Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

121–130 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#121

Earlier quoted context omitted.

Does CloudFlare proxy your website without your permission?

You're being needlessly pedantic. It might not be an attack in the usual sense, but it's a MITM "access point" and agencies like CIA/NSA/FBI would definitely have that kind of access. This access transforms Cloudflare's role into a de facto MITM "attack" on their customers and end users who didn't intend to share unencrypted data with 3-letter agencies.

I don’t think I’m being pedantic. In practical, the parent comment’s description is not that of MITM attack, but how a proxy works. Proxy is everywhere, useful, and voluntary.

I just don’t understand how a voluntary use of proxy can be called MITM attack.

I’m not saying I like the fact that CF is part of so much of the Internet, or that CF isn’t on some level a security risk. But that has nothing to do with being an MITM attack.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#122
post #109

Earlier quoted context omitted.

> It's really, really hard to be part of some grand conspiracy as a public company. No it's not. Twitter and Facebook have had defacto government censorship collusion, as suspected by the paranoid. For years and years it was dismissed as conspiracy, but clear evidence has now come out that it was happening in these public companies.

>clear evidence has now come out Source?

Twitterfiles, various publications on government access to Facebook takedown portal.

Including on this platform...

https://news.ycombinator.com/item?id=33418284

Re: CloudFlare’s last Warrant Canary was published over a year ago

#123
post #13

Warrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."

Yes and no.

They can say "don't do anything". They can't say "don't avoid doing something." That's the point if the age of the warrant canary notification--they stopped updating it. This is in effect a dead canary, they're saying they are subject to an order they can't disclose.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#124

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

Your response really shows a disconnect with the user and what was said

Not many users who encounter your service while trying to connect to a website will know _anything_ about your company, let alone knows its public or read disclosures.

Cloudflare has a public perception and sentiment problem and dismissing it as you have will lead to an inevitably negative outcome.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#125

Earlier quoted context omitted.

It doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.

It’s always the website’s choice what infrastructure is used to serve the website, including whether a proxy is used. You don’t have a chance to say no if the website owner wants a proxy in front of their site. The web owner has a say in how they want their server to be connected. In the same way, you can use a proxy to access sites, and the server cannot bypass that, either.

[flagged]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#126
post #34

Earlier quoted context omitted.

Why is the commentary of far-right reactionary, who is not a legal expert, commenting on a canadian law, that has nothing to do with warrants, with a citation pointing out that legal experts disagree with him, at all relevant to this conversation?

This forum requires a basic assumption of good faith for posters, especially when it comes to such a trivial mistake like having the wrong anchor section on a link to a short article. It was probably an artifact of their browser trying to be “helpful” when they were copying the link to the full article. Your aggression is unwarranted.

[flagged]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#127

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

> So… once we went public I kind of thought this silly speculation would end. But guess not.

In fairness, there are quite a number of public companies that turned out to be operating partially as fronts for spying agencies (AT&T is the shining example here). So simply being a public company could not be expected to serve as some kind of proof of independence.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#128

Earlier quoted context omitted.

How do you think any CDN works?

By MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?

This seems like a useless warning.

The owner of the domain has to choose to integrate a CDN. They implicitly trust the vendor who runs the CDN just like they implicitly trust the cloud provider that asserts their VPC between their server that terminates TLS and any API servers behind that which don’t use encryption for data in transit.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#129

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

> It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons.

As difficult as it was to keep PRISM and the many other overt and covert arrangements (public, private but leaked, and private but not yet leaked) between backbones, carriers, CDNs, hosting providers, ISPs, etc., and the agencies leveraging them, out of each firm's public filings?

Because evidence is it's not difficult at all, considering the whole of the 30 years since the Internet went commercial.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#130
post #114
post #100

Earlier quoted context omitted.

Immunity from prosecution seems like a marvellous way to destroy rule of law. Crazy that that and royal^H^H^H^H^H presidential pardons exist. Recipe for corruption of the state and then the justice system.

As the purpose of Presidential pardons is to provide the opportunity to right significant miscarriages of justice in system that is almost impossible to get perfect, and that is the way they were typically used, it does not seem crazy that they exist. What IS crazy is that they exist with very little consideration of a corrupt POTUS, judiciary, and/or congress. Seems the writings of the founders did worry about that…

> it does not seem crazy that they exist.

I think that it does seem crazy that they exist. To give a single politician the power to simply override our justice system is dangerous and crazy. If that's really necessary in order to ovoid miscarriages of justice, then we need to fix the real problem, not introduce a new one.

Why is the pardon ability a problem? Because it's the judgement not just of one person, but of a person who is a political animal. There is no way that power will be used in a way that is impartial, and there is no single person who is so wise that they should be entrusted with such decisions. That it's a politician making the decisions all but guarantees that the decisions will be made out of political interest, not some interest in actual justice.

All the pardon power does is to increase the potential for corruption.

Post reply on HN