Earlier quoted context omitted.
How would an attacker learn of the private key server? If that were easy, the very concept of CloudFlare would be undermined, which obviously is not the case. Having learned the address of the private key server, how would an attacker proceed? ISTM that all she could attempt would be to repeatedly try to set up the "secure tunnel" mentioned in TFA. At some point the private key server could just ignore those. I don't…
> How would an attacker learn of the private key server? If they're using CloudFlare and they're a large financial institution we'll just assume they're using this new service. Now we just need to find the location of the keyserver. There's a variety of ways to locate a server when you don't know where it is. The default is to scan the target's network. To find the network you can look at the ARIN info for addresses…
Fixed: "If they're using CloudFlare and they're a large [anything], we just need to find the location of the [origin webserver]."
This hasn't been a problem for any of their customers that do this so far (hint: all of them), adding a keyserver is no different.