3 ms·
To be fair, Cloudflare is also the reason why most sites even have TLS at all, because it offered free certs (through letsencrypt I think?) in a fairly easy to
by spoiler 10mo ago
To be fair, Cloudflare is also the reason why most sites even have TLS at all, because it offered free certs (through letsencrypt I think?) in a fairly easy to set up way.
Certs used to be expensive, and had way more operational overhead and quirks (even setting up ACME/LE)
- Tostino 10mo agoI'm not going to give them credit for the work that Lets Encrypt did.
- master_crab 10mo agoI agree, Let’s encrypt and ACME played a massive role. But it’s still far easier having Cloudflare handle TLS encryption for you. And i say this as someone who uses ACME in certmanager and certbot at home and still prefers the ease with which Cloudflare generates a cert for my domain and terminates TLS for the public side of my cloudflare tunnel.
- Tostino 10mo agoFor my home stuff I just use nginx-proxy-manager and haven't thought about it since I set it up a couple of years ago. For work, I used to use certbot directly at my old place. Now I am building my new stuff on k8s, and I have the ingress manage my certs for me (likely using certbot or similar behind the scenes). Both have been extremely low setup effort and no ongoing effort. I don't like giving Cloudflare my (or my companies/customers) data in exchange for being able to click a checkbox.
- TiredOfLife 10mo agoLets Encrypt can proxy my old http only website to show as https? Without access to server configuration? How?
- Tostino 10mo agoWith nginx-proxy-manager which uses Let's Encrypt for certs you can... This isn't the gotcha you think it is.
- TiredOfLife 10mo agoI don't have access to the server.
- Tostino 10mo agoIt can be run anywhere. You don't need it on the same server. Cloudflare isn't running on the same server either.
- TiredOfLife 10mo agoCloudflare is a checkbox.
- Tostino 10mo agoAnd you only let them see every bit of traffic to and from your site in exchange. What a deal. You changed the subject btw.
- TiredOfLife 10mo agoI didn't. I said that Cloudflare is the one that allowed my http only site to become https.
- spoiler 10mo agoMy bad! I slightly confused my timeline. CF offered free certs long before LE!
- estimator7292 10mo agoAbsolutely not, no. That is all thanks to Let's Encrypt.
- DoctorOW 10mo agoThis was true before Let's Encrypt existed, they'd buy massive 500 domain wildcard SSL certs that free users would split.
- thayne 10mo agoCloudflare has native integration with Let's encrypt, which makes using TLS with a CDN much easier than if you had to acquire the ACME cert and deploy it to the CDN yourself. Granted, most CDNs these days have some form of free certicate system, but that wasn't always the case.
- koakuma-chan 10mo agoLet's Encrypt is unusable for me because they want you to install that certbot thing. I don't know what that is or what it does. I don't want some magical auto update thing. Is it so hard to just make a generate button that gives you cert.pem and pkey.pem? Cloudflare managed to do it.
- anticrymactic 10mo agoLet's encrypt supports ACME. Here are hundreds of ways to obtain a certificate: https://letsencrypt.org/docs/client-options/#other-client-options https://letsencrypt.org/docs/client-options/#other-client-op...
- spoiler 10mo agoRight, DoctorOW correct me; I have limited memory about the state of affairs from a decade ago. They offered free certs for a long time regardless of LE integration
- udev4096 10mo ago[flagged]
- spoiler 10mo agoAre we witch hunting Cloudflare now? What have they done? I think overall CF seems like a pretty decent company? Lol I'm a bit out of the loop it seems. Also what mis-information (other than the claiming CF integrated with LE, but it turns out CF offered free certs before LE even existed lol) did I spread?
- Bratmon 10mo agoPeople on this website will just type any wild lie. I kinda love it. The sky is purple! Charlie Brown had hoes! Cloudflare invented Let's Encrypt! Just say anything you want! We live in a post-truth world- there's no need for anything you say to correspond to any external reality!
- balamatom 10mo agoCongrats! You get it!
- ranger_danger 10mo ago> this website you must be new to the internet...
- tracker1 10mo agoI'm pretty sure Lincoln said that first...
- spoiler 10mo agoI never said Cloudflare was behind Let's Encrypt… Did I? Probably just a misunderstanding. Someone l pointed out I mixed up my timeline a bit because this was over a decade ago, but it turns out CF offered free certs even earlier than LE :) So, while i got the details wrong, I still stand behind what I say: most sites on the web even have TLS enabled because CF offers it for free. I'm not talking about the reverse proxy aspect, but from the UA's perspective