Skip Navigation

The Cloudflare Poison

Daily reminder that sites "protected" by cloudflare are effectively MITM attacks. HTTPS is now even more worthless. Cloudflare can see everything. this is a known fact and not a theory.

And if you think Cloudflare aren't being tapped by the NSA, you're sadly sadly naive.

All the "privacy respecting" sites use it too. So remember, as soon as you see that cloudflare portal page, you can assume that everything you plug into the site is property of NSA Inc. Trust no one, and do not trust code being served to you over the web if it comes through CF, there is no way to know what they've modified.

Edit: good info link below https://serverfault.com/questions/662946/does-cloudflare-know-the-decrypted-content-when-using-a-https-connection

109

You're viewing a single thread.

109 comments
  • So does everyone here that fears Cloudflare as secretly out to get them not believe that the NSA doesn't have their hooks in all the major datacenters? The same datacenters used by all the major web hosts people are using to "self host" for privacy.

    Personally I think you have to have faith at some point that everything from your node to the destination is on the up-and-up unless you have a concrete reason to assume otherwise. Otherwise you should be suspicious of your ISP's network and every switch/router/firewall/node your data traverses on the internet. And being that paranoid basically means anything you didn't review the code of and compile yourself should be out of bounds.

109 comments