3 ms·
Hardly anything malicious ... yet and even that's debatable. Yes, when you proxy anything through Cloudflare (CF) you give up on having your contents encrypted
by eXpl0it3r 2mo ago
Hardly anything malicious ... yet and even that's debatable.
Yes, when you proxy anything through Cloudflare (CF) you give up on having your contents encrypted as CF terminates the TLS endpoints, but going from this to changing the content of the served site and injecting JavaScript is quite a big step and likely not what a lot of people would want nor expect. Your JavaScript-free site becomes a site that ships JavaScript without you knowing or having done anything.
Additionally, this introduces additional tracking of users, which a lot of people don't want.
And finally, there's the slippery slope. Today it's RUM, tomorrow it's ads or something else? Once CF starts modifying the user's content, what's stopping them from doing it more and more?
- deadbabe 2mo agoSlippery slope doesn’t apply here, because at the point the slope becomes too slippery, you can just get off and find a new solution. Maybe you don’t proxy at all. For now, a pure JavaScript free site and a JavaScript-free-except-a-bit-of-analytics does not make meaningful difference to visitors of the site. The benefits of proxying are more important.
- cryptonym 2mo agoCF tested the water with polyfill.io 2 years ago. Everyone liked them modifying user's content. We are now on the "more and more" side.