Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

41–50 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#41
post #7
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

As we sort of saw with the Twitter Files (and other incidents with foreign governments, eg the Indian government), they can get extremely pedantic about describing the kind of cooperation they have with government agencies.

(Not to point to a conspiracy to silence political opposition, just to highlight that, at least to me, the extent of their cooperation was really surprising relative to how little they talked about it)

Re: CloudFlare’s last Warrant Canary was published over a year ago

#42

Chrome should starting warning users if Cloudflare is used to protect a website, due to the risk of MITM.

Do you want a similar warning on every site that the server might be compromised? Because I don't think that risk is smaller than the CloudFlare MITM risk.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#43
post #34
post #23

Earlier quoted context omitted.

https://en.m.wikipedia.org/wiki/Compelled_speech#:~:text=Pet... .

Why is the commentary of far-right reactionary, who is not a legal expert, commenting on a canadian law, that has nothing to do with warrants, with a citation pointing out that legal experts disagree with him, at all relevant to this conversation?

This forum requires a basic assumption of good faith for posters, especially when it comes to such a trivial mistake like having the wrong anchor section on a link to a short article. It was probably an artifact of their browser trying to be “helpful” when they were copying the link to the full article. Your aggression is unwarranted.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#44

Is there a point to a company as large as Cloudflare even having a warrant canary? Half the internet goes through their servers. Of course the US government had or has hooks in them for something or other.

> Is there a point to a company as large as Cloudflare even having a warrant canary?

There was, is. There likely won't be, going forward.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#45
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

[deleted]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#46
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

Because these agencies are horrifically corrupt beyond any usefulness. These agencies could go after any number of human and drug traffickers and make these problems nearly vanish almost overnight because they collect practically all of our communications. But they don't do that. They are used as targeted political cudgels when its handy and when there is much money to be made.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#47

Chrome should starting warning users if Cloudflare is used to protect a website, due to the risk of MITM.

Do you want a similar warning on every site that the server might be compromised? Because I don't think that risk is smaller than the CloudFlare MITM risk.

I want a similar warning on any provider that is known to routinely MITM and send data unencrypted across the Internet. As far as I know that would only be sites hosted by Cloudflare and sites using certificates issued by the government of Kazakhstan. There's a difference between screwing up (and I wouldn't be against holding companies liable for that) and wilfully setting up a https:// URL that sends your requests unencrypted over the public Internet.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#48
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Why do we have to be pedantic and can't just say when the FBI or CIA come after us?

In the U.S., national security letters (NSL) typically include a nondisclosure requirement:

https://en.wikipedia.org/wiki/National_security_letter>

A warrant canary asserts that no such obligation has been incurred.

https://en.wikipedia.org/wiki/Warrant_canary>

Re: CloudFlare’s last Warrant Canary was published over a year ago

#49
post #35

Earlier quoted context omitted.

Probably the giant “United States” section with dozens of examples?

I do not think that the United States section of that article is valid. It seems to equate speech with communication. It does not feel right to call an IRS tax return "speech".

Speech in this context means an expression of ideas, wether literal speech, or a newspaper article, or...
Post reply on HN