← Back to context

Comment by OutOfHere

10 hours ago

Cloudflare is known to extort customers.

https://robindev.substack.com/p/cloudflare-took-down-our-web...

Reddit comments report more such incidents, with Cloudflare demanding an upgrade to Enterprise. This has also come up for other sites, such as gambling sites.

Also, Cloudflare implicitly screws over everyone by leaking data to the NSA.

> Also, Cloudflare implicitly screws over everyone by leaking data to the NSA

I have always operated under the assumption that every cloud provider and telco does this, so this claim has always seemed very silly to me.

  • Huh. When you don't use a man-in-the-middle service, you don't have this problem. When you host on a cloud vendor, you don't have this problem because you control the HTTPS certificate and don't leak it to the MITM. The assumption as such seems silly to me.

    • Your DNS lookups and IPs in use provide a lot of info. It's not always the data inside an encryption layer that is the most important.

      That said, these are US companies subject to FISA court orders and NSLs or National Security Letters. If they want your data, they can just pull it from memory in real time or pull it directly from the hypervisor and dump it wherever they're instructed to. Any idea that your data is protected because you're not even using a provider WAF or doing TLS termination for load balancing is a fantasy.

      2 replies →