7 ms·
CloudFlare’s last Warrant Canary was published over a year ago
- benreesman 3y agoMaybe I’m just getting old and distracted, but I feel like CloudFlare went from “whoa some HN pros are doing great CDN work with some serious chops and an underdog work ethic” to “is it possible to never connect to them” like, really fast.
- tmpX7dMeXU 3y agoI think there was 10 or so years in the middle there :)
- probably_a_gpt 3y agoI think we’d all be pleased to build something out of passion and have it survive a decade without corruption, probably harder than it sounds
- tsujamin 3y agoThe glossary entry on warrant canaries is dated December 2020, but there is a more recent canary list in their 2022 transparency report (https://www.cloudflare.com/en-au/transparency/ https://www.cloudflare.com/en-au/transparency/) with the same 6 items in it. Bizarre they appear to have skipped the H2 2022 transparency report unless I’m missing something
- JHorse 3y agoH2 2022 and H1 2023
- deleted 3y ago[deleted]
- tsujamin 3y agoGive H1 2023 has only just wrapped up I optimistically presumed it would be in production now, but I’ve got no idea what the lead time on these reports historically has been
- richij 3y agoalso on that page: "Confirmed: July 31, 2023"
- lallysingh 3y agoSo they got a warrant that they can't talk about. That seems obvious.
- JHorse 3y agoTheir Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enforcement organization a feed of our customers' content transiting our network. 4. Cloudflare has never modified customer content at the request of law enforcement or another third party. 5. Cloudflare has never modified the intended destination of DNS responses at the request of law enforcement or another third party. 6. Cloudflare has never weakened, compromised, or subverted any of its encryption at the request of law enforcement or another third party.
- 13of40 3y agoI wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.
- JHorse 3y agoSuuuuper pedantic. For instance, 2 and 3 narrowly specify just law enforcement agencies, of which the CIA and NSA are not.
- JHorse 3y agoBuuuut, since 703 allows law enforcement agencies to harvest data captured by intelligence agencies any statement that doesn't specifically exclude those intelligence agencies is essentially meaningless.
- 3y ago
- sulam 3y agoWarrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."
- 93po 3y agoIs there a precedent for compelling speech, even with something like an NSL?
- EGreg 3y agohttps://en.m.wikipedia.org/wiki/Compelled_speech#:~:text=Peterson%20argued%20that%20the%20law,criminalize%20using%20non%2Dpreferred%20pronouns https://en.m.wikipedia.org/wiki/Compelled_speech#:~:text=Pet....
- zaksoup 3y agoWhy is the commentary of far-right reactionary, who is not a legal expert, commenting on a canadian law, that has nothing to do with warrants, with a citation pointing out that legal experts disagree with him, at all relevant to this conversation?
- TylerE 3y agoProbably the giant “United States” section with dozens of examples?
- Dylan16807 3y agoBut they linked a specific section, and it wasn't the United States section.
- apostacy 3y agoI do not think that the United States section of that article is valid. It seems to equate speech with communication. It does not feel right to call an IRS tax return "speech".
- causality0 3y agoIs there a point to a company as large as Cloudflare even having a warrant canary? Half the internet goes through their servers. Of course the US government had or has hooks in them for something or other.
- jvanderbot 3y agoTo legitimize the suspicion. That's always been the point.
- nathanaldensr 3y agoAnd, it's not like there are really alternatives. So what if they were served a warrant? What are they, and the people, going to do about it?
- DANmode 3y ago> Is there a point to a company as large as Cloudflare even having a warrant canary? There was, is. There likely won't be, going forward.
- eastdakota 3y agoNo they don't.
- cj 3y agoRemember, Cloudflare CEO/CTO is active on HN. Their lack of reply (if that turns out to be the case) on this post would be telling.
- eastdakota 3y agoHmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.
- eastdakota 3y agoSorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.
- JHorse 3y ago[dead]
- jgrahamc 3y agoMorning.
- eastdakota 3y agoThink you’re supposed to be on vacation.
- rkagerer 3y agoTime to muster, HackerNews community decided to make a PR event this morning. Thanks for the comments and clarifications in this thread.
- EGreg 3y agoWell, it’s been 4 minutes. I’m calling it!
- tedunangst 3y agoWhat action do I need to take in response? Please advise.
- BillyTheMage 3y agoI'm not an expert, but my course of action is to stop using cloudflare. I never used them for whatever that other thing they do is, but I switched my upstream DNS to quad9 (9.9.9.9).
- edandersen 3y agoChrome should starting warning users if Cloudflare is used to protect a website, due to the risk of MITM.
- ocdtrekkie 3y agoThe biggest MITMer should complain about another service being an MITM? How much has Google now routed to go through themselves or be checked by them prior to serving your destination? Bear in mind Google doesn't have a warrant canary because it is served literally hundreds or thousands of warrants per year, to the tune it's just called a transparency report to count them.
- edandersen 3y agoOkay, Firefox should start warning users.
- tick_tock_tick 3y agoHow do you think any CDN works?
- edandersen 3y agoBy MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?
- jlbooker 3y agoI guess you like those cookie warnings that pollute the Internet these days? Because this would be cookie warnings all over again. Any site that's reasonably popular uses a CDN to increase scalability, improve performance, and add reliability. Half the Internet would need a new pop-up warning that a CDN is in use. The last thing we need is yet another pop-up when a page loads....
- 3y ago
- entriesfull 3y agoSo what's stopping these people that claim to be so righteous by using canaries from lying to you? Anyhow the ISPs and internet backbones are all tapped as many whistle-blowers have already revealed.
- JHorse 3y agoNothing is stopping them from lying. Signaling that their infrastructure has been compromised is kind of a weird lie for them to make though...
- eastdakota 3y agoThe SEC could throw me in jail. And, sure, you could believe that the FBI or whoever could tell the SEC what to do. We have European and Asian investors too, so their financial regulators could also sue me personally for lying. Perhaps the FBI/CIA/NSA control them too? Gets tricky to believe: the bigger the conspiracy the faster it falls apart. It's really, really hard to be part of some grand conspiracy as a public company.
- JHorse 3y agoThe concern isn't a grand conspiracy, it's that you've been coerced to comply with the kind of surveillance overreach that US intelligence and enforcement agencies have repeatedly engaged in. Cloudflare isn't the bad guy in this scenario, it's the hostage.
- pleoxy 3y ago> It's really, really hard to be part of some grand conspiracy as a public company. No it's not. Twitter and Facebook have had defacto government censorship collusion, as suspected by the paranoid. For years and years it was dismissed as conspiracy, but clear evidence has now come out that it was happening in these public companies.
- 542354234235 3y ago>clear evidence has now come out Source?
- ck2 3y agoIt's weird to me people think warrants are still used. No warrant is needed by any government agent to read your email that is over six months old and the major providers just give them a backdoor so as not to waste any time/money with requests. Who is going to stop them from doing that with anything else? The supreme court? Good luck with that belief system. You think the NSA ever stopped just because they were discovered? Or did they just switch to "try to stop us".
- djur 3y agoTheir "canaries" don't make any reference to warrants, and two of them explicitly rule out providing a backdoor for governments ("Cloudflare has never installed any law enforcement software or equipment anywhere on our network" and "Cloudflare has never provided any law enforcement organization a feed of our customers' content transiting our network").
- barrysteve 3y agoSo.. what? Endless despair?
- soared 3y agoSource?
- adamgamble 3y agoI love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.
- adamgamble 3y agoWhy wouldn’t they fund the worlds largest MITM attack?
- charcircuit 3y agoCloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.
- adamgamble 3y agoWhat am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.
- powersnail 3y agoDoes CloudFlare proxy your website without your permission?
- dns_snek 3y agoYou're being needlessly pedantic. It might not be an attack in the usual sense, but it's a MITM "access point" and agencies like CIA/NSA/FBI would definitely have that kind of access. This access transforms Cloudflare's role into a de facto MITM "attack" on their customers and end users who didn't intend to share unencrypted data with 3-letter agencies.
- powersnail 3y agoI don’t think I’m being pedantic. In practical, the parent comment’s description is not that of MITM attack, but how a proxy works. Proxy is everywhere, useful, and voluntary. I just don’t understand how a voluntary use of proxy can be called MITM attack. I’m not saying I like the fact that CF is part of so much of the Internet, or that CF isn’t on some level a security risk. But that has nothing to do with being an MITM attack.
- tamimio 3y ago[flagged]
- burnished 3y agoWhat is the language around the non-disclosure order? There seems to be speculation that a warrant canary would be construed the same as a disclosure, but are you required to not inform the concerned party, or required to not disclose law enforcement contacting you at all? From a practical perspective I don't imagine that cloudflare removing a canary could give any one organization a signal - I don't know what the bar for a 'disclosure' is but informally I would not consider it a targeted specific warning. EDIT: the other component I am curious about is duration, there is still utility in the canary even if it comes late, future users will know that there was a compromise and that further ones are likely, right?