Please Cloudflare, I'm a paying customer and have some IPv6 only users that are very frustrated every time they see a Cloudflare challenge page. Your provider, HCaptcha still do not support IPv6. I have to use workarounds like an alternative domain without CF and this is very frustrating.
HCaptcha is the absolute worst, their captchas are consistently harder, the datasets are impossible to decipher and the failure rate is much higher, even if I'm sure that I chose the right options. My parents had no chance last time they ran into one. CF should have just rolled their own captcha service instead of buying into someone else's public ML training program again.
A public letter to CloudFlare to fix their snoopy vendor
91–100 of 117 posts
Re: A public letter to CloudFlare to fix their snoopy vendor
#92Glad to see this getting attention. Flexible SSL is an awful option that has no place in the modern encrypted web. Out of the four SSL options Cloudflare gives users, only one is actually secure. It's a huge foot-gun.
On the contrary, the idea that a mom-and-pop shop running an HTTP website on some ancient shared hosting can easily just drop in Cloudflare is a Good Thing. Sure, you're not removing the attack surface, a state actor could intercept the server-to-server connections... but at least the hacked router in your customers' coffee shop is removed from the threat model. You make it any tougher, and that HTTP website is just…
This is why I think flexible SSL is worse than no SSL. Cloudflare's own docs used to say Flexible SSL "should only be used as a last resort if you are not able to setup SSL on your own web server, but it is less secure than any other option (even “Off”)" (this has since been removed).
Re: A public letter to CloudFlare to fix their snoopy vendor
#93Earlier quoted context omitted.
This is the “oil will never run out” argument. Technically true, but irrelevant.
I chose my analogy carefully. Oil is consumed but land and IP addresses are not.
Re: A public letter to CloudFlare to fix their snoopy vendor
#94Earlier quoted context omitted.
On the contrary, the idea that a mom-and-pop shop running an HTTP website on some ancient shared hosting can easily just drop in Cloudflare is a Good Thing. Sure, you're not removing the attack surface, a state actor could intercept the server-to-server connections... but at least the hacked router in your customers' coffee shop is removed from the threat model. You make it any tougher, and that HTTP website is just…
The downside of such a setup is that as a user, I now have no idea if the site is actually secure. If the mom-and-pop shop is taking credit card orders and has a secure Cloudflare cert, how do I know they aren't then transmitting my credit card number and other personal data unencrypted the rest of the way? If the website was HTTP I would know as a user not to enter sensitive info. This is why I think flexible SSL is…
You never do. SSL is not sufficient for security. It protects against a single attack vector, that's if it's set up correctly. For all you know, the set up of the server your visiting might have be old enough to have a driver's license, with public SSH and the root password "12345".
Re: A public letter to CloudFlare to fix their snoopy vendor
#95Re: A public letter to CloudFlare to fix their snoopy vendor
#96Cloudflare powered censorship in Pakistan works in a similar fashion. ISPs block websites, but because Cloudflare's data center forwards using local ISPs, you get a nice secure blocked page.
Posted this[0] months ago, even sent emails to Cloudflare NOC multiple times and nobody did even care.
[0] https://community.cloudflare.com/t/censored-pop-orpheus-not-...
Re: A public letter to CloudFlare to fix their snoopy vendor
#97Re: A public letter to CloudFlare to fix their snoopy vendor
#98Earlier quoted context omitted.
So really website owners are just misusing Cloudflare? How is this Cloudflare's fault?
In this case, it is not a random party in the CloudFlare--GitHub connection (say a network operator in UK). The snooping intermediary (Airtel) in this scenario is one that has a commercial relationship with CloudFlare and powers CloudFlare's network. CloudFlare has been aware of this issue for years, but it hasn't done anything to get its vendor to fix their network.
https://en.wikipedia.org/wiki/Internet_censorship_in_India
I don't see how Cloudflare or any other provider can make Airtel "fix" the snooping when Airtel is forced by law to block those sites.
This seems to be a policy/government problem, not a Cloudflare or Airtel problem.
Re: A public letter to CloudFlare to fix their snoopy vendor
#99Earlier quoted context omitted.
I chose my analogy carefully. Oil is consumed but land and IP addresses are not.
You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.