As an EU-based company, whenever we ask Cloudflare about the physical security of their edge locations, they consistently refer to encryption in transit and at rest—measures that do nothing to address threats like RAM interception or other physical security vulnerabilities in these questionable facilities. Moreover, when we raise these concerns, they attempt to upsell us on their Enterprise EU/FedRAMP offerings. Cloudflare has also deliberately restricted our ability to block non-Enterprise Workers, KV, and R2 from specific regions, leaving us with limited control over where our data is processed.
Ask HN: Why is there not more concern about the physical security of Cloudflare?
1–10 of 58 posts
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#2Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#3Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#4Notably, while Cloudflare has CDN edge locations in countries like China and Russia they don't appear to run workers there.
EDIT: I was wrong - I misinterpreted the map. A solid border circle around a location indicates "Worker-only Datacenter" (see the map legend) and there are indeed locations with those solid borders in Russia (including Moscow and Yekaterinburg) and China (Haidong, Lanzhou and more).
I doubt we could get them on the record for this, but I suspect this may be very deliberate. Maybe CDN edge locations can be run completely securely with forwarded encrypted traffic, while workers are at a higher risk of physical attack.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#5Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#6never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#7> which operates out of questionable ISP and IXP colocation facilities in various jurisdictions with dubious standards.
Why do you say that? Do you have signals that their colo facilities are less secure than they should be, and/or that Cloudflare hasn't gotten those facilities to beef up their security as part of their contract? Again, not saying this to defend Cloudflare. I just hadn't heard this before.
> Moreover, when we raise these concerns, they attempt to upsell us on their Enterprise EU/FedRAMP offerings.
That's going to be the case with almost all providers in the space. If you're asking for special treatment, you're going to have to pay for it. I don't mean that to insult you. At a past job, for various reasons we had strict compliance obligations that our data could not be accessed outside of the US. Some of our vendors used offshore tech support who'd have access to our data, and a couple times we faced a decision: pay that vendor $$$ to special-case our support setup to meet our requirements, or choose another vendor.
> Cloudflare has also deliberately restricted our ability to block non-Enterprise Workers, KV, and R2 from specific regions, leaving us with limited control over where our data is processed.
Same. Those fine-grained controls are often going to be an enterprise feature.
Again, I'm not saying this to defend Cloudflare in particular. They have their own paid spokespeople. I'm not one. Nothing you've said sounds particularly egregious though. If your data is sensitive enough that you're legitimately worried about someone sneaking in undetected and intercepting RAM, prepare to pay the enterprise tax with all your cloud vendors.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#8It's interesting to explore https://where.durableobjects.live/ - a tool that maps where Cloudflare's worker scripts actually run. Notably, while Cloudflare has CDN edge locations in countries like China and Russia they don't appear to run workers there. EDIT: I was wrong - I misinterpreted the map. A solid border circle around a location indicates "Worker-only Datacenter" (see the map legend) and there are indeed loc…
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#9never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?
If I were to guess CF is locating their PoPs at cheap peering points and the reason they are evading the question is because other customers in the facility have physical access to their equipment, which is both an expensive problem to solve and something that is not even remotely allowed at a real cloud provider.
Re: Ask HN: Why is there not more concern about the physical security of Cloudflare?
#10never heard of a story where physical security at any cloud provider has been a problem. are you worried about governments, or employees, or someone breaking in?