11 ms·
The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse
by pocksuppet 25d ago
The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
- CommanderData 25d agoIs there any evidence of this
- bcye 25d agoWell it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-nsa-taps-google-yahoo-data-center-links/ https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
- CommanderData 25d agoThe reputational damage for CF would be intense. Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
- samlinnfer 25d agoThey already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.
- stef25 25d agoMaybe that's why the keep hosting extremist content.
- done_lurking 25d agoI thought Cloudflare generally refuses to serve those kinds of sites. What content is Cloudflare serving that is extremist?
- pocksuppet 25d agoMany torrent sites, that's a kind of extremism.
- 1vuio0pswjnm7 24d agoI have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries I don't think it's convincing If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc. The fact is businesses do "tolerate it" For example, https://en.wikipedia.org/wiki/Cloudbleed https://en.wikipedia.org/wiki/Cloudbleed The MITM design of CF is what it is It creates risks, but these risks are tolerated
- 1vuio0pswjnm7 25d agoIf the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost The damage of being spied upon, if there is any, is already done 1. It's not clear why commenters are only concerned about intelligence agencies
- esperent 25d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)? If so, what's your source for that claim?
- icantevenhold 25d agoHeck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level
- strictnein 25d ago> "it’s no big secret that the NSA is listening in on the node/isp level" The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
- milkshakes 25d agosee https://en.wikipedia.org/wiki/XKeyscore https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago
- strictnein 25d agoYes, I'm well aware of XKeyscore. If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed? Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it. Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
- thorbutt 25d agoThat doesn't seem unique to Cloudflare though
- cassianoleal 25d agoNo, but nothing comes close to their breadth and scale.
- youngtaff 25d agoAmazon and Akamai is their scale, maybe Fastly too
- pocksuppet 25d agoThey are serving big commercial enterprises, ones the government already has direct access to. Cloudflare is serving the long tail.
- youngtaff 23d agoLast I heard (was a few years back) Cloudflare had more enterprise customers than Fastly Should be relatively easy to work out who uses what CDN I get your point about the long tail but what’s the value in a government MITM those?
- kakacik 25d agoIf you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one. Or clouds in general, its all wishful thinking and pinky promises.
- spacebanana7 25d agoWhat about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence
- tg180 25d agoPick your poison
- WarmWash 25d agoOne of them is just another arm of the government so all data is defacto government data, and the other releases transparency reports[1] [1]https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_CY2025.pdf https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_C...
- mitxela 25d agoYou have to be a registered Chinese business entity with a CCP director on your board to legally use that
- lukan 25d ago"We've known it has an always-on microphone and speech-to-text for over a decade" Literally? What is the reference here?
- a2ff6eeb0 25d agohttps://allaboutcookies.org/lg-smart-tvs-snooping https://allaboutcookies.org/lg-smart-tvs-snooping
- lukan 25d agoYeah, about those I know, but what about cloudflare?
- a2ff6eeb0 25d agoThey hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache and forward appropriately.
- lxgr 25d agoAlso to do DDoS mitigation. Being able to see the HTTP request, at least headers and path, greatly helps with distinguishing attackers from legitimate traffic. It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response. Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
- pocksuppet 23d agoAnd the best way to get people to let you do bad things, is to offer them something good, that uses the same mechanism. If I want to MITM the whole internet, what better way than offering free caching and bot blocking? I even get to charge the bots extra to bypass the block, and then charge the customers extra to block the bots that are paying extra to not be blocked!
- aranelsurion 25d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
- mopsi 25d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. That depends heavily on the kind of site you're hosting there. I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
- done_lurking 25d agoDo you really need Cloudflare for something like this?
- mopsi 25d agoIt's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site is handled by Cloudflare. And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
- mitxela 25d agoHe doesn't, but someone told him it was good so he uses it. This is Cloudflare's main audience, just like McAfee's.
- ExoticPearTree 25d ago> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest. Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes. I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
- deleted 25d ago[deleted]
- petcat 25d agoThe NSA collects and archives all internet traffic it can access for future analysis. It's the purpose of the Utah Data center. https://en.wikipedia.org/wiki/Utah_Data_Center https://en.wikipedia.org/wiki/Utah_Data_Center
- p-e-w 25d agoThere’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic. Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that. BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
- jgtrosh 25d agohttps://en.wikipedia.org/wiki/Fairview_%28surveillance_program%29 https://en.wikipedia.org/wiki/Fairview_%28surveillance_progr... https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A Public information shows that the NSA has been active intercepting as much data as possible. It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
- Betelbuddy 25d agoOr they will dump your secrets into all Internet caches... "Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752
- strictnein 25d agoThe NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare. This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta. https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking-everything-how-has-nobody-seen-them-coming-3.html https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...
- celsoazevedo 25d agoThere's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting for the NSA there.
- strictnein 25d agoOf course, but the comment I was replying to stated: "the NSA learns everything there is to know about you and your customers" Which implies that they are looking at it all and records it. The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.
- pocksuppet 25d agoThey are actively scanning all of it, looking for interesting stuff.
- strictnein 23d agoHow do you do DPI on hundreds of PBs a day? Explain the process that would allow you to "look for interesting stuff".
- pocksuppet 19d ago
- milkshakes 25d agoif your threat model includes the NSA i don't think your choice of CDN is going to make a difference
- seki285 25d ago>talks about how bad Cloudflare is with imaginary threats >doesn't offer an alternative and leaves Every. Single. Time.
- Perepiska 24d agoAlso CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog. Also CF raise checks on pages that I opened few hours ago and reload.