Earlier quoted context omitted.
Well HIPAA wouldnt allow your https traffic flow unencrypted through a shared proxy right? This means cloudflare couldnt offer that feature, so they probably didn't? Just think about the HIPAA document describing a single endpoint of dozens of sensitive datastreams, decrypting and then encrypting them all on the same machine, a machine that does some random HTML parsing for snippet caching on the side. I don't see th…
From their blog post: https://blog.cloudflare.com/incident-report-on-memory-leak-c... "Because Cloudflare operates a large, shared infrastructure an HTTP request to a Cloudflare web site that was vulnerable to this problem could reveal information about an unrelated other Cloudflare site." You don't need to be using this feature, or to be sending malformed HTML yourself - just to be in memory for this Cloudflare proc…
So we should see very quickly that Cloudflare knows what to do when stuff goes wrong.