Live data from Hacker News

CloudFlare enabling free SSL by mid-October

blog.cloudflare.com

31–40 of 66 posts

Re: CloudFlare enabling free SSL by mid-October

#31
post #27
post #7

Earlier quoted context omitted.

Depends what you're trying to protect against. Those links are notably very insecure against the NSA.

It's reasonable to suppose that the NSA have a whole bunch of private signing keys for a whole bunch of CAs, and will just MITM anyone they please regardless of our puny efforts.

I'm not sure that's a safe assumption and, regardless, an active MITM attack is a much bigger deal than passively collecting traffic as it flows past you in the clear.

Re: CloudFlare enabling free SSL by mid-October

#32

Earlier quoted context omitted.

No.

I would have guessed EV certs to remain business only. Well, perhaps not business only, but still requiring additional validation. How do you believe EV will be handled? Thanks! EDIT: I didn't realize you represented cloud-flare. I'm genuinely curious how EV certs will work. Thanks!

You'll have to supply your own EV cert, but you'll be able to use custom certs (EV or otherwise) at the Pro ($20/mo) level.

Re: CloudFlare enabling free SSL by mid-October

#34
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

Yes, it worries me that Cloudflare is proxying an ever larger number of websites I visit. It is not so easy to dump Cloudflare when you need it though. They mitigate DDoS attacks, handle large volume traffic. I think moot even said that he'd have to close 4chan if it wasn't for Cloudflare.

Cloudflare hosts and defends the sites of numerous DDoS-for-pay services and they refuse to take them down.

http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

"[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage industry of DDoS-for-hire services."

Re: CloudFlare enabling free SSL by mid-October

#35
post #18

Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…

So, you're saying that using HTTP instead of HTTPS doesn't increase the privacy of users? I'd say that it does "increase" the privacy, although nobody is saying that it fixes every hole in the boat...

Speaking strictly, you're right, but when you consider (a) Cloudflare's connection to your server is insecure (b) Cloudflare is listening in on every request (c) Cloudflare blocks VPN and Tor users, it doesn't seem like such an obvious decision. But that's a false dichotomy, since everybody should use HTTPS, nobody should use HTTP, and, most importantly, nobody should be okay with third-parties snooping on your users.

Re: CloudFlare enabling free SSL by mid-October

#36
post #10

Earlier quoted context omitted.

It would be free, but not necessarily easy, as it would still entail configuring your web server to use SSL, and that might not even be an option if you're using shared hosting. (Aside: self signed certs don't protect the connection from active attacks unless CloudFlare pins the cert. I'm mainly concerned with passive eavesdropping though.)

That's what we're going to do: issue certs that our customers can use on their origins, that will be trusted by our network, and that will be pinned to a particular site. That will allow end-to-end cryptographic connections. There are other groups working on making installing and setting up SSL on origin servers easier, that's not something we're likely to tackle, but agree it's important.

That's amazing. Thank you.

Re: CloudFlare enabling free SSL by mid-October

#37
post #34

Earlier quoted context omitted.

Yes, it worries me that Cloudflare is proxying an ever larger number of websites I visit. It is not so easy to dump Cloudflare when you need it though. They mitigate DDoS attacks, handle large volume traffic. I think moot even said that he'd have to close 4chan if it wasn't for Cloudflare.

Cloudflare hosts and defends the sites of numerous DDoS-for-pay services and they refuse to take them down. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... "[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage ind…

That actually makes me trust them more. If they don't take down a site like that, then whatever site I run is certainly in the clear.

Re: CloudFlare enabling free SSL by mid-October

#39
post #34

Earlier quoted context omitted.

Cloudflare hosts and defends the sites of numerous DDoS-for-pay services and they refuse to take them down. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... "[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage ind…

That actually makes me trust them more. If they don't take down a site like that, then whatever site I run is certainly in the clear.

https://news.ycombinator.com/item?id=7968247
Post reply on HN