This is excellent news - one question though - what would a user on XP see when he accesses one of these sites?
Universal SSL
171–180 of 250 posts
Re: Universal SSL
#172Earlier quoted context omitted.
"On the other hand, this completely destroys the premise of HTTPS that you have an encrypted connection to the website you are visiting ." Yes, you do. You are visiting a website that CloudFlare is serving, and you have encryption to that. Other replies have already gone into how HTTPS never guaranteed anything about what happened after that, but I think that's the wrong POV. What HTTPS guarantees is that one of the…
>> "On the other hand, this completely destroys the premise of HTTPS that you have an encrypted connection to the website you are visiting." >> Yes, you do. You are visiting a website that CloudFlare is serving, and you have encryption to that. Total newbie here. Since CloudFlare (and likewise any other CDN) is hosting many websites, how do I know the information served originated from the intended website and not fr…
You don't, really. The target website has indicated that they trust CloudFlare, and if CloudFlare turns out to be unworthy of that trust you're pretty much out of luck. From SSL's point of view it is exactly the same as if the originating party is unworthy of your trust.
I think there's a bit of a mental model update that people may need to process... the originating party does not have any mystical geas invoked upon it by SSL to be trustworthy itself. There's nothing stopping the other end from being untrustworthy for any reason. Nothing in HTTPS prevents the other party from posting your transaction on an electronic billboard on the nearest highway. Yes, it sounds obvious when I say it, but it's very important and clear many people aren't operating under this model. CloudFlare isn't doing anything weird or new here... you've always had to trust the judgment of the other end of the HTTPS connection, and it has always involved the trustworthiness of other parties as well. There's no change here. Among the many ways in which a remote party could be untrustworthy is for them to delegate that trust to an untrustworthy party. Nothing strange about that.
Re: Universal SSL
#173I just got the popup, clicked "okay" and when I go to "Cloudflare settings", it's still only available to select SSL options for the paid plans. For those who haven't yet seen the popup there's a bit more info here: https://www.cloudflare.com/ssl#universal_ssl It's a pity that I got the message saying it was available on my account, when the setting is not yet activated :)
Yes, sorry about that. We're rushing to set up certificates for everyone who uses CloudFlare.
Re: Universal SSL
#174Re: Universal SSL
#175Earlier quoted context omitted.
I guess you're right about that, but it still feels a bit weird that a third party can just allocate a private key and a valid certificate without the actual owner of the domain requesting it.
If you've given up control of the DNS on your domain to a third party, they can do whatever they want with that domain - they ultimately control email, web, and any other services on that domain. so if you use cloudflare, you've already given up that control and trust them completely with your domain. This is what makes me hesitant about using cloudflare or recommending it to clients; you give up a lot of control ove…
Unless you're using DNSSEC..!
Re: Universal SSL
#176Earlier quoted context omitted.
Since you ask so nicely I had your domain bumped up in the queue.
Hi John, I know Cloudflare will be announcing later today, but how will people be enabling Full SSL (Strict) with this new rollout? I see these certs being issued out automatically are to subdomains at cloudflare. Will customers who want to enable Full SSL (Strict) be given the ability to enroll for another certificate for free that is issued to their Common Name via your site? (Context from Cloudflare's announcement…
Re: Universal SSL
#177There are industries where off-premises key management is not appropriate and certainly not a trusted man-in-the-middle by a third-party vendor. For these organizations, having any party be in the position to be able to intercept communications is a total no-go.
But for a lot of the internet community that is not the primary threat to model. Rather its inertia that prevents SSL from being set up in the first place because it is seen as either expensive, hard, or somehow unnecessary. For these circumstances, protecting users from criminal surveillance at the local coffee shop and from content manipulation by unscrupulous, unaccountable cable internet service providers is a very good thing.
I have clients who I will advise to pass on this based upon their threat model and others for whom this is a great option. For my own blog, this is perfect too. It's about knowing your threat model and choosing the appropriate countermeasures accordingly.
Re: Universal SSL
#178CloudFlare now has the most sophisticated MITM attack in the world, where they tell you what they are doing and make you sign up for it. Does CloudFlare have a direct pipe to the NSA already, or is that only going to happen next week?
Your tinfoil's got a hole in it there buddy! But also https://www.cloudflare.com/transparency Could probs do with being a bit closer to realtime but it's more transparent than most hosts/ISPs
Re: Universal SSL
#179Earlier quoted context omitted.
1) That's not actually accurate; and 2) Just wait for the next trick we have up our sleeve ( https://blog.cloudflare.com/one-more-thing-keyless-ssl-and-c... )
It may not be entirely accurate; I can only go by the complaints I hear from my Chinese friends, and my limited experience with CloudFlare-enabled websites when I'm in China for short stays. However it definitely has significant impact for Chinese users. I see you have big plans for China :) Looking forward to seeing your new data centers coming online. How do you plan to solve the mandatory ICP Registration problem…
Sums it up nicely.
Re: Universal SSL
#180Earlier quoted context omitted.
Your cert hasn't been issued yet. We are in the processing of issuing 2 million certs. You got a default cert that's sort of a 'catch all'. When that goes away your domain will have been issued a real cert.
Not trying to diminish the value of what you're doing, but, who gave you(Cloudflare) permission to issue SSL certificates for my domains, hypothetically speaking ofcourse? Shouldn't that be an opt-in process?