Earlier quoted context omitted.
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
Cloudflare is doing this already. Once they had enough monopoly power, they started a program to block all bots that don't undergo invasive KYC procedures. Eventually, they might become a KYC broker for regular browser users too. The free internet is over.
Tell HN: Cloudflare silently injects its analytics when you switch nameservers
21–30 of 217 posts
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#22Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#23You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required. If they can inject script, they can also snoop on all your cleartext traffic without you knowing....
Oh gosh I didn’t enable anything like that also. I just wanted the nameservers in order to serve the bucket under my subdomain. What else is there I wonder?
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#24I have all my domains set to DNS only, so no CF proxy. Wondering if that is why?
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#25Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#26Are you using CF as a proxy or only for DNS? I ask because I just went to check my domains on the dashboard (some purchased a few years ago, one purchased just a couple days ago), and none of them have Web Analytics enabled. I have all my domains set to DNS only, so no CF proxy. Wondering if that is why?
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#27Cloudflare injected hostile code into a site they are not even hosting? If it's HTTPS, how do they even do that?
Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#28Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.
Re: Tell HN: Cloudflare silently injects its analytics when you switch nameservers
#29> injected a JS analytics snippet in my HTML-only JS-free site textlog.cc Cloudflare injected hostile code into a site they are not even hosting? If it's HTTPS, how do they even do that? Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?