I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.
I have absolutely no reason to think Cloudflare is a covert CIA operation. In fact, I’m sure there are plenty of good reasons to think it isn’t. But if it were, pretty much everything it does is exactly what you'd expect from one.
Is the DHS story not widely known?
Source: https://www.bbc.co.uk/news/business-37348016first thing i thought of. cloudflare is like the most successful widely scaled man in the middle attacker who may or may not be attacking of all time
Of course it's not a CIA operation — that agency is foreign intelligence agency. The domestic intelligence agency is called NSA.
Whether they abide by that is another matter.
https://en.wikipedia.org/wiki/NSA_warrantless_surveillance_(...
Well, you see, Your Honor, when the foreign entities do the spying inside the US, they inevitably become one side in the domestic activities of United States persons. So it's only reasonable to conclude that this part of the Executive Order is null and void.
Well, their operations are (intended to be) foreign... But that hasn't stopped them from selling drugs to American to raise money for their operations.
Also the NSA is a "signals intelligence" agency... Wouldn't the FBI be the local analog to the CIA? Or maybe the DHS?
Well, the problem with that is then you have to deal with the legalities of the USA. What you do instead is have the UK (and a couple other eyes, up to five or eighteen) do the spying on Americans, and in exchange, the Americans will spy on the UK. All perfectly extra-legal.
Two branches from the same trunk with their leaves touching. The boundaries are pure show.
Other than platforming some of the worst people on the web … a lot of the stuff coming out of Cloudflare has been really awesome. No egress fees R2 is top of mind.
The US Gov can just ask, and American corporations will deliver. No need to get their hands dirty.
I may be naive, but they offer a privacy service which adds a hop on the way. They don't control both their server and the third-party, and that is the whole point of the design, right?
How is that exactly what you would expert from a covert government operation?
Do we agree that the design goes through two hops, only one of which is controlled by Cloudflare? And that it is the whole point of the design?
>They don't control both their server and the third-party, and that is the whole point of the design, right?
Yeah I'm not sure what everyone's complaining about. The lack of criticism of anything specific about OHTTP makes me think it's just kneejerk "cloudflare = bad".
> makes me think it's just kneejerk "cloudflare = bad".
I mean, sure. There is that against BigTech all the time, and I understand where it comes from.
What I don't get is that... I don't know, I feel like it should be possible to be against the fact that there are monopolies and criticise them on the one hand, and on the other hand to actually have technical discussions about technical solutions. Here it feels like many comments denigrate Cloudflare without even understanding what the OHTTP gateway does.
For example:
- "Google sucks, they just optimise for profit like all BigTech and that makes it worse for everybody" -> criticises a monopolist entity, all good. No need to be constructive here, it's just sharing a feeling.
- "Android's security model is soooo bad because Android is developed by Google, you should use Linux on mobile it's a lot more secure" -> criticises a technical solution (Android's security model) in a completely uninformed manner, not good.
In other words, BigTech companies "suck" by being BigTech companies, but they do hire brilliant engineers and develop nice stuff (when they don't develop technology to screw us, that is), and I think it would be worth acknowledging that. Cloudflare does contribute a lot of cool stuff open source. One doesn't have to like that Cloudflare is as big as it is, but that's not a reason to say that what they open source is bad software.
You want to say the intelligence agencies are the biggest protectors of piracy (Piracy websites love Cloudflare)?
The way I look at it is more like civil vs criminal.
The more people join in and become dependent on CF, the more incentive there is to subvert CF. Or am I being dumb?
Another thing is the motivation to send people to work for CF. And another thing is the question of preparation vs hope.
Are you, by chance, an operative, sir? :)
I dare say that Cloudflare would represent excellent value for money to the intelligence agencies.
And Google. And Apple. And Microsoft.
Less good value though. Cloudflare is currently 1/20th the valuation and is actively operating as a MITM attack on half of the internet.
Ok, so grant for the moment that it’s both the largest conspiracy ever and the best kept secret ever.
How is anyone worse off using their OHTTP gateway than not using it? Is the idea that CF is this spectacular conspiracy, but nobody thought of capturing traffic from backbones?
Cloudflare Proxy, which is required for their ddos protection - and which as I recall accounts for like half of internet traffic - handles TLS termination at CF servers.
When you capture traffic at internet backbones, which the NSA does (Room 641A), you don't get to middle-man the encrypted traffic. Cloudflare gets access to unencrypted traffic, because they act as the TLS termination.
Most companies take this trade-off because "we can trust cloudflare", or "the data isn't that important, and besides it's encrypted the rest of the way anyway."