Ask HN: Why is there not more concern about the physical security of Cloudflare?
11–20 of 58 posts
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#12never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#13What's the threat model that ram interception is an issue? I think the upsell is entirely reasonable, you get charged more for weird compliance demands.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#14> infrastructure, which operates out of questionable ISP and IXP colocation facilities in various jurisdictions with dubious standards
What are these questionable facilities? When CloudFlare has installed those servers and software, and they have also made software that manages those servers, what is the problem?
CloudFlare has written some articles about some of those very many security protections they have. But that is a very lot of technical detail to explain, so if that is so important, their Enterprise/FedRAMP offerings fund CloudFlare to make possible to explain that amount of detail. But question is, do you really need that amount of detail? How much you have expertise to build same amount of security protections? Isn't it better to use CloudFlare Workers security features to concentrate on building your app? Alternative is to get your own bare metal servers, and manage them yourself.
With CloudFlare Workers, they have security features to keep code and data of each customer separate from each other.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#15never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?
When I worked at AWS they were insanely hardcore about mandating physical access controls, that is all I’ll say, even to the point of ridiculousness. For all the things AWS does poorly security is not one of them. If I were to guess CF is locating their PoPs at cheap peering points and the reason they are evading the question is because other customers in the facility have physical access to their equipment, which is…
Even your cheapest of colo's offer locked cage areas. For someone on Cloudflare's scale, the cost is trivial.
I've been inside some really "low rent" colo's and even they would provide an escort to unlock your cabinet.
Obviously standards/expectations will vary from DC to DC. I'd wager the situation might be different in some of the smaller countries CF operates in around the world though.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#16Some of my own thoughts about this. I don't know, I don't work at CloudFlare. Anyway: > infrastructure, which operates out of questionable ISP and IXP colocation facilities in various jurisdictions with dubious standards What are these questionable facilities? When CloudFlare has installed those servers and software, and they have also made software that manages those servers, what is the problem? CloudFlare has writ…
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#17What's the threat model that ram interception is an issue? I think the upsell is entirely reasonable, you get charged more for weird compliance demands.
What's a threat model where RAM intercept wouldn't be an issue?
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#18What's the threat model that ram interception is an issue? I think the upsell is entirely reasonable, you get charged more for weird compliance demands.
What's a threat model where RAM intercept wouldn't be an issue?
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#19ultimately you trust the company and the jurisdiction in which they operate...if they give you the wrong answers then you should adjust your level of trust accordingly...thankfully there are other platforms and this is one concern that can certainly be better marketed
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#20Earlier quoted context omitted.
What's a threat model where RAM intercept wouldn't be an issue?
Isn't it difficult to actually analyze the RAM content for any sensitive data? There is so much noise in it