Comment by purpleidea
7 hours ago
Yikes! I see this too:
<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>
Yup, I explicitly had all anaytics turned off. But had a few sites using Cloudflare for caching. Now I'm checking and seeing this on all of them. This is gross and unacceptable. "Caching" does not mean "modifying my site".
MITM attack, that's what it is. Why is this not in the news? Ah, no one cares.
I'm not seeing this on my site (if you want to check: https://stackgho.st), are you using their `strict` http settings? I.e. is your server terminating TLS or is theirs?
edit: perhaps it's only for sites added after that policy came into effect