Seriously, why do so few people worry about the big ass proxy that is cloudflare? they can, literally...

seriously, why do so few people worry about the big ass proxy that is cloudflare? they can, literally, get all your credentials, track you from site to site, see and potentially store everything you upload and post
same for similar services, btw.
big corporations are a threat to the internet, but journalists only care about the most visible ones

Attached: What is Cloudflare_v7.png (702x482, 75K)

Other urls found in this thread:

github.com/iamcryptoki/snowden-archive
new.blog.cloudflare.com/terminating-service-for-8(chan)/
poynter.org/reporting-editing/2015/defying-critics-to-publish-the-unabomber-manifesto/
en.wikipedia.org/wiki/Nothing_to_hide_argument
twitter.com/NSFWRedditVideo

What are you hiding that makes you so worried?

welcome to the Internet, newfriend

they even offer "security" features (SSL) that gives users a false sense of security, but in reality, they can literally see everything. and if an attacker compromises their shit, we are absolutely fucked.

I prefer a specific type of porn and I don't want to be tracked

i thought it was cool when it was new, because it made it very easy to improve a websites availability without doing your own load balancing and traffic filtering and such. Now it has taken over, and that's always a problem

>why do so few people worry
They are given a lot to worry about, so they don't have time for petty things like dystopia tier surveillance.

they are awesome in a technical sense, just like google or any other high tech company has been at some point in its life.
but we should NOT EVER FORGET that tech stuff and security and privacy and freedom of speech are SEPARATE THINGS.

- credentials and generaly information of my bank accounts and similar things
- personal stuff that I post in supposedly private and/or anonymous websites that I visit, that use proxy services like cloudflare
- metadata about websites I browse, habits
and so on
how about you?

>website gets collectively shut down by free market for hosting a mass murderer's manifesto and allowing him to be radicalized. TWICE
Sorry, whats the problem again?

who the fuck is even talking about eight-chan here?

also
>muh free market
do you really think they didn't get some money from the US government in return of favors? kek

Cause its the only reason to bring up cloudflair being a threat
>conspirad theory

>>conspirad theory
>Cloudflare's business model is to be a Man-In-The-Middle for every DNS Query and every HTTP Transaction. This makes it very suspicious and makes me think of Cloudflare as providing NSA or other security agencies access to the data and logs they collect.

HOW? No matter how secure your cloudflare based website is for the entire world, at cloudflare datacenters its all Naked. All the encryption and protection ends there and data is re-encrypted before sending to the origin servers/users. So, you are fully secured from 3rd parties, but fully naked for them. Security Agencies know this.

So, I would say, it is VERY LIKELY that either Cloudflare is an NSA project, or it is actively providing data to NSA or other agencies.

Look at the cloudflare products, and decide for yourself:

> Free Secure 1.1.1.1 “DNS Directory”.
> Free DNS, with DNS over HTTPS.
> Free CDN.
> Free SSL certificates (SSL terminates at their data centers. They can see you.)
> Zero-Margin Domain Registrar, means bigger piece of the DNS cake.

For all the above security related offerings... you are being protected from the entire world, but at cloudflare datacenters everything is being decrypted and visible.

Considering the above points, Cloudflare can make it easy for agencies to do the surveillance at massive scale while at the same time preventing other country governments to do the same because of “Everything-Single-Thing-Over-Encrypted-Connection”.

Pic related.

Attached: prism-slide-4.jpg (700x525, 70K)

Let's not forget...

Attached: goog.png (1484x1113, 968K)

Go ahead and post your name and full browser history, retard.

Attached: 1.png (930x2982, 680K)

these came from github.com/iamcryptoki/snowden-archive

Attached: 2.png (924x2538, 539K)

Attached: 3.png (936x2124, 377K)

:^)

ITT: no reading comprehension and strawmen

bump

because everyone thinks it doesn't matter because they won't target them.
which in most cases will be true but if it turns out to be wrong, no one will come to their aid because everyone else also thinks they won't be targeted

my private life. if you don't care about stuff like that, go to /soc/ right now and upload a picture of yourself, your browsing history and your full name and address. after all, you have nothing to hide, right?

I wish rabulism was a banable offense.

Everything. Nobody is entitled to any of my data.

>hosting a mass murderer's manifesto and allowing him to be radicalized. TWICE
Okay, two people out of the entire 8ch userbase. Statistically less than marginal, yet blown out of any proportion. It's sad that people died but both murderers were apprehended, case closed.

>because everyone thinks it doesn't matter because they won't target them.
Nobody on Jow Forums hasn't fantasised about needing to roll their own infrastructure from scratch.

why do you guys always have to nitpick. obviously I don't mean literally everyone on this planet, I'm just too lazy to always list the few exceptions that exist.

I would be more worried that the majority of website hosts are totally okay giving the monopoly for that market to Cloudflare. They have so much power on the internet. If people manage to fuck up cloudflare that also means they take down a good portion of the web, which is also something to be concerned about.

Why hasn't the hacker culture done something about this? Surely this is probably something to be extremely paranoid about for the future of the internet.

Attached: 1457911811183.png (1200x796, 596K)

>Why hasn't the hacker culture done something about this?
Stuff like DDOS protection is basically impossible to do on a small scale. Cloudflares whole business model only works because they're huge.

My nudes, the NSA wants them.

Is there a way to know without much research if a website uses cloudflare?

>All the encryption and protection ends there and data is re-encrypted before sending to the origin servers/users.
What is the official or technical reason for the decryption on their servers in the first place?

Okay, so what's the solution then? If you don't use cloudflare (or equivalent) you get DDoS'd

>What is the official or technical reason for the decryption on their servers in the first place?
Because the whole point is to cache content. But to cache it, it needs to be cleartext, because you can't cache what looks like random data.

I'm pretty sure it's now basically a CIA honeypot. Even if it did not start as one, now that more than 50% of the web traffic goes through it, all it took was a bit of cash and a few moles to own it.

Yeah but
>my feelings, you bigot, are the **REAL VICTIMS**

Thanks, makes sense!

$ nslookup some-domain.com
then, with the IP you get, you can run
$ whois $IP | grep -i cloudflare
and it'll tell you if it's using CF or not

also check the SSL certificates

The cloudflare ceo openly said in an interview in the last day or two that part of the reason he was conflicted about cutting off 8ch was that law enforcement would lose the data they were providing them about posters

>but journalists only care about
Money. That is all they care about. To make money they only report on things that make them money. Such as things that lobbyist pay them to report on or things that gain them ad revenue.

Identity theft is a massive problem and getting worse. the more companies who have access to your private data the larger that threat is to you.

That is all the reason anyone needs for privacy.

I guess everyone's already forgotten about the massive Cloudflare leak couple of years ago that caused hundreds of thousands of user accounts on numerous sites to be compromised. That should've been a huge warning sign of what can happen when shit is centralized like this.

Attached: 1504701737442.png (1600x1600, 1.66M)

Do you have a source on that?

new.blog.cloudflare.com/terminating-service-for-8(chan)/

take out the ()

>meanwhile you can host the quran and the bible just fine
Retarded AF.

>website gets collectively shut down by free market for hosting a mass murderer's manifesto
not illegal, and actively done all the time. Major newspapers are happy to promote and publish manifestos that encourage violence at the behest of active killers

poynter.org/reporting-editing/2015/defying-critics-to-publish-the-unabomber-manifesto/

Who did publish the unabomber manifesto again?

>unaboomer
you mean luke smith?

Comparing apples to oranges. The unabomber manifesto was published while the terrorist was still active in hopes that it would help identify him, which worked successfully. That is not what is happening here at all.

>journalists only care about the most visible ones
Journalists only care about incels.

its either that or buzzfeed titles

It could not be more similar. Also the shooter recently just uploaded the fuckign file as an user. Anyone could do that on any site, it's not like 8ch decided to publish it

8ch legally did nothing wrong

No it's not even remotely the same. I urge you to research more about why the unabomber manifesto was published, it was not a decision that was made lightly and all the risks were considered. 8ch has done nothing of the sort, they actively welcome terrorist killers without any kind of thought and no matter the reason.

You don't think a newspaper making the conscious decision to publish a 35,000 word manifesto for an active bomber on the loose has similarities regarding legal responsibility to some guy dumping a file on 8ch and that because he dumped the file on 8ch and not dropbox or mega or something 8ch should be shut down for all time and violated the law somehow

ok bro, your opinion is noted and will be given the consideration it deserves

No it's not anywhere close to being the same. I told you, go research why the decision was made to publish it.

Another user here and I researched the story and I tell you what the NYT did was much worse. They have millions of reader worldwide.

You are ignoring the entire context under which it was done for the sake of your poorly-constructed argument.

I am not ignoring anything. I know they did it save more victims and maybe get the bomber. But the motives don't compensate a bad deed. And because of the massive reach of the NYT it was compared to 8-chan a much worse deed, even if you believe they had 'pure' motives. I between believe that 8-chan has pure motives as a forum of freedom as well. But you won't understand this anyways because you think that only your opinions are morally right.

No I understand it and it would not say it was a bad deed because they DID get the bomber as a result. 8ch is not doing good deeds, it's a terrorist recruitment site at this point, all the other boards there are eclipsed by Jow Forums and /leftypol/

This. I'd love if it were possible to get the same features without cloudflare, but it just ain't economical.

some guy uploaded a small file onto 8ch how is that their fault? is it facebook's fault when that aus guy streamed the killing live?

the fuck are you even talking about? do you know how an image board works? Did you know anons can upload files and text without the owners reviewing them first?

remember, if it’s not a mainstream social media site, it’s a “terrorist weird hangout full of hackers” even though the media LOVES to spread hate.

>Nothing to fear if you have nothing to hide
en.wikipedia.org/wiki/Nothing_to_hide_argument

Whats the FOSS scalable alternative to CF?

say that to my face fucker not online and see what happens

>some guy uploaded a small file onto 8ch how is that their fault
The mods did nothing and encouraged this kind of content.
>is it facebook's fault when that aus guy streamed the killing live
Yes
>The media that I hate so much does it therefore I should do it too
Retard

>The mods did nothing and encouraged this kind of content.
they absolutely did not, get fucked