Earlier quoted context omitted.
And it's Cloudflare's decision to expose the endpoint as HTTPS, suggesting to visitors that it's a secure endpoint when Cloudflare knows that it is not.
It's each website's decision to use (or not use) Cloudflare. It's thus also by extension each website's decision to expose the site over HTTPS.
Cloudflare CEO on whether Airtel is sniffing data packets to block websites
11–18 of 18 posts
Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#12MediaNama: So the only way they can understand what to block via this route is by sniffing every packet?
Matthew Prince, Cloudflare: That is what I’m concerned about, but we don’t have a satisfactory answer at this point. But you are correct, that is what I infer.
Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#13An interesting aside: CloudFlare is likely inadvertently exporting Indian censorship to neighboring countries like Sri Lanka, Nepal and Bangladesh.
Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#14Title is clickbait. The only important/interesting quote from the article: > That particular customer had set up their configuration in such a way that the connection from Cloudflare back to the customers origin was not passed over an encrypted link. Clouldflare has the ability to pass that over an encrypted link. We don’t have any idea why this particular customer chose to do that, but that’s the customers decision.
The background to this is that when a security researcher discovered that CloudFlares upstream connections are being tampered with, Airtel issued a denial. Matthew Prince's answers here contradict Airtel's statement.
Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#15Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#16[deleted]
Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#17Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites
#18Earlier quoted context omitted.
It's each website's decision to use (or not use) Cloudflare. It's thus also by extension each website's decision to expose the site over HTTPS.
For sure. From the perspective of a visitor to the site, you see the padlock, it should be secure. Cloudflare makes it extremely easy to disguise an insecure endpoint as a secure one. In fact, Cloudflare does this for free! It harms visitors.
Cloudflare is part of the customer's website, it's not some random third-party that happens to be there on the path to the HTTP client.