5 ms·
The link does not provide any supporting evidence for your claim about them logging passwords. Nor does the Cloudflare blog post that's the source. It seems pre
by jsnell 2y ago
The link does not provide any supporting evidence for your claim about them logging passwords. Nor does the Cloudflare blog post that's the source. It seems pretty good that we aren't discussing something that you've just made up.
- mdhb 2y agoThis is literally how TLS works.
- jsnell 2y agoThe claim you made was "they just admitted to logging the usernames and passwords". The fact is that they did not admit to that. If you think otherwise, please quote the actual admission. I don't know how you think "this is how TLS works" is relevant here. Just e.g. terminating a TLS connection certainly doesn't mean that you're going to be logging all the unencrypted data. And you claim, again, was about logging.
- deleted 2y ago[deleted]
- mdhb 2y agoHow exactly do you suppose they are able to talk in great detail and specificity what passwords people were using in this magical world where they also aren’t inspecting everyone’s passwords as they pass through their servers?
- jsnell 2y agoYou've moved the goalposts from "logging" to "inspecting". But pretty obviously checking for password reuse does not require logging, or otherwise storing, the passwords. Again: your claim was that Cloudflare had admitted to logging the passwords. You've been unable to provide any evidence of such an admission. Why not admit that it was an incorrect claim?
- mdhb 2y agoThat is truly one of the dumbest things I’ve heard in such a long time. Thanks for the laugh genuinely.
- jsnell 2y agoI guess I don't see which part you're finding objectionable. What you wrote initially was verifiably incorrect. It's not clear whether you made an honest mistake and just can't admit it now for some reason; whether you intentionally lied; or whether you genuinely can't see that what you wrote is not supported even by your own sources. It might be possible to figure out which, if you actually engaged in the discussion and explained what you mean. Like, anybody can see what your initial claim was. Everyone can also verify that you've still not provided any evidence for it. Other than the "this is literally how TLS works" non sequitur. Could you possibly be thinking that "logging" and "inspecting" are the same thing? Seems hard to believe. The two are obviously totally different things. In particular, the security and privacy properties of the two would be totally different. If you knew from the start that that the passwords were not being stored anywhere, saying it was "logging" is just acting in monumentally bad faith.