Regardless of whether or not you provide your own SSL certificates, cloudflare still uses their own between their servers and client browsers. So any SSL encrypted traffic is unencrypted at their end before being re-encrypted with your certificate. How can such an entity be trusted?

  • amunak@alien.topB
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 months ago

    Because it’s “everyone’s MITM” it would make it a perfect spot for state actors to tap into in order to surveil pretty much everything without anyone being able to notice.

    Hell, just the server logs (timestamps, IP addresses and exact URLs) would be unbelievably valuable.

    I’d be really surprised if someone wasn’t taking advantage of that.

    Which is to say if you selfhost because you want more control and privacy, you probably want to avoid services like that.

    • Patient-Tech@alien.topB
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 months ago

      Depends what you’re putting on there. If it’s some blog that’s out there for the world to see, and if you’d like to have more traffic checking it out, then privacy isn’t your goal. Now your personal data, yeah that’s different. I have that stuff segregated.

    • nemec@alien.topB
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 months ago

      If your threat model includes the U.S. government you are in the very, very, very, very, very minority of the population of selfhosters.

    • malastare-@alien.topB
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 months ago

      Hell, just the server logs (timestamps, IP addresses and exact URLs) would be unbelievably valuable.

      People say that, but the actual data would be so vast and with so little actual usability, that the dilution of it still results in largely garbage data. Its only when you have a particular focus and have the ability to filter to that focus that the data becomes very valuable.

      Even banks and card processors, who have direct, legal, and completely open access to data as critical as where every one of their customers spends money struggle to do more than harvest aggregated usage patterns. The idea that data volumes, at a couple more orders of magnitude and notably more generalized will be easily processed and harvested ends up being pretty silly.

      • amunak@alien.topB
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 months ago

        Well yeah, it’s not easy. Which is why they limit what they do to the aggregated data or to targeted discovery.

        But that’s only a small technical hurdle and the speed with which you can analyze the data grows much faster than the volume (especially if you are smart about what data you analyze and how you do it) so it won’t last forever.

    • jared252016@alien.topB
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 months ago

      ThePirateBay, the most notorious site in the world, uses Cloudflare. This isn’t China. Wiretapping is illegal in most circumstances, and that’s essentially what it would be doing.