Earlier quoted context omitted.
Depends what you're trying to protect against. Those links are notably very insecure against the NSA.
It's reasonable to suppose that the NSA have a whole bunch of private signing keys for a whole bunch of CAs, and will just MITM anyone they please regardless of our puny efforts.
CloudFlare enabling free SSL by mid-October
31–40 of 66 posts
Re: CloudFlare enabling free SSL by mid-October
#32Earlier quoted context omitted.
No.
I would have guessed EV certs to remain business only. Well, perhaps not business only, but still requiring additional validation. How do you believe EV will be handled? Thanks! EDIT: I didn't realize you represented cloud-flare. I'm genuinely curious how EV certs will work. Thanks!
Re: CloudFlare enabling free SSL by mid-October
#33Re: CloudFlare enabling free SSL by mid-October
#34Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…
Yes, it worries me that Cloudflare is proxying an ever larger number of websites I visit. It is not so easy to dump Cloudflare when you need it though. They mitigate DDoS attacks, handle large volume traffic. I think moot even said that he'd have to close 4chan if it wasn't for Cloudflare.
http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...
"[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage industry of DDoS-for-hire services."
Re: CloudFlare enabling free SSL by mid-October
#35Please note that using Cloudflare, even with free SSL, is not an increase to the security and privacy of your users. On the contrary, Cloudflare records information about your users (this cannot be disabled) and, by default, blocks users who attempt to view your site through privacy-enhancing software. I would suggest that people looking to install SSL on their website (this should be everybody) instead get their fre…
So, you're saying that using HTTP instead of HTTPS doesn't increase the privacy of users? I'd say that it does "increase" the privacy, although nobody is saying that it fixes every hole in the boat...
Re: CloudFlare enabling free SSL by mid-October
#36Earlier quoted context omitted.
It would be free, but not necessarily easy, as it would still entail configuring your web server to use SSL, and that might not even be an option if you're using shared hosting. (Aside: self signed certs don't protect the connection from active attacks unless CloudFlare pins the cert. I'm mainly concerned with passive eavesdropping though.)
That's what we're going to do: issue certs that our customers can use on their origins, that will be trusted by our network, and that will be pinned to a particular site. That will allow end-to-end cryptographic connections. There are other groups working on making installing and setting up SSL on origin servers easier, that's not something we're likely to tackle, but agree it's important.
Re: CloudFlare enabling free SSL by mid-October
#37Earlier quoted context omitted.
Yes, it worries me that Cloudflare is proxying an ever larger number of websites I visit. It is not so easy to dump Cloudflare when you need it though. They mitigate DDoS attacks, handle large volume traffic. I think moot even said that he'd have to close 4chan if it wasn't for Cloudflare.
Cloudflare hosts and defends the sites of numerous DDoS-for-pay services and they refuse to take them down. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... "[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage ind…
Re: CloudFlare enabling free SSL by mid-October
#38Most of the websites wont encrypt the link from Cloudflare to the server, ultimately defeating the purpose of SSL aside from a better search ranking.
Re: CloudFlare enabling free SSL by mid-October
#39Earlier quoted context omitted.
Cloudflare hosts and defends the sites of numerous DDoS-for-pay services and they refuse to take them down. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... "[The DDoS-for-pay] industry probably would destroy itself without Cloudflare’s protection, and furthermore ... some might perceive a credibility issue with a company that sells DDoS protection services providing safe haven to an entire cottage ind…
That actually makes me trust them more. If they don't take down a site like that, then whatever site I run is certainly in the clear.