Cloudflare injected hostile code into a site they are not even hosting? If it's HTTPS, how do they even do that?
Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?
Cloudflare injected hostile code into a site they are not even hosting? If it's HTTPS, how do they even do that?
Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?
It seems incredibly unlikely cloudflare does this when just DNS hosting, if for no other reason then that this would break so many things.
Or is it that when you sign over DNS to a provider, they can take over your cert? They can "ass-cert" their own? :)
This may tell you something about how keen Cloudflare are to handle traffic they themselves cannot decrypt.
Realistically its a totally different product, and 5 digit price is probably cheap relative to competitors in that space.
You do ideally want your own /24, though even that's not a hard requirement. And it can be provider-assigned space as long as your provider is willing to sign an LOA for you.
As for competitors, there are a few that start in the low 4 digits per month for similar services. That's not to say Cloudflare doesn't have anything unique to offer though, they're great at scale and standardization.
What a certificate is supposed to verify is that traffic is going to the right place. If you designate cloudflare as the rightful host of your website then they can get a certificate.
This isn't an edge case though. This is cloudflare's primary product. It is why users use them.
You can disable this, at which point the record will be set as a normal DNS record.
I can see the advantage of Cloudflare's proxy systems, but I wish they'd be clearer about when they're being used and not pretend that this is some DNS feature or that records have been set to one thing when they've actually been set to something else. If nothing else, it makes debugging DNS issues a lot more confusing, particularly if you're not a DNS expert.
You could say the same about the reverse, ie. people set up their site on cloudflare, thought it was "protected", but really it's dns only and their servers are wide open. It's even worse if they migrated from another provider that was providing ddos protection.
I think a better question is: why would you be using cloudflare, if you didn't want that?
I agree that it makes sense to link products together ("vertical integration" and all that), but I think it's very confusing to have a DNS dashboard that lets you configure DNS how you like, but then by default doesn't set up the DNS as you configured it. That's a weird choice.
Not to mention impossible when ‘just’ DNS hosting. Though I suppose they could secretly replace the stated IP with one of their own anyway and then still proxy the content.
Worth checking which of your records are actually proxied. DNS-only ones (grey cloud) pass straight through and can't be touched.