2 ms·
I can't shake the feeling that since its dealing with a huge amount of network traffic and it also strips SSL from every connection before passing it onto origi
by amiga-workbench 21d ago
I can't shake the feeling that since its dealing with a huge amount of network traffic and it also strips SSL from every connection before passing it onto origins, they are a very juicy target for a certain three letter agency to place a tap.
The bit I'm less bothered about is the centralising effect it has on the internet.
- juliend2 21d ago> strips SSL from every connection before passing it onto origins What do you mean? You definitely can serve with TLS end-to-end with CF, it's called Full (strict) mode, or something like that.
- thesh4d0w 21d agoThey're still decrypting on their nodes, and then re-encrypting before sending to the origin. There's no getting around the fact they can see the traffic as plain text.
- notanazzi 21d agoAnd they leaked said decrypted traffic at one point...
- skinfaxi 21d agoAnd they issue certs in your name, right?
- wmf 21d agoI don't think anybody uses that mode.
- judge2020 21d agoFull Strict just means that CF verifies your origin cert against actual CAs (or the private CA they issue you a cert for). "Full" means they don't verify the certificate authority of your origin, which technically is _a lot worse_ because that means you could be getting silently MITMd by some middlebox, since Cloudflare will accept whatever self-signed certificate your origin presents. For almost all of Cloudflare's features. CDN, WAF, and all the compute features require seeing, storing, and caching content in plaintext. CF doesn't have much of a value proposition if all they're doing is handling Layer 3/4 DDOS prevention (most DDOS hits even back in 2015 were done on the protocol layer, or at least most DDOSes that actually showed up or impacted the underlying service).
- tomrod 21d agoNah, they only recently got FedRAMP high. The real traffic still can't use it.