Cloudflare Introduces Automatic SSL/TLS
blog.cloudflare.com
blog.cloudflare.com
Setting up a mapping from DNS name to route should not be called DNS and should absolutely not pretend to be a CNAME. The mapping from origin-side route to tunnel should not be done by pretending that a tunnel has a domain name. The routes should not be apparently separately configured in at least three places (DNS, Tunnel, and and Access). The JWT verification feature of tunnels should document what it does, and whatever it does should make sense and be well integrated with everything else. The Access settings should make sense, should not magically create other config, and the security settings should not require creating named groups that have entirely unclear scoping.
And for Pete’s sake, get rid of the bizarre config split between Zero Trust and everything else. It makes no sense and appears to just involve pointlessly reloading the config SPA because I guess Zero Trust uses a separate SPA that merely pretends like it’s the same one as everything else.
This sort of thing is frustrating from a company that seems to launch a new product every week.
The Zero Trust portal is such a terrible experience to use and has felt very badly “bolted on” to the rest of the Cloudflare portal from the beginning and has only continued to diverge from there.
Cloudflare’s usability took a huge dive for me when tunnels moved out of the main UI.
The integration between critical security products is poor too (eg Access and Tunnels) leading to confusion and uncertainty - which is exactly what you don’t need when it comes to security.
I used to happily accept the MITM downsides for the benefits that CF brings but I’m getting quite close to writing my own simple managed reverse proxy system based on Nginx and just focusing on a few core features that I need.
Is Cloudflare actually trying to take credit for Let's Encrypt or am I misunderstanding what they're trying to say here?
So no, this was a separate effort.
[0] https://blog.cloudflare.com/introducing-universal-ssl#:~:tex...
Is this a huge security problem? Yes, it probably will be, some day. But it is what it is, they don't mislead users about the fact that traffic gets decrypted and re-encrypted.
(Aka CloudBleed https://en.m.wikipedia.org/wiki/Cloudbleed)
As a security company, anything less than "Full (Strict)" should not exist.
They also offer CloudflareD (Tunnels, formerly Argo), which connects origin directly to their network- so no chance of interception or Bypassing their services.
So, as long as it's set up correctly- theres no opportunity to MitM between Origin and Cloudflare.
Do people set it up correctly? I doubt it. I've seen several companies think they were using CF's WAF product, when all they really setup was DNS.
This makes it a little bit annoying to deploy applications securely, since any self signed cert would be accepted with this setting as well, which is not what I want as it opens up the possibility of MITM attacks.
You can use a worker to proxy things like this, but that's going to live outside of the SSL settings and CF proxy, unless you set up an additional zone for "origin." and proxy apex to that.
I'm guessing because this topic is a "fractal".
At a high-level, it appears super simple - but the more you zoom in, the more complex it becomes.