Live data from Hacker News

CloudFlare’s last Warrant Canary was published over a year ago

cloudflare.com

91–100 of 145 posts

Re: CloudFlare’s last Warrant Canary was published over a year ago

#91

I love cloudflare, but honestly I assumed they WERE the CIA/FBI not just compromised by them. It would be the perfect front company for the government.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

> I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts

CIA/FBI/NSA agreements include immunity from prosecution in the US at least. Your problem would be in foreign jurisdictions only.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#92

Earlier quoted context omitted.

Why wouldn’t they fund the worlds largest MITM attack?

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

It's worse. You can't just start Mitm'ing regular encrypted internet traffic without compromised infrastructure. With Cloudflare everything is already in place.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#93
post #35

Earlier quoted context omitted.

Probably the giant “United States” section with dozens of examples?

I do not think that the United States section of that article is valid. It seems to equate speech with communication. It does not feel right to call an IRS tax return "speech".

US law uses 'speech' that way.

'Expression' would arguably be a better word for it, but the term of art is what it is.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#94

Earlier quoted context omitted.

Morning.

Think you’re supposed to be on vacation.

Time to muster, HackerNews community decided to make a PR event this morning.

Thanks for the comments and clarifications in this thread.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#95

Earlier quoted context omitted.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

Hi, kind of hijacking this conversation but as Cloudflare is unfortunately routing the majority of websites I visit I have to ask this: Can you guarantee my Firefox browser will keep on working on 'the open internet' now Chrome moves towards "Web Environment Integrity" and Safari towards "Private Access Tokens" and Cloudflare is supporting and implementing such technologies on scale? I intent to not participate in th…

Heh, he posted the GP comment and went to bed. Good luck getting a response.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#96

Earlier quoted context omitted.

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

[deleted]

Re: CloudFlare’s last Warrant Canary was published over a year ago

#97
post #18

Earlier quoted context omitted.

> That seems obvious. You would assume, but when the Riseup canary expired plenty of people seemed willing to believe that a procedural issue or carelessness was to blame.

Same with Spideroak.

What happened with SpiderOak?

Re: CloudFlare’s last Warrant Canary was published over a year ago

#98

Earlier quoted context omitted.

Cloudflare is not a MitM attack. By that same logic AWS would be an even bigger MitM attack.

What am I missing? They literally decrypt all the traffic to your website, do some stuff, then re-encrypt and send it on to your server.

Not an attack but certainly a person in the middle.

IAAL and advise on data protection and privacy.

Anecdotally I can tell you that the MitM aspect of Cloudflare and other similar providers is not well understood.

My impression is that a lot of people use these services without really understanding the implications.

For example, when you look at some of the risks that privacy laws are trying to protect against, especially access to data by foreign actors (including government agencies) without due process, use of these types of services changes the game.

Sometimes the benefits might outweigh the risks, but the decision to use these types of services should not be taken trivially.

That said, I routinely use Cloudflare for my personal projects.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#99
post #5

So they got a warrant that they can't talk about. That seems obvious.

Their Canary has more to do with their infrastructure being compromised. It's likely one or more of these statements are no longer true: 1. Cloudflare has never turned over our encryption or authentication keys or our customers' encryption or authentication keys to anyone. 2. Cloudflare has never installed any law enforcement software or equipment anywhere on our network. 3. Cloudflare has never provided any law enfo…

Bear in mind that there are multiple ways for Cloudflare to give law enforcement or intelligence agencies customer information that do not breach one of these six statements.

It doesn’t mean that they are not helpful. Just that - as warrant canaries go - they are not complete.

Re: CloudFlare’s last Warrant Canary was published over a year ago

#100

Earlier quoted context omitted.

These threads amuse me. If adamgamble's speculation were the case, I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts. Suffice it to say, I like not being in jail. It's really, really hard for public companies to be part of some grand conspiracy for so many different reasons. So… once we went public I kind of thought this sil…

> I'd go to jail for things I'd have illegally signed in our SEC disclosures attesting to the sources of our revenue and any government contracts CIA/FBI/NSA agreements include immunity from prosecution in the US at least. Your problem would be in foreign jurisdictions only.

Immunity from prosecution seems like a marvellous way to destroy rule of law. Crazy that that and royal^H^H^H^H^H presidential pardons exist. Recipe for corruption of the state and then the justice system.
Post reply on HN