this post was submitted on 20 Dec 2023
11 points (82.4% liked)

Privacy

1098 readers
1 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 1 year ago
MODERATORS
11
submitted 8 months ago* (last edited 8 months ago) by [email protected] to c/[email protected]
 

cross-posted from: https://links.hackliberty.org/post/609883

This BBC interview has a #Cloudflare rep David Bellson who describes CF’s observations on internet traffic. CF tracks for example the popularity of Facebook vs. Tiktok. Neither of those services are Cloudflared, so how is CF tracking this? Apparently they are snooping on traffic that traverses their servers to record what people are talking about. Or is there a more legit way Cloudflare could be monitoring this activity?

top 6 comments
sorted by: hot top controversial new old
[–] [email protected] 10 points 8 months ago

They run a lot of servers that handle traffic and DNS, as well. If someone looks up FB.com, they almost certainly aren't just going to stare at the IP address, but go to the site.

Basically... They're just reading addresses on the envelopes, not opening them up.

[–] [email protected] 8 points 8 months ago (1 children)

Oh, it's a podcast. Does anyone have a summary/transcript?

[–] [email protected] 4 points 8 months ago

Sorry I do not know if BBC interviews are transcribed.

But FWIW it will air again on BBC World Service at 02:32 GMT tomorrow and the next day (which could be useful for those on limited internet connections)

[–] [email protected] 2 points 8 months ago (1 children)

They are basically MITM (man-in-the-middle) attack all the traffic that passes through their servers. Most Cloudflare defenders will tell you it's not technically MITM as the site operators gives them permission to do that, but the end result is the same.

Even though sites are encrypted, they hold the decryption key, so they can see all traffic in plain text.

[–] [email protected] 2 points 8 months ago

I agree.

One of the reasons no one gives a shit is there is never news about CF making use of that MitM position. But I know they hire data scientists and what corp can resist the urge to monetize data they have access to? So I think it’s just a matter of time before they get caught abusing the vast amount of valuable data they have visibility on.

[–] [email protected] 1 points 4 months ago

It’s a dns… aren’t they just reporting how many dns look ups they get for Facebook vs TikTok?