> <sigh> and a lot of similar rebuttals to this one.
My point is that a lot of people don't seem to understand the 'why' of this issue and instead appeared to just jump to the conclusion that:
> It's exactly the same difficulty.
When that's not at all the case.
> using JS for client-side probing, and if Cloudflare is indeed injecting arbitrary JS into HTML pages it serves then that's utterly horrifying and is a problem in and of itself.
Well they are. From CF:
>> Cloudflare’s bot products include JavaScript detections via a lightweight, invisible code injection that honors Cloudflare’s strict privacy standards
But even before we consider that, if the request is for html then it's likely coming from a browser. If CF replaces that html with their own then the browser will likely run it allowing them to run all kinds of probes then run the redirect. The same is not true for a .txt file or an image.