Securing Infrastructure at Scale with Cloudflare Access
blog.cloudflare.com
blog.cloudflare.com
Is anyone here using this Cloudflare feature in production?
What has your experience been?
My only complaint is the security of it is not perfect. When you launch the tunnel, you declare the domain you want it to use. I can be any domain on the account and can't limit it to specific domains. It's a little dangerous if you have sensitive domains on your Cloudflare account that you don't want to use Argo.
>What I don't like about this is that (as fas as I know) it would require sending all of our traffic over Cloudflare and let them decrypt it.
Isn't that what a VPN is?
Since we can encrypt HTTP traffic using TLS between the client as well as the proxy and the destination the security should not be much worse than a VPN (though TLS leaks slightly more metadata as far as I know).
What I don't like about Cloudflare's solution is that I have to trust them with my traffic, as they decrypt and re-encrypt it in transit. I'd rather have that done by a server that's under my control.
(I've been told by other founders and investors that I should pretend this was an "exit" for "optics", but I'm really bad at lying...)
It also depends, are companies selecting software freedom. At those companies, they control their own data on their own servers, and have their own company developers contributing to Open Source they use, or sponsor Open Source project developers. So when size of company grows, there is no license cost per user licenses.
Propietary companies just keep buying propietary software, and then wonder why they are locked in.
It seems to work similarly to this but you run it yourself so it doesn't need to tunnel traffic through cloudflare, and it's open source.
This feels a lot like mid-2000s all over again (hey we have this new idea it's <insert SaaS-rehash of existing services>)