▲ 97 ▼ Am I wrong for blocking the Cloudflare domain because I assume they are gathering as much as google? (lemmy.dbzer0.com) submitted 4 months ago by ScoffingLizard@lemmy.dbzer0.com to c/privacy@lemmy.ml 63 comments fedilink hide all child comments
[–] bjoern_tantau@swg-empire.de 3 points 4 months ago (1 child) How can they act as a proxy if they can't terminate the connection? Or what service does that offer? I guess they could filter out some connections based on IP addresses. But is that enough for some customers? Or am I overlooking something? permalink fedilink source parent hideshow 2 child comments replies: [–] chicken@lemmy.dbzer0.com 4 points 4 months ago* (last edited 4 months ago) (2 children) How can they act as a proxy if they can’t terminate the connection? Why wouldn't they be able to? The DNS record points to Cloudflare's IP, they forward the traffic to your server's IP. This is a common choice for self hosting setups because it's a free service and it is a way to avoid pointing a DNS record at your home IP, which you may not want everyone to know. That doesn't require decrypting the traffic. How this squares with the ddos protection and caching stuff, I'm not sure, but I know I set up SSL locally, did not give Cloudflare the keys, turned off all the options for them to handle it, and everything seems to work. permalink fedilink source parent hideshow 4 child comments replies: [–] bjoern_tantau@swg-empire.de 2 points 4 months ago Thanks! I hadn't considered just wanting to hide your own IP. permalink fedilink source parent [+] Lee@retrolemmy.com 1 point 4 months ago [deleted] permalink fedilink source parent
[–] chicken@lemmy.dbzer0.com 4 points 4 months ago* (last edited 4 months ago) (2 children) How can they act as a proxy if they can’t terminate the connection? Why wouldn't they be able to? The DNS record points to Cloudflare's IP, they forward the traffic to your server's IP. This is a common choice for self hosting setups because it's a free service and it is a way to avoid pointing a DNS record at your home IP, which you may not want everyone to know. That doesn't require decrypting the traffic. How this squares with the ddos protection and caching stuff, I'm not sure, but I know I set up SSL locally, did not give Cloudflare the keys, turned off all the options for them to handle it, and everything seems to work. permalink fedilink source parent hideshow 4 child comments replies: [–] bjoern_tantau@swg-empire.de 2 points 4 months ago Thanks! I hadn't considered just wanting to hide your own IP. permalink fedilink source parent [+] Lee@retrolemmy.com 1 point 4 months ago [deleted] permalink fedilink source parent
[–] bjoern_tantau@swg-empire.de 2 points 4 months ago Thanks! I hadn't considered just wanting to hide your own IP. permalink fedilink source parent