How are so many sites OK with using cloudflare when they are basically a MITM? - eviltoast

Regardless of whether or not you provide your own SSL certificates, cloudflare still uses their own between their servers and client browsers. So any SSL encrypted traffic is unencrypted at their end before being re-encrypted with your certificate. How can such an entity be trusted?

  • mrkesu@alien.topB
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 year ago

    People go out of their way to de-Google their phones but them are ok with this situation.

    I don’t think this venn-diagram is a circle.

    • TheQuantumPhysicist@alien.topB
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      Don’t even get me started… I just made a huge comment about the clown-nature of this thought-process.

      I think it all boils down to experience. Some people need time to understand how to make their systems secure (including myself). It took me years of experience to learn how to raise all defenses to ensure security in all my self-hosts.