Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

131–140 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#131

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

Why wouldn’t they fund the worlds largest MITM attack?

You can avoid that with some programming/setup and money: https://developers.cloudflare.com/ssl/keyless-ssl/

Re: CloudFlare’s last Warrant Canary was published over a year ago

#132
post #53
post #20

Earlier quoted context omitted.

Is there a precedent for compelling speech, even with something like an NSL?

Compelled speech has lots of examples from warning labels, disclosures, truth in advertising, etc. What you should be asking is their precedent for compelled false speech, which is a much more interesting and difficult to answer.

Many of those seem to be "you cannot do this legally codified activity unless you also fulfill the requirements enumerated therein". Can't sell food in retail setting without labeling it as required in the law that regulates food sales, and so on. That seems separate from compelling a creation of a false statement unrelated to business activity.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#133
post #13

Warrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."

What's more likely, they removed it to signal they think canaries are a legal uncertainty or because of something else?

If they don't think warrant canaries are legally doable, wouldn't they have put out a statement saying that?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#134

Earlier quoted context omitted.

By MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?

I guess you like those cookie warnings that pollute the Internet these days? Because this would be cookie warnings all over again. Any site that's reasonably popular uses a CDN to increase scalability, improve performance, and add reliability. Half the Internet would need a new pop-up warning that a CDN is in use. The last thing we need is yet another pop-up when a page loads....

It doesn't need to be a pop up. Just behave like a HTTP site ("not secure" warning) when you could be MITM'd between yourself and the entity you think you are communicating with.

If it turned out "End to end" encrypted chat went through a third party that even transiently had access to the plaintext version of the chat (like how Cloudflare works) you'd be apoplectic.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#135

Earlier quoted context omitted.

By MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?

This seems like a useless warning. The owner of the domain has to choose to integrate a CDN. They implicitly trust the vendor who runs the CDN just like they implicitly trust the cloud provider that asserts their VPC between their server that terminates TLS and any API servers behind that which don’t use encryption for data in transit.

That's fine but the user has no way of knowing if a third party is party to the communications or not. Surely they should know?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#136

Earlier quoted context omitted.

It doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.

It’s always the website’s choice what infrastructure is used to serve the website, including whether a proxy is used. You don’t have a chance to say no if the website owner wants a proxy in front of their site. The web owner has a say in how they want their server to be connected. In the same way, you can use a proxy to access sites, and the server cannot bypass that, either.

I know. I understand the tech and the business decisions behind all of this. I understand the value of a CDN.

It's still a MitM. It's a centralised entity that sees a huge share of the global Internet's traffic, unencrypted. I doubt most people are aware of that.

Someone in another comment mentioned AWS is one as well, and they're right. AWS, GCP and Azure all have TLS-terminating gateways of some kind.

Take Cloudflare, AWS, GCP and Azure, all USA companies bound by the CLOUD act, and nearly all Internet traffic is immediately accessible by US authorities, unencrypted.

Makes the whole "think of the children" rhetoric being spun to pass anti-E2EE laws tame in comparison.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#137
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I'll state right here: all these are still true. We'll get the canary updated. Checking with legal and trust & safety why it hasn't been for so long. Likely just slipped someone's mind. Will make sure that doesn't happen again.

[dead]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#138

Maybe I’m just getting old and distracted, but I feel like CloudFlare went from “whoa some HN pros are doing great CDN work with some serious chops and an underdog work ethic” to “is it possible to never connect to them” like, really fast.

I think there was 10 or so years in the middle there :)

I think we’d all be pleased to build something out of passion and have it survive a decade without corruption, probably harder than it sounds

Re: CloudFlare’s last Warrant Canary was published over a year ago

#139

Earlier quoted context omitted.

This forum requires a basic assumption of good faith for posters, especially when it comes to such a trivial mistake like having the wrong anchor section on a link to a short article. It was probably an artifact of their browser trying to be “helpful” when they were copying the link to the full article. Your aggression is unwarranted.

[flagged]

Could you please stop posting unsubstantive comments and flamebait? You've unfortunately been doing it repeatedly. It's not what this site is for, and destroys what it is for.

https://news.ycombinator.com/item?id=36944821 was particularly bad. We ban accounts that do that kind of thing, so please don't again.

If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#140
post #139

Earlier quoted context omitted.

[flagged]

Could you please stop posting unsubstantive comments and flamebait? You've unfortunately been doing it repeatedly. It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/item?id=36944821 was particularly bad. We ban accounts that do that kind of thing, so please don't again. If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting h…

[flagged]
Post reply on HN