Live data from Hacker News

A public letter to CloudFlare to fix their snoopy vendor

github.com

91–100 of 117 posts

Re: A public letter to CloudFlare to fix their snoopy vendor

#91
post #88
post #7

Please Cloudflare, I'm a paying customer and have some IPv6 only users that are very frustrated every time they see a Cloudflare challenge page. Your provider, HCaptcha still do not support IPv6. I have to use workarounds like an alternative domain without CF and this is very frustrating.

HCaptcha is the absolute worst, their captchas are consistently harder, the datasets are impossible to decipher and the failure rate is much higher, even if I'm sure that I chose the right options. My parents had no chance last time they ran into one. CF should have just rolled their own captcha service instead of buying into someone else's public ML training program again.

reCaptcha is definitely worse, but it goes easy on people logged into a google account.

Re: A public letter to CloudFlare to fix their snoopy vendor

#92
post #81
post #11

Glad to see this getting attention. Flexible SSL is an awful option that has no place in the modern encrypted web. Out of the four SSL options Cloudflare gives users, only one is actually secure. It's a huge foot-gun.

On the contrary, the idea that a mom-and-pop shop running an HTTP website on some ancient shared hosting can easily just drop in Cloudflare is a Good Thing. Sure, you're not removing the attack surface, a state actor could intercept the server-to-server connections... but at least the hacked router in your customers' coffee shop is removed from the threat model. You make it any tougher, and that HTTP website is just…

The downside of such a setup is that as a user, I now have no idea if the site is actually secure. If the mom-and-pop shop is taking credit card orders and has a secure Cloudflare cert, how do I know they aren't then transmitting my credit card number and other personal data unencrypted the rest of the way? If the website was HTTP I would know as a user not to enter sensitive info.

This is why I think flexible SSL is worse than no SSL. Cloudflare's own docs used to say Flexible SSL "should only be used as a last resort if you are not able to setup SSL on your own web server, but it is less secure than any other option (even “Off”)" (this has since been removed).

Re: A public letter to CloudFlare to fix their snoopy vendor

#93
post #79
post #78

Earlier quoted context omitted.

This is the “oil will never run out” argument. Technically true, but irrelevant.

I chose my analogy carefully. Oil is consumed but land and IP addresses are not.

You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.

Re: A public letter to CloudFlare to fix their snoopy vendor

#94
post #92
post #81

Earlier quoted context omitted.

On the contrary, the idea that a mom-and-pop shop running an HTTP website on some ancient shared hosting can easily just drop in Cloudflare is a Good Thing. Sure, you're not removing the attack surface, a state actor could intercept the server-to-server connections... but at least the hacked router in your customers' coffee shop is removed from the threat model. You make it any tougher, and that HTTP website is just…

The downside of such a setup is that as a user, I now have no idea if the site is actually secure. If the mom-and-pop shop is taking credit card orders and has a secure Cloudflare cert, how do I know they aren't then transmitting my credit card number and other personal data unencrypted the rest of the way? If the website was HTTP I would know as a user not to enter sensitive info. This is why I think flexible SSL is…

> The downside of such a setup is that as a user, I now have no idea if the site is actually secure.

You never do. SSL is not sufficient for security. It protects against a single attack vector, that's if it's set up correctly. For all you know, the set up of the server your visiting might have be old enough to have a driver's license, with public SSH and the root password "12345".

Re: A public letter to CloudFlare to fix their snoopy vendor

#95

Cloudflare is not doing anything wrong, why to pick that call ? Airtel support is here https://www.airtel.in/contact-us Also, vote with your wallet and don't use Airtel ?

Even better: vote for a party that is not BJP? :)

Yes vote for congress.

Re: A public letter to CloudFlare to fix their snoopy vendor

#96

Cloudflare powered censorship in Pakistan works in a similar fashion. ISPs block websites, but because Cloudflare's data center forwards using local ISPs, you get a nice secure blocked page.

Same here in Turkey. But this one is an int'l transit provider.

Posted this[0] months ago, even sent emails to Cloudflare NOC multiple times and nobody did even care.

[0] https://community.cloudflare.com/t/censored-pop-orpheus-not-...

Re: A public letter to CloudFlare to fix their snoopy vendor

#97
post #71

Earlier quoted context omitted.

No, because there is nothing interesting that's IPv6-only.

That depends a great deal on what country / language is your norm.

Which country/language has interesting IPv6-only content?

Re: A public letter to CloudFlare to fix their snoopy vendor

#98

Earlier quoted context omitted.

So really website owners are just misusing Cloudflare? How is this Cloudflare's fault?

In this case, it is not a random party in the CloudFlare--GitHub connection (say a network operator in UK). The snooping intermediary (Airtel) in this scenario is one that has a commercial relationship with CloudFlare and powers CloudFlare's network. CloudFlare has been aware of this issue for years, but it hasn't done anything to get its vendor to fix their network.

Isn't the censorship applied by Airtel, Jio, etc, because of local laws?

https://en.wikipedia.org/wiki/Internet_censorship_in_India

I don't see how Cloudflare or any other provider can make Airtel "fix" the snooping when Airtel is forced by law to block those sites.

This seems to be a policy/government problem, not a Cloudflare or Airtel problem.

Re: A public letter to CloudFlare to fix their snoopy vendor

#99
post #93
post #79

Earlier quoted context omitted.

I chose my analogy carefully. Oil is consumed but land and IP addresses are not.

You can't really just "find" more IPv4 though. Cloud platforms are eating blocks for breakfast, lunch and dinner, and while it's always going to be for sale, there's no reason to expect you'll be able to afford it.

Fortunately, if you can't afford IPv4 then no one else can afford it either, which means the incentive to adopt IPv6 is extremely strong and thus you no longer need IPv4.
Post reply on HN