Live data from Hacker News

CloudFlare enabling free SSL by mid-October

blog.cloudflare.com

21–30 of 66 posts

Re: CloudFlare enabling free SSL by mid-October

#21
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

[deleted]

Re: CloudFlare enabling free SSL by mid-October

#22
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

Yes, it worries me that Cloudflare is proxying an ever larger number of websites I visit. It is not so easy to dump Cloudflare when you need it though. They mitigate DDoS attacks, handle large volume traffic. I think moot even said that he'd have to close 4chan if it wasn't for Cloudflare.

Re: CloudFlare enabling free SSL by mid-October

#23
post #14

Are EV certs going to remain Business/Enterprise-only?

No.

I would have guessed EV certs to remain business only. Well, perhaps not business only, but still requiring additional validation. How do you believe EV will be handled? Thanks!

EDIT: I didn't realize you represented cloud-flare. I'm genuinely curious how EV certs will work. Thanks!

Re: CloudFlare enabling free SSL by mid-October

#24
post #6
post #5

Most of the websites wont encrypt the link from Cloudflare to the server, ultimately defeating the purpose of SSL aside from a better search ranking.

Could you elaborate on this. My impression was that connections between data centres (e.g. in the case of using an EC2 instance with Cloudflare) were already very secure and therefore do not require SSL.

Agree with others that it depends on what you are trying to protect against. It's also worth reading through the options that Cloudflare supports for origin server communication:

http://blog.cloudflare.com/introducing-strict-ssl-protecting...

Re: CloudFlare enabling free SSL by mid-October

#25
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

Gandi is free for a year and then expensive after - Namecheap may not be free but renewals and initial costs are much lower. StartSSL is free but revoke-ing costs money.

Namecheap vs Gandi is like 6.5 vs 12 EUR. Yes is almost double, but I don't know if I would consider them as cheap and "expensive".

Re: CloudFlare enabling free SSL by mid-October

#26
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

Gandi is free for a year and then expensive after - Namecheap may not be free but renewals and initial costs are much lower. StartSSL is free but revoke-ing costs money.

just checked now, Gandi is 40€/yr, not that expensive compared to big names like Verisign & co. I have used in the past RapidSSL, but it is same price, 50$/yr. I've just checked Namecheap and it's reselling other SSL like Comodo or Geotrust, but it looks less expensive, so yes, probably it's the best price.

Re: CloudFlare enabling free SSL by mid-October

#27
post #7
post #6

Earlier quoted context omitted.

Could you elaborate on this. My impression was that connections between data centres (e.g. in the case of using an EC2 instance with Cloudflare) were already very secure and therefore do not require SSL.

Depends what you're trying to protect against. Those links are notably very insecure against the NSA.

It's reasonable to suppose that the NSA have a whole bunch of private signing keys for a whole bunch of CAs, and will just MITM anyone they please regardless of our puny efforts.

Re: CloudFlare enabling free SSL by mid-October

#28
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

So, you're saying that using HTTP instead of HTTPS doesn't increase the privacy of users? I'd say that it does "increase" the privacy, although nobody is saying that it fixes every hole in the boat...

Re: CloudFlare enabling free SSL by mid-October

#29
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

Gandi is free for a year and then expensive after - Namecheap may not be free but renewals and initial costs are much lower. StartSSL is free but revoke-ing costs money.

Revoking StartSSL is only $25. If you go 3 years without needing revocation then you're ahead of paying Namecheap or anyone else for basic domain validation.

Re: CloudFlare enabling free SSL by mid-October

#30

what I just paid 20/month for the SSL.... Update: I have another concern I just found out. For example, I do a lot of web scraping through my domain and I see that I was automatically opted in to use https://www.cloudflare.com/apps/scrapeshield , something that is supposed to block scraping. There's a huge conflict of interest if it turns out that the cloudflare network actively aims to help block scraping. I know yo…

I don't get it. A domain is just an address, how can you scrape through your domain? Do you mean server? But scrapping is an outbound connection, how could they monitor it?
Post reply on HN