Damus
Blake profile picture
Blake
@wakoinc
Reminder: Cloudflare is a man in the middle, and decrypts all traffic and re-encrypts it using it’s own certificate.

Sometimes this is ok, for example Nostr events are effectively public, and relays can prevent DDOS. However it’s important to understand that the green certificate saying valid cert and encrypted in browsers does not mean private or 100% secure or true end-to-end without ease dropping.

Their ‘malware detection’ capability is more likely there for dual purpose surveillance. If you mature and roll out systems that mass spy on your population, flipping the switch from passive to active is easy.

If I was the government, I’d pay for a few (secret) contracts.
56❤️4🤙5💯1
Nice and Kind Vic · 135w
This is one key reason why I consider self signed certificates superior to browsers with baked in trusts. There's literally no way that anyone can verify SSL certificates with their bank, online stores, etc.
jascha · 135w
Best to avoid Cloudflare. They are subverting the Internet under the guise of simplifying services for lazy devs.
The Fishcake (nostr.build) · 135w
If you pay enough you get keyless encryption with them, so they never see the inside. As much as I appreciate people bringing this important information to public scrutiny, it’s also important to be balanced and disclose it fully! 🐶🐾🫡 And I am not affiliated with them in any way, just a h...