I've used the full ssl mode on self hosted servers and can't see what the dilemma is besides you being paranoid that Cloudflare will tamper with data passing through them. Evidence?
I've used the full ssl mode on self hosted servers and can't see what the dilemma is besides you being paranoid that Cloudflare will tamper with data passing through them. Evidence?
That's not quite true. The sensitive data that is getting passed around in this case isn't your articles, but who is reading them.
> besides you being paranoid that Cloudflare will tamper with data passing through them. Evidence?
Why would this require evidence? It's a threat, plain and simple. Threat modeling isn't based on evidence, it's based on assuming the worst-case realistic scenario, because overestimating is less harmful than underestimating.
Why would you sit and wait for something to go wrong, when you could close a potential security problem now?