Cloudflare automatically fixes Polyfill.io for free sites
blog.cloudflare.com
blog.cloudflare.com
At the same time, there is a wrongness in Cloudflare being able to overwrite content and changing the 'truth'. I'm like that larry david gif, I just don't know how to process this.
One more thing to note, if you go to the polyfill repo, they've also mentioned they're using Cloudflare to distribute the library.
https://github.com/polyfillpolyfill/polyfill-service/commit/...
This is one of the many features of Clouldflare though, that you can enable additional features that modify your website in various ways - whether it's image resizing or analytics or security scanning.
If you don't trust Cloudflare to deliver your website, then you shouldn't use Cloudflare.
Of course this is all just philosophical anyway. We’ve not even touched on external module usage.
[1] https://blog.ipv6.rs/understanding-tls-mitm-and-privacy-poli...
The one exception is Cloudflare turning this on by default for free 'customers', but hey, if you're not paying really what leg do you have to stand on?
Probably a good idea to not claim affiliation with cloudflare without permission.
This is sort of exactly what cloudflare does, though. They host your content on their servers. They're serving a mirror of the original files from polyfill.io and browsers are getting the same original bytes. If it's a fact that pulling content from polyfill.io is a security issue, why wouldn't you want them to do this? The "truth" as you describe is a third party that you don't trust (who acquired a service you use from the original provider). The status quo is inherently bad. "We served your page for you, but without the injected code and with full compatibility" feels like an awfully nice thing for Cloudflare to do that they simply didn't need to do.
Cloudflare is all about changing the "truth". When your site is behind Cloudflare, they block many requests to your site. The lock in the browser can be lies. Cloudflare is decrypting that content - and if the site owner hasn't setup TLS between Cloudflare and the backend, it's being re-transmitted over the internet unencrypted. On paid plans, Cloudflare will compress images and swap in their version. Cloudflare will compress an uncompressed response before returning it. Cloudflare will take the HTML returned by your backend and obfuscate any email addresses in that HTML before sending it along to the browser.
Your server returns a page with evil-polyfill/bad.js and Cloudflare inspects the HTML and rewrites it to say good-polyfill/good.js
You might not want this behavior and you can shut it off in Cloudflare, but it seems like a reasonable default given that customers have signed up for a product meant to protect them against attacks. Cloudflare has never been about passing back the raw HTML it receives from the backend or passing along the raw requests it receives from browsers.
Is it “shots fired” situation?
Because you know bullies and other bad people start testing ground to see what they can get away with. That is why you slap them hard and quick on the first attempt right away so they see that they cannot fool around.
So I am asking can it be we have to say - well yeah technically they are right - but stop right there doing that and never do it again!
They could make terms that they don’t serve vulnerable things from their cache and it is up for the customer to update or fix it - but they shouldn’t overwrite stuff, period.
If you don't trust Cloudflare to not abuse this to inject ads, stop using Cloudflare.
If they serve ads on their captcha or some redirect I'd say well it is not nice - but for me fundamental difference is messing with my content even in a good faith - send me a notification an email or stop serving my content if it is active malware but don't change it.
when does cloudflare starts to inject ads into my content
You content, as in, you the developer who is making a website, and has set up Cloudflare in front of your website? Presumably they wouldn't inject ads into your website, or else you'd stop using Cloudflare: just change the nameservers in DNS to point to someone else.
But worrying about ad injection off the back of a legit good-guy action seems like an overreaction. They've always been able to alter the websites they serve. They do frequently to optimise and this seems like a very benign extension of that.
Don't get wet before it rains.
Cloudflare shouldn't have such a control over a part so big of the internet.
But since they do, they are right to use this control against malware.
Relevant today as ever given that the Supreme Court ruled that the 1A challenge to the executive branch asking big tech to censor doesn’t have standing to be ruled on.
Google has a big red button that can shut down any webpage on the internet for 99.9%+ of the web browsing public. There’s no bypass button in the UI like a TLS failure.
Didnt his friend from work own and sell it?
I get that they want to do a good thing, but is this something you agree to when you sign up as a Cloudflare customer? If so, that’s kind of crazy.
edit: I am talking about both free and paid users. A toggle does not discount my question whatsoever, especially if this is on by default for free users. I am asking specifically about terms of service.
The article says that if you are a paying customer this is off by default.
It does show that you have to trust cloudflare, which seems like a safe bet given their desire to keep the internet secure.
This is assuming that Cloudflare's interests will now and always align with your own interests, and that their desire to "keep the internet secure" will never lead to them actually screwing over you and your customers.
It's a lot like many classic AI Sci-Fi stories. If their mission ever comes into conflict with your real interests, a mission statement that sounds perfect in theory can suddenly become very very dangerous.
If you don't assume this, why are you using Cloudflare?
This is literally the tradeoff of using any SaaS/PaaS/IaaS vendor. Every single one. It's not unique to cloudflare in any way.
https://blog.cloudflare.com/polyfill-io-now-available-on-cdn...
In the earlier thread, there was a link to triblondon's post on 2024-02-25 where he urges users to remove that dependency:
https://x.com/triblondon/status/1761852117579427975
Unfortunately, neither of these early warnings seem to have gotten much attention. I wonder if there is some news site or service that would make suspicious ownership transfers of this sort more noticeable? Or maybe this type of supply chain changes actually happen all the time and we just got used to them?
Is this normal operating behaviour for Cloudflare? This seems like very very bad anti-consumer behaviour?
Doesn’t seem to make a lot of sense, does it?
If you're at that level of scrutiny, that's not a service for you in the first place.
But then again, if the people who carelessly include 3rd party dependencies (i.e. playing with fire) are those who use CF... they probably won't object to it :-)
Some grim future who knows if cloudflare will be the ones under new owners re-writing payloads to serve adverts (or worse).
edit: I think my comment is being misunderstood, I'm not saying this will happen, there's just a neat symmetry between exploit and mitigation.
In any case it's extremely unlikely to happen any time soon, but who knows what could happen 50 years down the line, especially if they were to lose market share or the internet fades from relevance.
I'm not accusing cloudflare of anything malicious, I want to be clear. But this polyfill wasn't originally malicious either, it was just eventually bought by a malicious actor.
My original comment was just commentary on the symmetry of the exploit and the mitigation, they're essentially the same vector.
uBlock origin blocks Polyfill.io https://news.ycombinator.com/item?id=40802393
Polyfill supply chain attack: https://news.ycombinator.com/item?id=40791829
The good news is that a (strict) CSP can help with that - and they do mention it in their blog post that they don't rewrite anything if there's a CSP header.
It's also worth noting that a (strict) CSP also prevents them from injecting their analytics JS from being injected to your site.
The warning signs should have been obvious. There's no profit to be had in this kind of free CDN.
Nobody paid this OSS person - only when there is a problem do we ’accuse’ OSS maintainers not when they were actually doing their job for free.
Even if a maintainer slaps on a, “I do what I want with this project. I am not responsible for any damages. There is no support” disclaimer, I am not sure that necessarily removes some social responsibilities.
In this case the service is "push", which is very different. Any website that used polyfill.io can have any changes pushed to it, regardless of if the author even had known about a change being made.
If my popular project is replaced with a single poop emoji on NPM any existing user is fine (especially since NPM keeps old versions after the whole left-pad thing) and will find an alternative. If polyfill.io replaces their code with
document.documentElement.innerHTML = '💩'
that's not fine, since it affects existing users without any update step.I think that nobody should use these public CDNs at all, including things like unpkg and cdnjs, or at the very least using subresource integrity. Either way this has been something that has been on the horizon for years and similar to the buying of popular webextensions.
---
Comic Book Guy : Last night's Itchy & Scratchy was, without a doubt, the worst episode ever. Rest assured that I was on internet within minutes registering my disgust throughout the world.
Bart Simpson : Hey, I know it wasn't great, but what right do you have to complain?
Comic Book Guy : As a loyal viewer, I feel they owe me.
Bart Simpson : What? They've given you thousands of hours of entertainment for free. What could they possibly owe you? I mean, if anything, you owe them.
Comic Book Guy : Worst episode ever.
If he simply made the DNS not resolve to a server anymore I'd be fine with it (and if giving people a warning a few months in advance would be great) but this is not inaction, this is selling trust. It's reasonable to have less than zero trust in anyone that would willingly sell my trust to an unknown third party for profit in this manner.
I think that people should have never used this service or used it with subresource integrity (which by design is not possible in this case), but that's not how it was pitched so now the owner has some responsibility if they want to maintain dignity and trust.
This isn't just about an open source project. It's about an online service. The owner could have simply shut it down instead of allowing it to be acquired.
That doesn't help me feel better about volunteering for this community.
That's great they are fixing it on free sites though.
Frankly I find this to be a weak argument. "We'll continue serving malware because broken websites are worse than infected ones" is not a good argument. I'm a cloudflare customer and I think this is a very bad look, even if it does mean websites keep "working."