6 ms·
CloudFlare enabling free SSL by mid-October
- donavanm 12y agoAre there more actual implementation details somewhere? Sounds like selecting the ssl context based on the clients SNI request. This (obviously) would predicate client SNI support, as opposed to anycast IPs or similar.
- moonboots 12y agoCloudFlare's CEO says that free SSL will use SNI with ipv4 [1] and possibly non-SNI with ipv6 [2]. A CloudFlare engineer has discussed splitting the SSL handshake between servers so their many edge nodes don't need to keep customer secret keys in memory [3]. However, this sounds slightly different than the lazy loading behavior in the blog post. [1] https://news.ycombinator.com/item?id=7910849 https://news.ycombinator.com/item?id=7910849 [2] https://twitter.com/eastdakota/status/478369486643658754 https://twitter.com/eastdakota/status/478369486643658754 [3] http://www.slideshare.net/cloudflare/running-secure-server-sw-on-insecure-hw-without-parachute http://www.slideshare.net/cloudflare/running-secure-server-s...
- asdfaoeu 12y agoNon-SNI over ipv6 seems pretty pointless since anything supporting ipv6 is going to have sni anyway.
- otterley 12y agoNot true; Windows XP supports IPv6 but not SNI.
- p1mrx 12y agoWhile that's technically true, XP doesn't enable IPv6 by default, so virtually no one uses it.
- donavanm 12y agoNot sure why otterley was down voted. XP is going to exist for a while. Old android/mobile clients are another case. Mobile operators are moving towards transparent "4 in 6" NAT/encap on their edges. The server would see a layer 3 IPv6 client, while the actual layer 7 client is an old Android/java stack.
- indutny 12y agoI believe you could use node.js or https://github.com/indutny/bud https://github.com/indutny/bud for asynchronously selecting SNI context per request. This is very fast and flexible.
- tuananh 12y agoCloudFlare is the coolest free CDN out there.
- user3 12y agoMost of the websites wont encrypt the link from Cloudflare to the server, ultimately defeating the purpose of SSL aside from a better search ranking.
- guyht 12y agoCould you elaborate on this. My impression was that connections between data centres (e.g. in the case of using an EC2 instance with Cloudflare) were already very secure and therefore do not require SSL.
- eli 12y agoDepends what you're trying to protect against. Those links are notably very insecure against the NSA.
- agwa 12y agoRight. If there were a diagram of this architecture, the NSA would scribble "SSL added and removed here" with a smiley face[1]. It's arguably even worse, since the traffic between CloudFlare and the origin server would be traveling in the clear on the public Internet, as opposed to in the clear within Google's private network. [1] http://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html http://www.washingtonpost.com/world/national-security/nsa-in...
- nly 12y agoIt's reasonable to suppose that the NSA have a whole bunch of private signing keys for a whole bunch of CAs, and will just MITM anyone they please regardless of our puny efforts.
- eli 12y agoI'm not sure that's a safe assumption and, regardless, an active MITM attack is a much bigger deal than passively collecting traffic as it flows past you in the clear.
- curiousjorge 12y agowhat I just paid 20/month for the SSL.... Update: I have another concern I just found out. For example, I do a lot of web scraping through my domain and I see that I was automatically opted in to use https://www.cloudflare.com/apps/scrapeshield https://www.cloudflare.com/apps/scrapeshield, something that is supposed to block scraping. There's a huge conflict of interest if it turns out that the cloudflare network actively aims to help block scraping. I know you guys said you will be on the neutral side but if the cloudflare is helping Scrapeshield become more intelligent about scraping by monitoring my scraping actions, I really don't know if it's wise to stay with cloudflare, as much as I love it.
- eastdakota 12y agoWe'll be adding some cool new features to our paid plans at the same time, so I hope you'll decide to continue paying us the $20.
- thoughtpolice 12y agoGood to hear - I just signed up and put in the $20 myself (not a very large barrier), and I'm glad features like custom certificates (& other things) will be available as mentioned elsewhere in this thread. CloudFlare seems like a great product so far.
- eastdakota 12y agoScrapeshield is a CloudFlare feature. If you don't want it, turn it off. Here's the announcement from when we launched the feature: http://blog.cloudflare.com/introducing-scrapeshield-discover-defend-dete http://blog.cloudflare.com/introducing-scrapeshield-discover...
- icebraining 12y agoI don't get it. A domain is just an address, how can you scrape through your domain? Do you mean server? But scrapping is an outbound connection, how could they monitor it?
- willu 12y agoAre EV certs going to remain Business/Enterprise-only?
- eastdakota 12y agoNo.
- deleted 12y ago[deleted]
- daveslash 12y agoI would have guessed EV certs to remain business only. Well, perhaps not business only, but still requiring additional validation. How do you believe EV will be handled? Thanks! EDIT: I didn't realize you represented cloud-flare. I'm genuinely curious how EV certs will work. Thanks!
- eastdakota 12y agoYou'll have to supply your own EV cert, but you'll be able to use custom certs (EV or otherwise) at the Pro ($20/mo) level.
- daveslash 12y agoThank you!
- nilved 12y agoPlease note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their free SSL certificate from gandi.net or StartSSL, who do not spy on or block your users.
- namidark 12y agoGandi is free for a year and then expensive after - Namecheap may not be free but renewals and initial costs are much lower. StartSSL is free but revoke-ing costs money.
- tuneladora 12y agoNamecheap vs Gandi is like 6.5 vs 12 EUR. Yes is almost double, but I don't know if I would consider them as cheap and "expensive".
- Ecio78 12y agojust checked now, Gandi is 40€/yr, not that expensive compared to big names like Verisign & co. I have used in the past RapidSSL, but it is same price, 50$/yr. I've just checked Namecheap and it's reselling other SSL like Comodo or Geotrust, but it looks less expensive, so yes, probably it's the best price.
- general_failure 12y agoDo not announce things until done. This is just shameless marketing stunt.
- tanglesome 12y agoWhy are people up-voting an ad?
- junto 12y agoI presume that customer private keys need to be stored on Cloudflare servers to implement this. Has that just made Cloudflare servers a legitimate prime NSA target? I.e. all your keys belong to us
- rdl 12y agoWe have a product, "keyless ssl", which is used by some customers to retain on premise custody of their asymmetric key material, actually.
- alanbyrne 12y agoDoes it bother anyone else that when you try to visit the Google post explaining that they are using HTTPs as a ranking signal via https it redirects to http? http://googleonlinesecurity.blogspot.co.uk/2014/08/https-as-ranking-signal_6.html http://googleonlinesecurity.blogspot.co.uk/2014/08/https-as-...
- taksintik 12y agoCloudflare throwing it down with authority...well played. In the end the consumer really doesn't give a hoot. They want simple.