Live data from Hacker News

Ask HN: Why is there not more concern about the physical security of Cloudflare?

news.ycombinator.com

1–10 of 58 posts

Ask HN: Why is there not more concern about the physical security of Cloudflare?

#1
Using Hetzner and Azure, we trust that our unencrypted in-memory data and business logic are housed in professional data centers with strong physical security measures. However, Cloudflare has built its Workers and serverless offerings on top of its Cache/CDN and anti-DDoS infrastructure, which operates out of questionable ISP and IXP colocation facilities in various jurisdictions with dubious standards.

As an EU-based company, whenever we ask Cloudflare about the physical security of their edge locations, they consistently refer to encryption in transit and at rest—measures that do nothing to address threats like RAM interception or other physical security vulnerabilities in these questionable facilities. Moreover, when we raise these concerns, they attempt to upsell us on their Enterprise EU/FedRAMP offerings. Cloudflare has also deliberately restricted our ability to block non-Enterprise Workers, KV, and R2 from specific regions, leaving us with limited control over where our data is processed.

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#2
ultimately you trust the company and the jurisdiction in which they operate...if they give you the wrong answers then you should adjust your level of trust accordingly...thankfully there are other platforms and this is one concern that can certainly be better marketed

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#4
It's interesting to explore https://where.durableobjects.live/ - a tool that maps where Cloudflare's worker scripts actually run.

Notably, while Cloudflare has CDN edge locations in countries like China and Russia they don't appear to run workers there.

EDIT: I was wrong - I misinterpreted the map. A solid border circle around a location indicates "Worker-only Datacenter" (see the map legend) and there are indeed locations with those solid borders in Russia (including Moscow and Yekaterinburg) and China (Haidong, Lanzhou and more).

I doubt we could get them on the record for this, but I suspect this may be very deliberate. Maybe CDN edge locations can be run completely securely with forwarded encrypted traffic, while workers are at a higher risk of physical attack.

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#6
post #3

never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?

Just because there hasnt been a story doesnt mean its not important or critical

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#7
I don't use Cloudflare and I don't have strong opinions for or against them. These questions are the same I'd ask if you were discussing any other company:

> which operates out of questionable ISP and IXP colocation facilities in various jurisdictions with dubious standards.

Why do you say that? Do you have signals that their colo facilities are less secure than they should be, and/or that Cloudflare hasn't gotten those facilities to beef up their security as part of their contract? Again, not saying this to defend Cloudflare. I just hadn't heard this before.

> Moreover, when we raise these concerns, they attempt to upsell us on their Enterprise EU/FedRAMP offerings.

That's going to be the case with almost all providers in the space. If you're asking for special treatment, you're going to have to pay for it. I don't mean that to insult you. At a past job, for various reasons we had strict compliance obligations that our data could not be accessed outside of the US. Some of our vendors used offshore tech support who'd have access to our data, and a couple times we faced a decision: pay that vendor $$$ to special-case our support setup to meet our requirements, or choose another vendor.

> Cloudflare has also deliberately restricted our ability to block non-Enterprise Workers, KV, and R2 from specific regions, leaving us with limited control over where our data is processed.

Same. Those fine-grained controls are often going to be an enterprise feature.

Again, I'm not saying this to defend Cloudflare in particular. They have their own paid spokespeople. I'm not one. Nothing you've said sounds particularly egregious though. If your data is sensitive enough that you're legitimately worried about someone sneaking in undetected and intercepting RAM, prepare to pay the enterprise tax with all your cloud vendors.

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#8
post #4

It's interesting to explore https://where.durableobjects.live/ - a tool that maps where Cloudflare's worker scripts actually run. Notably, while Cloudflare has CDN edge locations in countries like China and Russia they don't appear to run workers there. EDIT: I was wrong - I misinterpreted the map. A solid border circle around a location indicates "Worker-only Datacenter" (see the map legend) and there are indeed loc…

Nice map but are you sure it overlaps with Workers in general? Workers can run without DO.

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#9
post #3

never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?

When I worked at AWS they were insanely hardcore about mandating physical access controls, that is all I’ll say, even to the point of ridiculousness. For all the things AWS does poorly security is not one of them.

If I were to guess CF is locating their PoPs at cheap peering points and the reason they are evading the question is because other customers in the facility have physical access to their equipment, which is both an expensive problem to solve and something that is not even remotely allowed at a real cloud provider.

Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?

#10
post #3

never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?

cough https://www.datacenterdynamics.com/en/analysis/ovhcloud-fire... (physical security isn't just access control)
Post reply on HN