Because they're literally MITM-as-a-service. I wish I was exaggerating.
Seriously. If a website uses Cloudflare, Cloudflare can see everything you do on that website. Stuff you say. What pages you go to and what you're looking at. Any passwords you type in. Everything.
(And your browser doesn't warn you about that because Cloudflare has a legit cert for the site; as far as your browser is concerned they ARE the site.)
Every single CDN provider works this way, and the internet as we know it wouldn’t work without them. If you don’t like that Cloudflare works this way then you should be upset at Amazon, Akamai, Google, Fastly, and many others as well.
The thing is, every CDN provider does the exact same thing, and the modern internet wouldn’t work without them. Cloudflare gets a bad rap largely because they offer free and low cost services that are very attractive to individuals, hobbiests, etc.
Companies like Akamai, Fastly, AWS, etc. offer virtually identical services but you may never have heard of them because they mostly only offer services to corporate customers. But their CDNs operate the same way - by decoding the traffic so they can analyze it for purposes of caching it to speed up delivery.
Edit: Love how my comments are being downvoted. What I’ve said here is 100% accurate and true. I used to work at Akamai, and still work with it on a daily basis at my current employer so I have a lot of knowledge of the platform. If you think what I’m saying isn’t accurate then just say so.
Yeah it's... DEFINITELY a thing you should know, and definitely a thing they don't want you to know, because they want you to not even know they're there!
At least with normal trackers that embed JS on the page, like Google, which can also snoop on basically everything you do by the way, if you block the tracker you're relatively safe (until they change the tracker, until you get an updated filter list... it's a constant back and forth).
You can't block Cloudflare MITMing you. ("man-in-the-middle", they pretend to be the server and pass on everything you say to the server and the server's response to you, while probably writing down everything for their own purposes. this is a large part of what HTTPS was explicitly intended to protect against...)
Because they're literally MITM-as-a-service. I wish I was exaggerating.
Seriously. If a website uses Cloudflare, Cloudflare can see everything you do on that website. Stuff you say. What pages you go to and what you're looking at. Any passwords you type in. Everything.
(And your browser doesn't warn you about that because Cloudflare has a legit cert for the site; as far as your browser is concerned they ARE the site.)
-- Frost
Every single CDN provider works this way, and the internet as we know it wouldn’t work without them. If you don’t like that Cloudflare works this way then you should be upset at Amazon, Akamai, Google, Fastly, and many others as well.
Um, no they don't. They typically provide a third party domain the website includes stuff from.
Cloudflare also does that, but it's not the issue here.
-- Frost
Wow, thanks. I didn't know. Get my upvote! Honestly, this is the best reply on this post.
The thing is, every CDN provider does the exact same thing, and the modern internet wouldn’t work without them. Cloudflare gets a bad rap largely because they offer free and low cost services that are very attractive to individuals, hobbiests, etc.
Companies like Akamai, Fastly, AWS, etc. offer virtually identical services but you may never have heard of them because they mostly only offer services to corporate customers. But their CDNs operate the same way - by decoding the traffic so they can analyze it for purposes of caching it to speed up delivery.
Edit: Love how my comments are being downvoted. What I’ve said here is 100% accurate and true. I used to work at Akamai, and still work with it on a daily basis at my current employer so I have a lot of knowledge of the platform. If you think what I’m saying isn’t accurate then just say so.
Yeah it's... DEFINITELY a thing you should know, and definitely a thing they don't want you to know, because they want you to not even know they're there!
At least with normal trackers that embed JS on the page, like Google, which can also snoop on basically everything you do by the way, if you block the tracker you're relatively safe (until they change the tracker, until you get an updated filter list... it's a constant back and forth).
You can't block Cloudflare MITMing you. ("man-in-the-middle", they pretend to be the server and pass on everything you say to the server and the server's response to you, while probably writing down everything for their own purposes. this is a large part of what HTTPS was explicitly intended to protect against...)
This very much. They are probably the largest private worldwide vigilance operation ever to exist.
Unfortunately they provide services that are very valuable to some organisations, so they get away with it.