I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.
Why wouldn’t they fund the worlds largest MITM attack?
CloudFlare’s last Warrant Canary was published over a year ago
131–140 of 145 posts
Re: CloudFlare’s last Warrant Canary was published over a year ago
#132Earlier quoted context omitted.
Is there a precedent for compelling speech, even with something like an NSL?
Compelled speech has lots of examples from warning labels, disclosures, truth in advertising, etc. What you should be asking is their precedent for compelled false speech, which is a much more interesting and difficult to answer.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#133Warrant canaries are largely believed to be unworkable. Ie federal lawyers are going to say "cute, but no, you cannot disclose that we warranted you in this or any other way."
What's more likely, they removed it to signal they think canaries are a legal uncertainty or because of something else?
Re: CloudFlare’s last Warrant Canary was published over a year ago
#134Earlier quoted context omitted.
By MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?
I guess you like those cookie warnings that pollute the Internet these days? Because this would be cookie warnings all over again. Any site that's reasonably popular uses a CDN to increase scalability, improve performance, and add reliability. Half the Internet would need a new pop-up warning that a CDN is in use. The last thing we need is yet another pop-up when a page loads....
If it turned out "End to end" encrypted chat went through a third party that even transiently had access to the plaintext version of the chat (like how Cloudflare works) you'd be apoplectic.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#135Earlier quoted context omitted.
By MITMing traffic between you and the host. Maybe Firefox should display a warning when it detects intermediaries that could have decrypted the traffic between the host and you?
This seems like a useless warning. The owner of the domain has to choose to integrate a CDN. They implicitly trust the vendor who runs the CDN just like they implicitly trust the cloud provider that asserts their VPC between their server that terminates TLS and any API servers behind that which don’t use encryption for data in transit.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#136Earlier quoted context omitted.
It doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.
It’s always the website’s choice what infrastructure is used to serve the website, including whether a proxy is used. You don’t have a chance to say no if the website owner wants a proxy in front of their site. The web owner has a say in how they want their server to be connected. In the same way, you can use a proxy to access sites, and the server cannot bypass that, either.
It's still a MitM. It's a centralised entity that sees a huge share of the global Internet's traffic, unencrypted. I doubt most people are aware of that.
Someone in another comment mentioned AWS is one as well, and they're right. AWS, GCP and Azure all have TLS-terminating gateways of some kind.
Take Cloudflare, AWS, GCP and Azure, all USA companies bound by the CLOUD act, and nearly all Internet traffic is immediately accessible by US authorities, unencrypted.
Makes the whole "think of the children" rhetoric being spun to pass anti-E2EE laws tame in comparison.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#137Earlier quoted context omitted.
Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…
I'll state right here: all these are still true. We'll get the canary updated. Checking with legal and trust & safety why it hasn't been for so long. Likely just slipped someone's mind. Will make sure that doesn't happen again.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#138Maybe I’m just getting old and distracted, but I feel like CloudFlare went from “whoa some HN pros are doing great CDN work with some serious chops and an underdog work ethic” to “is it possible to never connect to them” like, really fast.
I think there was 10 or so years in the middle there :)
Re: CloudFlare’s last Warrant Canary was published over a year ago
#139Earlier quoted context omitted.
This forum requires a basic assumption of good faith for posters, especially when it comes to such a trivial mistake like having the wrong anchor section on a link to a short article. It was probably an artifact of their browser trying to be “helpful” when they were copying the link to the full article. Your aggression is unwarranted.
[flagged]
https://news.ycombinator.com/item?id=36944821 was particularly bad. We ban accounts that do that kind of thing, so please don't again.
If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting here, we'd appreciate it.
Re: CloudFlare’s last Warrant Canary was published over a year ago
#140Earlier quoted context omitted.
[flagged]
Could you please stop posting unsubstantive comments and flamebait? You've unfortunately been doing it repeatedly. It's not what this site is for, and destroys what it is for. https://news.ycombinator.com/item?id=36944821 was particularly bad. We ban accounts that do that kind of thing, so please don't again. If you'd please review https://news.ycombinator.com/newsguidelines.html and stick to the rules when posting h…