Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

81–90 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#82

Earlier quoted context omitted.

Hmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.

Sorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.

[dead]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#83
What is the language around the non-disclosure order? There seems to be speculation that a warrant canary would be construed the same as a disclosure, but are you required to not inform the concerned party, or required to not disclose law enforcement contacting you at all?

From a practical perspective I don't imagine that cloudflare removing a canary could give any one organization a signal - I don't know what the bar for a 'disclosure' is but informally I would not consider it a targeted specific warning.

EDIT: the other component I am curious about is duration, there is still utility in the canary even if it comes late, future users will know that there was a compromise and that further ones are likely, right?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#84

Earlier quoted context omitted.

Hmm. Don't think that's intentional. Will ping legal and policy team and make sure they get a heartbeat published ASAP.

Sorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.

Morning.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#85

Earlier quoted context omitted.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

Does CloudFlare proxy your website without your permission?

You're being needlessly pedantic. It might not be an attack in the usual sense, but it's a MITM "access point" and agencies like CIA/NSA/FBI would definitely have that kind of access. This access transforms Cloudflare's role into a de facto MITM "attack" on their customers and end users who didn't intend to share unencrypted data with 3-letter agencies.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#86

Earlier quoted context omitted.

Sorry for the delay. I was writing our Q2 earnings script rather than checking HN. And John (CTO) is in Lisbon where he's probably just waking up. Also: he's on vacation this week.

Morning.

Think you’re supposed to be on vacation.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#87

Earlier quoted context omitted.

Why wouldn’t they fund the worlds largest MITM attack?

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

> By that same logic AWS would be an even bigger MitM attack.

Amazon HQ2, Arlington Virginia: https://en.wikipedia.org/wiki/Amazon_HQ2

Re: CloudFlare’s last Warrant Canary was published over a year ago

#88

Earlier quoted context omitted.

Why wouldn’t they fund the worlds largest MITM attack?

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

By that same logic, it would not be surprising to discover AWS working with the feds either.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#89

Earlier quoted context omitted.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

Does CloudFlare proxy your website without your permission?

It doesn't, but it does proxy my connections to several websites without my me having a chance to say no - in fact, without even telling me.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#90

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

Hi, kind of hijacking this conversation but as Cloudflare is unfortunately routing the majority of websites I visit I have to ask this:

Can you guarantee my Firefox browser will keep on working on 'the open internet' now Chrome moves towards "Web Environment Integrity" and Safari towards "Private Access Tokens" and Cloudflare is supporting and implementing such technologies on scale?

I intent to not participate in these DRM APIs with my Firefox browser and would like to keep browsing the internet.

Post reply on HN