Live data from Hacker News

Celebrating CloudFlare's 4th Birthday

blog.cloudflare.com

11–20 of 42 posts

Re: Celebrating CloudFlare's 4th Birthday

#11
post #9
post #3

CloudFlare is the biggest MITM attack in the history of the internet. Why are we putting this much power in the hands of a few US citizens, who are legally obliged to record all that unencrypted data passing through their servers?

Most sites which are not on HTTPS now are static sites like blogs etc. Google recently announced HTTPS will be determining SERP so many webmasters are going to use it anyway even with a MITM.

> Google recently announced HTTPS will be determining SERP

Seriously? So now I have to buy into the corrupt CA system in order to rank well in searches? :/

Re: Celebrating CloudFlare's 4th Birthday

#12
post #3

CloudFlare is the biggest MITM attack in the history of the internet. Why are we putting this much power in the hands of a few US citizens, who are legally obliged to record all that unencrypted data passing through their servers?

who are legally obliged to record all that unencrypted data

They may be compelled to do that. It was actually a European directive, and subsequent regulations in each member state, that forced providers to retain data pre-emptively, and even that didn't require them to record all traffic.

https://en.wikipedia.org/wiki/Data_Retention_Directive

Re: Celebrating CloudFlare's 4th Birthday

#13
post #9

Earlier quoted context omitted.

Most sites which are not on HTTPS now are static sites like blogs etc. Google recently announced HTTPS will be determining SERP so many webmasters are going to use it anyway even with a MITM.

> Google recently announced HTTPS will be determining SERP Seriously? So now I have to buy into the corrupt CA system in order to rank well in searches? :/

It's supposed to be a minor ranking signal for now.

http://googleonlinesecurity.blogspot.com/2014/08/https-as-ra...

Re: Celebrating CloudFlare's 4th Birthday

#14
post #3

CloudFlare is the biggest MITM attack in the history of the internet. Why are we putting this much power in the hands of a few US citizens, who are legally obliged to record all that unencrypted data passing through their servers?

We are not recording the data that passes through our servers.

Re: Celebrating CloudFlare's 4th Birthday

#15
post #8
post #2

First letter of each paragraph = "SSL TLS FREE".

Time to go grab a cert from startssl.com for free. No more excuses for not having an SSL site.

CloudFlare will probably supply their own certificates so you won't even need to do that.

Re: Celebrating CloudFlare's 4th Birthday

#16
post #8
post #2

First letter of each paragraph = "SSL TLS FREE".

Time to go grab a cert from startssl.com for free. No more excuses for not having an SSL site.

I think CloudFlare "free SSL" is CloudFlare-issued instead of Custom Cert, which I think it is good enough. If their "free SSL" allow free plan customers to upload Custom Cert, that is even awesome.

Re: Celebrating CloudFlare's 4th Birthday

#17

Wonder why DDOSes have been getting worse lately? DDOS groups are putting their sites behind Cloudflare so they cannot be DDOSed off the internet by rival groups, thus their "services" become a lot more accessible, and they have grown bolder. This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare. This absolutely needs to be addre…

It is because many DDoS websites sitting behind Cloudflare are FBI run. See titaniumstresser[0] as an example. One of their sub-domain's IP address is allocated to the FBI[1]. Seems like the longest lasting sites peddling stolen info, child pornography, or malicious services are all run by feds.

Hostname: direct.titaniumstresser.net IP Address: 153.31.25.12 Organization: FBI Criminal Justice Information Systems

[0] http://titaniumstresser.net/

[1] http://direct.titaniumstresser.net.ipaddress.com/

Re: Celebrating CloudFlare's 4th Birthday

#19

Wonder why DDOSes have been getting worse lately? DDOS groups are putting their sites behind Cloudflare so they cannot be DDOSed off the internet by rival groups, thus their "services" become a lot more accessible, and they have grown bolder. This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare. This absolutely needs to be addre…

It is because many DDoS websites sitting behind Cloudflare are FBI run. See titaniumstresser[0] as an example. One of their sub-domain's IP address is allocated to the FBI[1]. Seems like the longest lasting sites peddling stolen info, child pornography, or malicious services are all run by feds. Hostname: direct.titaniumstresser.net IP Address: 153.31.25.12 Organization: FBI Criminal Justice Information Systems [0] h…

LOL, that's just so someone (of a rival group) who tries to get their real IP address (to ddos them), finds that subdomain, and doesn't look closely, and goes to ddos the FBI.

Re: Celebrating CloudFlare's 4th Birthday

#20
post #8

Earlier quoted context omitted.

Time to go grab a cert from startssl.com for free. No more excuses for not having an SSL site.

CloudFlare will probably supply their own certificates so you won't even need to do that.

Shouldn't we all be glad with it? HTTPS-MITM-as-a-service... and authorized... awesome!
Post reply on HN