Patching the Internet
blog.jgc.org
blog.jgc.org
An "Edit" button. You can change the content of a page and save your changes for later visits. Optionally: a history of your edits to a page, or a way to share your changes, or see that other people have edited the page, or "subscribe" to changes from certain users. Like turning the web into your private wiki.
An American company can now snoop into https, see all the data and insert random javascript whenever they want? And they can do it for an ever growing segment of the web?
Great. Just great.
I loved the idea of CloudFlare, now not so much. Or am I massively misunderstanding what they are capable of doing?
EDIT: This went further than I meant it to. I think CloudFlare is great. I'm just not sure you should run your SSL stuff through it, this article made me realise how they actually handle SSL.
In addition, if we started doing any of the nasty things the parent suggests (inserting random JavaScript of our choosing or spying on the traffic passing through our network) we'd be out of business. Our entire business rests on the web site owners trusting us with their traffic. That means not doing bad things.
As our CEO likes to say: it takes 5 minutes to sign up for CloudFlare and just 2 to leave.
How can an ISP or mobile install a new certificate onto your computer? I know how companies do it as they send their IT bud round to do it. Or is SSL far less secure than I thought? Totally exposed to MITM attacks?
The SSL decryption is happening all in one massive centralized place. Running through one legal company. Completely under American jurisdiction. The server doesn't have the SSL certificate, CloudFlare does:
http://blog.cloudflare.com/easiest-ssl-ever-now-included-aut...
I'm more than willing to admit being wrong. But I don't see how CloudFlare being able to inspect all SSL traffic between two parties is anything like ISPs and mobile providers having proxies.
And worse the consumer has no reasonable expectation that a third party is even involved. Will all EU startups need to start putting disclaimer clauses in?
I'm not suggest your CEO want's to become the new go to guy for FBI wire tapping, I'm just saying he could be forced to and given the current climate in America it's a bit worrying that everyone's going to CloudFlare if this is the case.
It just seems, well, all a little dangerous. Imagine someone hacking CloudFlare. Wow, they're really becoming a very high value target.
Thousands of businesses don't share the same caching proxy.
I will still probably use it. But it's a little worrying and CloudFlare could suddenly become the source of the internet breaking instead of the cure the jgc's hoping for. Because it's American and they're going a bit crazy atm.
CloudFlare, insomuch as it is encouraging people to use it's platform while is it under the jurisdiction of the American government when that government is demonstrating the behaviors is it demonstrating, is as equally culpable as that government for the type of events which we are currently expressing concern of.
Think of is as an attractive nuisance doctrine[1] for the Internet.
[1]: http://en.wikipedia.org/wiki/Attractive_nuisance_doctrine