Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

71–80 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#71
post #19

Remember, Cloudflare CEO/CTO is active on HN. Their lack of reply (if that turns out to be the case) on this post would be telling.

Hmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#72

Earlier quoted context omitted.

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

Does CloudFlare proxy your website without your permission?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#73

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me.

If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this silly speculation would end. But guess not.

Beyond that, if you think about it, it's a way better business to run Cloudflare and serve the world than serve some US intelligence entity. That's just per se true. So if that's the case why would we ever do anything that would remotely compromise the trust necessary to, you know, be Cloudflare?

Lastly, here's a funny story. Early in our history one of our investors suggested that we talk to In-Q-Tel. Here's how naive Michelle and I were: we had no idea it was the CIA's venture capital arm. So we showed up in their office on Sand Hill Road. It was weirdly austere compared with other VCs we'd visited. And lots of security cameras. The partner at some point came out and greeted us. As he was walking us back he looked back right before we crossed the threshold back to the inner offices, "You're both American citizens, right?"

"No," Michelle said. "I'm Canadian."

"Oh." the VC said. Then you can't come back here.”

"I'm not going back there without her," I said.

"Ok, well, I guess we'll have to do the meeting in the reception area," decided the In-Q-Tel VC.

We had a very cordial meeting and then left. As we were driving away Michelle said, "Those guys were weird." And that was the end of that. Never talked to In-Q-Tel again.

But maybe it's the Canadian equivalent of the CIA/FBI/NSA we're beholden to??! ;-)

Re: CloudFlare’s last Warrant Canary was published over a year ago

#74
post #19

Remember, Cloudflare CEO/CTO is active on HN. Their lack of reply (if that turns out to be the case) on this post would be telling.

Hmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.

Sorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#75
post #5

So they got a warrant that they can't talk about. That seems obvious.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

I'll state right here: all these are still true. We'll get the canary updated. Checking with legal and trust & safety why it hasn't been for so long. Likely just slipped someone's mind. Will make sure that doesn't happen again.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#76
post #10
post #7

Earlier quoted context omitted.

I wonder how pedantic you could legally get with that. Cloudflare has never been compelled to give up information to an agency called AAA. Cloudflare has never been compelled to give up information to an agency called AAB. ...etc.

Suuuuper pedantic. For instance, 2 and 3 narrowly specify just law enforcement agencies, of which the CIA and NSA are not.

I think we'd consider them "law enforcement agencies." But, for the sake of complete clarity, I'm happy to say that we haven't done any of these for the CiA or NSA or any non-US equivalent.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#77
post #8
post #5

Earlier quoted context omitted.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

#5 seems most likely.

Agree #5 is the riskiest right now with the Quad9 decision in Germany and some of the cases we're facing in Italy, Austria, and elsewhere. The copyright industry has decided that DNS is their new target; never mind that anyone can setup their own local DNS resolver. Good news: those are extremely public cases. And, if we lose, we'll make a lot of news about how dangerous they are. If you're in Europe, it'd be really helpful for more people to be telling the courts and legislatures: DNS is not the right place to try and censor the Internet.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#78

Is there a point to a company as large as Cloudflare even having a warrant canary? Half the internet goes through their servers. Of course the US government had or has hooks in them for something or other.

No they don't.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#79
post #51

So what's stopping these people that claim to be so righteous by using canaries from lying to you? Anyhow the ISPs and internet backbones are all tapped as many whistle-blowers have already revealed.

Nothing is stopping them from lying. Signaling that their infrastructure has been compromised is kind of a weird lie for them to make though...

The SEC could throw me in jail. And, sure, you could believe that the FBI or whoever could tell the SEC what to do. We have European and Asian investors too, so their financial regulators could also sue me personally for lying. Perhaps the FBI/CIA/NSA control them too? Gets tricky to believe: the bigger the conspiracy the faster it falls apart. It's really, really hard to be part of some grand conspiracy as a public company.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#80

Earlier quoted context omitted.

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

And AWS has control of all of your servers and everything stored on them. If it's part of your systems architecture and how it's intended to work it isn't being attacked.

>They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

That doesn't mean they are an attack. That is just how a CDN works.

Post reply on HN