8 ms·
I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.
by adamgamble 3y ago
I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.
- adamgamble 3y agoWhy wouldn’t they fund the worlds largest MITM attack?
- charcircuit 3y agoCloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.
- adamgamble 3y agoWhat am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.
- powersnail 3y agoDoes CloudFlare proxy your website without your permission?
- dns_snek 3y agoYou're being needlessly pedantic. It might not be an attack in the usual sense, but it's a MITM "access point" and agencies like CIA/NSA/FBI would definitely have that kind of access. This access transforms Cloudflare's role into a de facto MITM "attack" on their customers and end users who didn't intend to share unencrypted data with 3-letter agencies.
- powersnail 3y agoI don’t think I’m being pedantic. In practical, the parent comment’s description is not that of MITM attack, but how a proxy works. Proxy is everywhere, useful, and voluntary. I just don’t understand how a voluntary use of proxy can be called MITM attack. I’m not saying I like the fact that CF is part of so much of the Internet, or that CF isn’t on some level a security risk. But that has nothing to do with being an MITM attack.
- cassianoleal 3y agoIt doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.
- powersnail 3y agoIt’s always the website’s choice what infrastructure is used to serve the website, including whether a proxy is used. You don’t have a chance to say no if the website owner wants a proxy in front of their site. The web owner has a say in how they want their server to be connected. In the same way, you can use a proxy to access sites, and the server cannot bypass that, either.
- DropInIn 3y ago[flagged]
- cassianoleal 3y agoI know. I understand the tech and the business decisions behind all of this. I understand the value of a CDN. It's still a MitM. It's a centralised entity that sees a huge share of the global Internet's traffic, unencrypted. I doubt most people are aware of that. Someone in another comment mentioned AWS is one as well, and they're right. AWS, GCP and Azure all have TLS-terminating gateways of some kind. Take Cloudflare, AWS, GCP and Azure, all USA companies bound by the CLOUD act, and nearly all Internet traffic is immediately accessible by US authorities, unencrypted. Makes the whole "think of the children" rhetoric being spun to pass anti-E2EE laws tame in comparison.
- charcircuit 3y agoAnd AWS has control of all of your servers and everything stored on them. If it's part of your systems architecture and how it's intended to work it isn't being attacked. >They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server. That doesn't mean they are an attack. That is just how a CDN works.
- deleted 3y ago[deleted]
- james_in_the_uk 3y agoNot an attack but certainly a person in the middle. IAAL and advise on data protection and privacy. Anecdotally I can tell you that the MitM aspect of Cloudflare and other similar providers is not well understood. My impression is that a lot of people use these services without really understanding the implications. For example, when you look at some of the risks that privacy laws are trying to protect against, especially access to data by foreign actors (including government agencies) without due process, use of these types of services changes the game. Sometimes the benefits might outweigh the risks, but the decision to use these types of services should not be taken trivially. That said, I routinely use Cloudflare for my personal projects.
- Lammy 3y ago> By that same logic AWS would be an even bigger MitM attack. Amazon HQ2, Arlington Virginia: https://en.wikipedia.org/wiki/Amazon_HQ2 https://en.wikipedia.org/wiki/Amazon_HQ2
- hamandcheese 3y agoBy that same logic, it would not be surprising to discover AWS working with the feds either.
- adamgamble 3y agoYou're right. That definitely wouldn't be surprising!
- byndlimitsfy 3y agoThis might be anticipated, it won't be a surprise.
- pieter_mj 3y agoIt's worse. You can't just start Mitm'ing regular encrypted internet traffic without compromised infrastructure. With Cloudflare everything is already in place.
- udev4096 3y agoThat's a lie. Cloudflare decrypts HTTPS connections
- yencabulator 3y agoYou can avoid that with some programming/setup and money: https://developers.cloudflare.com/ssl/keyless-ssl/ https://developers.cloudflare.com/ssl/keyless-ssl/
- eastdakota 3y agoThese threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this silly speculation would end. But guess not. Beyond that, if you think about it, it's a way better business to run Cloudflare and serve the world than serve some US intelligence entity. That's just per se true. So if that's the case why would we ever do anything that would remotely compromise the trust necessary to, you know, be Cloudflare? Lastly, here's a funny story. Early in our history one of our investors suggested that we talk to In-Q-Tel. Here's how naive Michelle and I were: we had no idea it was the CIA's venture capital arm. So we showed up in their office on Sand Hill Road. It was weirdly austere compared with other VCs we'd visited. And lots of security cameras. The partner at some point came out and greeted us. As he was walking us back he looked back right before we crossed the threshold back to the inner offices, "You're both American citizens, right?" "No," Michelle said. "I'm Canadian." "Oh." the VC said. Then you can't come back here.” "I'm not going back there without her," I said. "Ok, well, I guess we'll have to do the meeting in the reception area," decided the In-Q-Tel VC. We had a very cordial meeting and then left. As we were driving away Michelle said, "Those guys were weird." And that was the end of that. Never talked to In-Q-Tel again. But maybe it's the Canadian equivalent of the CIA/FBI/NSA we're beholden to??! ;-)
- TechTechTech 3y agoHi, kind of hijacking this conversation but as Cloudflare is unfortunately routing the majority of websites I visit I have to ask this: Can you guarantee my Firefox browser will keep on working on 'the open internet' now Chrome moves towards "Web Environment Integrity" and Safari towards "Private Access Tokens" and Cloudflare is supporting and implementing such technologies on scale? I intent to not participate in these DRM APIs with my Firefox browser and would like to keep browsing the internet.
- nonameiguess 3y agoI haven't been able to visit a site with Cloudflare's bot protection for over a year because it goes into an infinite loop on Firefox.