3 ms·
While this is a cool feature, I wouldn't say the improvement is more than marginal: all potentially sensitive customer data is still available to Cloudflare in
by vader1 12y ago
While this is a cool feature, I wouldn't say the improvement is more than marginal: all potentially sensitive customer data is still available to Cloudflare in plain text. And after all, with a Business plan you can already use your own ("custom") SSL certificate which you can then revoke at any time.
Why not offer a "pass through" mode where the proxying is done on the network layer rather than the application layer? Of course in such a modus all CDN-like functionality could no longer be offered, but it could still do a fair amount of DDOS protection, no?
- cbhl 12y agoWell, for the use case given, with "Keyless SSL", if Cloudflare is compromised, then the bank doesn't need to report the incident to the Federal Reserve. But yes, users' plaintexts would still be compromised. "Security theatre" indeed.
- willvarfar 12y agoIt seems harsh to call it theatre, and I expect all cloud services will adopt it. It means people can use a cloud service without giving them private keys. This seems much better than giving them keys. I too was hoping there would be some clever math to make it so some part of the conversation between client and back end was an encrypted tunnel that cloudfare can route but not read. This doesn't seem to be the case. But all the same, however small a step, its not theatre.
- dfc 12y agoI am not sure that a Cloudflare compromise would not rise to the level of a reportable event. In my experience/opinion "users' plaintext compromise" is certainly an instance of unauthorized access to customer information. I understand the whole framework here is risk-based so it is a matter of interpretation; but I do not want to be the person who has to explain to the nice folks from the OCC the intricacies of Cloudflare's implementation and why I deemed the compromise low risk. > An institution should notify its primary Federal regulator as soon > as it becomes aware of the unauthorized access to or misuse of > sensitive customer information or customer information systems. FDIC: Supervisory Insights https://www.fdic.gov/regulations/examinations/supervisory/insights/siwin06/article01_incident.html https://www.fdic.gov/regulations/examinations/supervisory/in...