Live data from Hacker News

Cloudflare CEO on whether Airtel is sniffing data packets to block websites

medianama.com

11–18 of 18 posts

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#11
post #6
post #5

Earlier quoted context omitted.

And it's Cloudflare's decision to expose the endpoint as HTTPS, suggesting to visitors that it's a secure endpoint when Cloudflare knows that it is not.

It's each website's decision to use (or not use) Cloudflare. It's thus also by extension each website's decision to expose the site over HTTPS.

For sure. From the perspective of a visitor to the site, you see the padlock, it should be secure. Cloudflare makes it extremely easy to disguise an insecure endpoint as a secure one. In fact, Cloudflare does this for free! It harms visitors.

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#12
TL;DR:

MediaNama: So the only way they can understand what to block via this route is by sniffing every packet?

Matthew Prince, Cloudflare: That is what I’m concerned about, but we don’t have a satisfactory answer at this point. But you are correct, that is what I infer.

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#13
For those who missed the background to this, CloudFlare’s Indian ISP was modifying the response from the upstream server to their proxy servers; Unable to detect this, CloudFlare serves the fake response to users under an authentic SSL certificate for that domain.

An interesting aside: CloudFlare is likely inadvertently exporting Indian censorship to neighboring countries like Sri Lanka, Nepal and Bangladesh.

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#14
post #3

Title is clickbait. The only important/interesting quote from the article: > That particular customer had set up their configuration in such a way that the connection from Cloudflare back to the customers origin was not passed over an encrypted link. Clouldflare has the ability to pass that over an encrypted link. We don’t have any idea why this particular customer chose to do that, but that’s the customers decision.

Not at all.

The background to this is that when a security researcher discovered that CloudFlares upstream connections are being tampered with, Airtel issued a denial. Matthew Prince's answers here contradict Airtel's statement.

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#17
Can someone explain this to an encryption dummy? The 'customer' the CEO is talking about, who chose to not encrypt traffic from cloudfare back to the origin is the PirateBay? So airtel could be sniffing all the unencrypted packets going from cloudfare to other cloudfare customers if the content is stored in cloudfare's india data centers?

Re: Cloudflare CEO on whether Airtel is sniffing data packets to block websites

#18
post #11
post #6

Earlier quoted context omitted.

It's each website's decision to use (or not use) Cloudflare. It's thus also by extension each website's decision to expose the site over HTTPS.

For sure. From the perspective of a visitor to the site, you see the padlock, it should be secure. Cloudflare makes it extremely easy to disguise an insecure endpoint as a secure one. In fact, Cloudflare does this for free! It harms visitors.

... And it's the customer's decision to leave the cloudflare->upstream link in the clear. Just like it was Google's decision to add and remove SSL between the frontend server and the backends.

Cloudflare is part of the customer's website, it's not some random third-party that happens to be there on the path to the HTTP client.

Post reply on HN