I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)”
If NSA aren’t installed at Cloudflare, I wonder what they are even doing.
I recall a PRISM slide showing the diagram of Google and the public internet, with a big arrow on GFE saying, quote, “SSL added and removed here! :-)”
If NSA aren’t installed at Cloudflare, I wonder what they are even doing.
Hmm do we want them to decide what stuff is shady and what isn't?
We're already allowing payment processors to do that and it's not good.
They took down KF (which is hosted in the US, so seemingly to be legal), but have always allowed everything from sites dedicated to livestreaming animal abuse to ISIS-affiliates hosting beheading videos (both which AFAIK is illegal).
That doesn't mean collusion
Either way, if they were directly colluding with Google, they would have had a much simpler time siphoning off that data.
People didn’t care when they learned about PRISM, why would they care now when it’s a known fact? The sane stance would be to assume Cloudflare is in cahoots with NSA.
The NSA leaks dominated news cycles for the entirety of 2013.
it does give better peering. reduces latency a bit for me.
but you can also see from curl or traceroute, that the endpoint you talked to was a cloudflare ip and your ssl ended there. after that you can't see inside cloudflare.
This is as helpful as Whatsapp's so called E2E encryption comms (that just happens to not be applicable by default in certain situations).
Meta data is also not encrypted. Your messaging graph is known to Whatsapp including message timestamps.
Also, IIRC, they (Meta) could also partially bypass the e2e (they can't access past messages but they can receive future messages) without you noticing (unless you have certain settings on whatsapp enabled, settings most people don't even know they exist).
The new feature of sharing past messages with new arrivals to a group also further widens the potential scope of messages leaking.
And it is very difficult to back them up anywhere other than a secret bucket at Google
Also they say messages are E2E encrypted. I don't recall that page saying anything about what happens at rest. Presumably the Meta AI will have, or already has access to them.
That nonetheless doesn't help them unless they are doing active MITM. In order to do that they'd have to have at least some physical presence at Cloudflare or on the path to Cloudflare.
That requires cooperation from a couple people at the company. People that could do it for "patriotic duty", be payed off, simply be coerced, or be replaced by NSA agents (I wonder how many cloudflare employees are NSA plants?). If you want to go even more low-profile, tap the fiber lines a block further down outside the cloudflare PoP and use one of the above techniques to get the key material
Even if it takes the NSA a decade to get an NSA agent hired and moved up in the organization until they have a vector to extract private keys that's still an incredible return on investment
I think more people than you would expect would be happy to accept that as the price for protection against malicious actors