Comment by pocksuppet
3 hours ago
The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers
You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.
Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.
I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
The NSA collects and archives all internet traffic it can access for future analysis. It's the purpose of the Utah Data center.
https://en.wikipedia.org/wiki/Utah_Data_Center
There’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic.
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
4 replies →
Not all traffic, but any.
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
That doesn't seem unique to Cloudflare though
No, but nothing comes close to their breadth and scale.
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
"We've known it has an always-on microphone and speech-to-text for over a decade"
Literally? What is the reference here?
https://allaboutcookies.org/lg-smart-tvs-snooping
Yeah, about those I know, but what about cloudflare?
2 replies →
If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.
Or clouds in general, its all wishful thinking and pinky promises.
What about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence
Pick your poison
That depends heavily on the kind of site you're hosting there.
I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
Is there any evidence of this
Well it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
The reputational damage for CF would be intense.
Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
2 replies →
Or they will dump your secrets into all Internet caches...
"Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752