10 ms·
because they’re an amazing piece of technology that also happens to be a state sponsored man-in-the-middle platform.
by hipadev23 2y ago
because they’re an amazing piece of technology that also happens to be a state sponsored man-in-the-middle platform.
- nicholasjarnold 2y agoI was assuming that it's a loss-leader sort of business strategy at play before reading your comment. Do you care to share any insights/references to support this claim?
- hipadev23 2y agoNah that’d be a national security crisis. But the presence of https://en.wikipedia.org/wiki/PRISM https://en.wikipedia.org/wiki/PRISM well over 10 years ago should be sufficient.
- nicholasjarnold 2y agoGotcha. Yeah, I mean all of these platforms are certainly juicy targets for room 641A [0] shenanigans. I just wondered if there had been some public leaks or something which we might not all be aware of yet. [0] - https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A
- ceejayoz 2y agoPost Snowden, I think the assumption has to be any large US hosting/service provider is compromised in a similar fashion.
- hipadev23 2y agoI'd also point out the following from Cloudflare CEO Matthew Prince's wiki page [1]: > "Prince co-founded Unspam Technologies, which supported the development of Project Honey Pot [2], an open source data collection software created by Prince and Lee Holloway designed to gather information on IP addresses used by email-address harvesting services." > In 2008, the Department of Homeland Security (DHS) contacted Unspam Technologies, asking, "Do you have any idea how valuable the data you have is?" The DHS' email served as the impetus for Cloudflare, a technology company Prince co-founded with Holloway and fellow Harvard Business School graduate Michelle Zatlyn the following year > The DHS' email served as the impetus for Cloudflare Emphasis mine. I love Cloudflare, their tech is amazing, but to bury our heads in the sand that it wasn't started from day one to be a government spying program would be extremely naive. [1] https://en.wikipedia.org/wiki/Matthew_Prince https://en.wikipedia.org/wiki/Matthew_Prince [2] https://en.wikipedia.org/wiki/Project_Honey_Pot https://en.wikipedia.org/wiki/Project_Honey_Pot
- wumeow 2y agohttps://blog.cloudflare.com/cloudflare-prism-secure-ciphers/ https://blog.cloudflare.com/cloudflare-prism-secure-ciphers/ > At CloudFlare, we have never been approached to participate in PRISM or any other similar program. > To date, CloudFlare has never received an order from the Foreign Intelligence Surveillance Act (FISA) court.
- fidotron 2y agoOverly specific weaseling. (Not by you, by Cloudflare). The questions are not about if they were approached or participate in any programs, it's what they do and if they provide the data or not.
- wumeow 2y agoAgain, an offhand comment about an email from the DHS is given all the weight in the world while a direct statement from Cloudflare is nitpicked to death.
- fidotron 2y agoThe whole point is it's not a direct statement. It is a lot of words which fails to answer the core question: is cloudflare syphoning data off to any of the Five Eyes (and I almost wrote Five Guys . . ) government intelligence agencies or their allies? For example, in your link: "One of the ways we limit the scope of orders we receive is by limiting the data we store. I have written before about how CloudFlare limits what we log and purge most log data within a few hours. For example, we cannot disclose the visitors to a particular website on CloudFlare because we do not currently store that data." So if they are MITMing everything they totally could just send everything out straight away and not contradict what they're saying at all. Them storing the data or not is completely beside the point.
- ahofmann 2y agoUS based companies (like china and europe based ones) are not allowed to talk about it, when state actors implementing their spying tools. It is just naive to think that cloudflare doesn't give access to state agencies. As others have said, it is more likely that cloudflare as a company is entirely built around the idea to provide a singe point of surveillance to US agencies.
- ForHackernews 2y agoOne half of the NSA's mission is defensive, dedicated to improving the security of US systems and infrastructure: https://www.nsa.gov/Cybersecurity/ https://www.nsa.gov/Cybersecurity/
- nosioptar 2y agoSELinux is a great example of that end. Of course, I know an embarrassing number of people that won't touch it because they're convinced it's an NSA backdoor into your system.
- BoingBoomTschak 2y agoNobody remembers the "SSL added and removed here :)"? https://www.agwa.name/blog/post/cloudflare_ssl_added_and_removed_here/media/slide.jpg https://www.agwa.name/blog/post/cloudflare_ssl_added_and_rem...
- sophacles 2y agoHow else would a cdn work? Or an l7 ddos protection?
- edelbitter 2y ago"Our Free plan gives Cloudflare access to unique threat intelligence" https://blog.cloudflare.com/cloudflares-commitment-to-free/ https://blog.cloudflare.com/cloudflares-commitment-to-free/
- fiatjaf 2y agoHonestly this is the most likely hypothesis, but would be nice to have some more evidence.
- sophacles 2y agoIf a cdn didn't intercept requests, how else could it work? Literally every cdn is an mitm.
- ycombinatrix 2y agoI'm sure you've heard this before but Cloudflare isn't really a CDN. CDNs don't have to intercept requests to be useful. I think what you describe is closer to "TLS terminating reverse proxy", which does need to intercept every request.
- jjordan 2y agoWhat are some alternatives? Preferably the more open source the better.
- Strongbad536 2y agoIdk if they're open source, but netlify was the company that I thought sort of made this feature free and easy to use. Github pages is also a free alternative.
- mhitza 2y agoSomeone was (incidentally?) ddos'ed on Netlify last year and was served a 104k bill. The fees were waved in the end, but the caveat remains on all these free services that you pay by bandwidth. https://news.ycombinator.com/item?id=39520776 https://news.ycombinator.com/item?id=39520776
- wahnfrieden 2y agoThat's why I like Bunny, the only such service I could find with prepaid pricing. I would rather have service shut off than to have to pay $104k for a day or two of service.
- Marsymars 2y agoIt's not the same type of platform as Bunny, but NearlyFreeSpeech.NET has done cheap, prepaid hosting for 20+ years.
- nosioptar 2y agoI've used them for small stuff for years. I've never had any issues with them.
- ycombinatrix 2y agoWow, thanks for sharing. Their policies look great. I am going to try them out.
- MarkuC 2y agoPRISM revealed secrets. It also revealed that some companies fought back as much as possible. It's also possible to design core tech so that even when forced to participate, you reveal as little or no information. CloudFlare, PRISM, and Securing SSL Ciphers, 2013-06-12 Matthew Prince https://blog.cloudflare.com/cloudflare-prism-secure-ciphers/ https://blog.cloudflare.com/cloudflare-prism-secure-ciphers/
- deleted 2y ago[deleted]
- gosub100 2y agoSo the deep state is smart enough to take over the corporation and inject all this secret squirrel tech, but didn't think to cook the books to make it look like a marginally-profitable (but boring) business? It reminds me of the counterargument to UFOs where they say "so the UFO flew here from 100 light-years away, through extreme cold, deep space, intense radiation, dodged space rocks, but as soon as it came into a lukewarm atmosphere with a modest gravity and tame weather, it crashed into a field in New Mexico?"
- zimpenfish 2y agoTo be fair, you could see how a vehicle designed rigidly for extreme cold, extreme vacuum, zero gravity, etc. might fail catastrophically when introduced to modest temperatures, a modest atmosphere, and a modest gravity.[1] It wouldn't say much for the foresight of the alien designers, mind. [1] "100 KILOpascals? KILO? I thought you said milli, you blithering nixflorp!"
- throwaway92853 2y ago> [1] "100 KILOpascals? KILO? I thought you said milli, you blithering nixflorp!" The numbers were given in Universal Standard Units, but the manufacturer assumed Galactic Imperial Units
- hipadev23 2y agoWhat? What does business profitability or viability have to do with anything? Cloudflare can serve both customers at the same time. They still make amazing products, have incredibly talented engineers, and provide extremely valuable commercial services. PRISM worked with numerous participants from well-oiled tech startups to aging why-wont-you-just-die companies.
- edm0nd 2y agoThey have the nickname "Crimeflare" for a reason and there is a reason so many threat actors, phishers, and malware people use CF on their landing pages and c2s. When you file an abuse ticket with CF, CF takes the route of "oh we are only routing the data and content, not hosting it" and will refuse to terminate the CF accounts of someone being malicious. Threat actors know this which is why so many use em.
- gruez 2y ago>When you file an abuse ticket with CF, CF takes the route of "oh we are only routing the data and content, not hosting it" and will refuse to terminate the CF accounts of someone being malicious. Threat actors know this which is why so many use em. Their abuse page says they forward abuse tickets to the origin hosting provider. The origin hosting provider could ignore your tickets, but I don't see how that's any different than if they didn't use cloudflare to begin with.
- jazzyjackson 2y agoOk but why can’t they take responsibility for the abuse and terminate the accounts themselves, forcing the malicious actors back to being in a position of not being protected by cloudflare?
- michaelt 2y agoBefore CF, there were no DDOS for hire services, because they all DDOSed each other offline. Keeping them online generates more DDOSes, driving demand for CF’s DDOS protection product. Protecting such sites is a sound business strategy.
- mattbee 2y agoMy favourite CF conspiracy theory is that by terminating booters' SSL they know who will be DDoS'd, and when.
- celsoazevedo 2y ago