't trust Cloudflare, but usually a checklist item for these kinds of bastion hosts in certain compliance environments.
- acdha 2y agoYes, but it’s not a man in the middle attack when it’s monitoring your own servers any more than it’s a privacy breach when HR looks at your file. My intent was simply that trying to make things sound scary by using language normally used in adversarial contexts really isn’t helpful when talking about things companies need to do. There isn’t an expectation of privacy what what you do on company servers.