this post was submitted on 13 Aug 2023
543 points (95.8% liked)

Memes

45637 readers
1827 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS
543
submitted 1 year ago* (last edited 1 year ago) by w00t@lemy.lol to c/memes@lemmy.ml
 
you are viewing a single comment's thread
view the rest of the comments
[–] redditcandoone@sopuli.xyz 84 points 1 year ago (3 children)
[–] odium@programming.dev 92 points 1 year ago

Cloudflare has human checks before you can access some sites. Some apps and screenreaders no longer work with those sites.

[–] Saik0Shinigami@lemmy.saik0.com 69 points 1 year ago (1 children)

They're all uppity that to use cloudflare proxy they have to terminate the ssl connection there. So technically cloudflare can sniff all the traffic. But that's kind of the point of WAFs and Reverse Proxies.

I would argue that the sheer amount of data throughput that Cloudflare has, you'd have to really be on a list to be monitored... and they certainly cannot just log all data willy nilly.

[–] r00ty@kbin.life 35 points 1 year ago (1 children)

I suppose this one is quite simple. How can they cache, if they don't MitM the connection? I don't think it would be technically possible. If you want the cache/CDN you just need to use a company you trust. If you don't trust them then you don't get the cache/CDN.

[–] Saik0Shinigami@lemmy.saik0.com 22 points 1 year ago

Correct. But people are viewing the DDOS protection, Cache, WAF, etc... functions as evidence that Cloudflare is obviously malicious and storing 100% of all data traversing them.

I've seen no evidence of that yet, and will certainly discontinue use of them if they show such tendencies. Until then, I will absolutely leverage their platform for my use as a paying customer.

I do understand the fear with their free platform though... They've gotta make money somehow, and I feel there's probably a fear that is data collection.

[–] w00t@lemy.lol 19 points 1 year ago (4 children)

No high-profile cases yet, but some people are already concerned: https://crimeflare.eu.org/

[–] xusontha@ls.buckodr.ink 31 points 1 year ago* (last edited 1 year ago)

Doesn't load, maybe they need Cloudflare lol (i'm joking don't send me to internet hell) Wayback doesn't seem to work with it either

[–] qaz@lemmy.world 9 points 1 year ago* (last edited 1 year ago)

I might be missing something but the document seems to be comparing Cloudflare to the great firewall of China and calling them criminal because of things they could potentially do?

[–] 01189998819991197253@infosec.pub 7 points 1 year ago (1 children)
[–] Double_A@discuss.tchncs.de 3 points 1 year ago* (last edited 1 year ago)

It would help if that site wouldn't look like it was written by some crazy person trying to make a shitpost...

[–] Brimos@lemmy.world 6 points 1 year ago

Site appears to be down. What is this for?