Stay Away from Cloudflare (2017)
unixsheikh.com
unixsheikh.com
> In the control panel for DNS setup you have an option called "Firewall", and within that option there is a setting called "Security level".
> By default it is set to "Medium", which means that a lot of people will be blocked from your website by a very annoying and time consuming CAPTCHA. And the problem with this option is that it cannot be disabled in the free service. You actually has to pay for the Enterprise edition, which is more that 200 dollars a month per domain, in order to disable the feature. Even if you set the setting to the lowest available value in the free service, which is Essentially off, many of your visitors will still be blocked.
> Your connection is only really encrypted up until the CloudFlare servers, after that the connection can simply be clear text. The connection is encrypted between the browser and CloudFlare, and between CloudFlare and the website if the website has a SSL certificate, but the communication in-between remains completely visible to CloudFlare.
> It means that sensitive data is being disclosed to CloudFlare without the consent or knowledge of your visitors.
That is a really interesting point.
When you install your SSL certificate on Cloudflare and point your DNS at them, you are essentially installing Cloudflare as a "man in the middle" between your visitors and your server.
Even if you have SSL between Cloudflare's servers and your in-house servers, there is technically still a point where Cloudflare terminates the SSL and can see all the traffic in plain text before they forward it on to your own servers.
That is a lot of trust to be putting in Cloudflare!
To be fair, though, it's just like working with any third party cloud provider. If you host on AWS, for example, you better believe sysadmins at AWS could look at all of your traffic, too, if they wanted to.
So no matter what you do, if you host in the cloud at scale instead of owning your infrastructure, you have to trust third parties.
most cloud providers have not posted that they will actively scan what your visitors read and write to send info to three letter agencies so that men with guns can decide if freedoms you or your visitors have had should continue.
It's even more interesting that the ssl and encryption stuff is so confusing that even tech focused professionals do not know it's possible - just because cloudflare is the dns used.
I guess that really means that the little lock icon in the url bar is a very false sense of whatever for 18% of the web.
recently trying to ban ip blocks from some bad actors, found I can't get their actual ip in my raw access logs. The really bad people just show up as cloudflare ips in the logs.
So I find a cpanel plugin that is to help, but it was once promoted by cloudflare and no longer supported. There is now some command line thing that needs install and some nano/vim to add cloudlfare things into it.. after a few rounds of trying to piece this together I found it much faster/simpler to disable cloudflare.
Besides Cloudflare panel (firewall) also shows IP addresses, And the bad faith actors can be blocked through that via rules. This works in the free version too.
[1]https://support.cloudflare.com/hc/en-us/articles/200170986-H...
How many companies reach this level? 99% of companies will have to rely on a CDN provider for this.
> You'll want to avoid anything HTTP-specific (as it will be prone to the same privacy issues as CloudFlare), and opt for layer 3/4 mitigation only.
Of course your CDN provider will be more effective if it can inspect unencrypted traffic. So, again, either you are at the level of traffic of a big IaaS provider, or like 99% of CDN customers you choose between letting your provider inspect your traffic or not be protected against app-level DDoS.
> Even something relatively simple like ModSecurity will cover a wide array of problems.
Everything is a question of measure. How much is "a wide array of problems"? How much is "some serious connectivity"?
A middle-ground would be using a CDN to protect against L3/L4 volumetric attacks, without TLS interception. And using ModSecurity or another WAF against application-level attacks. But the result will probably not be as good as applicative protection at CDN level, and will cost you more (you pay for the CDN, for your own WAF infrastructure, and for your 24/7 team ready to write new protection rules when a new attack occur).
> The connection is encrypted between the browser and CloudFlare, and between CloudFlare and the website if the website has a SSL certificate, but the communication in-between remains completely visible to CloudFlare.
This critique applies to all content delivery networks. CDNs can't deliver content if they can't see the request and response. That visibility is a problem in certain use cases, but in those cases you simply shouldn't use a CDN.
and
"I don't understand tls termination"
Lots of people don't and that can create a serious problem when someone else is doing it. It's not unreasonable to have it in a cons list.
Also the cloudflare captchas absolutely suck. That's a huge con and you really shouldn't put up with it.
I'm not feeding a fucking robot just to look at a page.
"TOR traffic" is as undesirable as regular traffic, no more no less. From first-world perspective, this maybe skewed towards TOR, but elsewhere TOR is used as everyday, lifeline resource.
From data volume perspective, maybe you are correct. From number of users perspective, I do not believe so.
>If you're running a business that accepts credit cards then it's completely negligent to not block TOR traffic.
Blocking a set of known bad exit relays should be blocked. TOR in general, no.
I like the idea of an open free-for-all Web, too, but I don't expect businesses to stop doing this, given the incentives in play.
In my whole life, I have been hit with maybe 2-3 recaptcha before accessing a website. They probably upgraded the system since then, but still, feels like the author is just pissed without any good reason. (actually I would have expected a mention about google collecting data with this but it's not even mentioned)
Now, for someone who lives in a country where ISPs have a bad rep, this makes part of the web horrible. People are then considered as bad actors by default with no way to improve their experience.
Cloudflare ended up getting listed as authoritative DNS in its own DNS resolver (even though the registrar's records were supposed to be authoritative)
The only reason they couldn't fully steal DNS settings was I had 2FA enabled with my registrars and on my email account
Took nearly 3 days to claim the malicious Cloudflare account via password resets to my actual email address and enable 2FA on it to my authentication tools
Took another week+ to delete all attempted DNS registries and get Cloudflare to not recognize themselves as authoritative DNS resolution for the domains
And over a month for tech "support" and "legal" to finally get around to responding to my complaints basically saying, "you should have created an account with us with that email so no one else could try to steal it"
This sounds like they had your password?
Like, when you are CF big you can't just start resolving domains however you feel because folks use your DNS service.
free markets!
/s
But Cloudflare still let them start making DNS entries
Cloudflare (at least at the time) would let you create an account and start doing stuff without verifying you actually owned the email address
Fat-finger? bob[at]bob[dot]com to bon[dot]com? No worries
Enter my email instead of yours? Go for it
It's just a login...right?