You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?
If so, what's your source for that claim?
The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?
If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.
Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.
One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.
> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?
ISP taps globally, undersea cable taps, the list goes on.
[1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...
That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.
If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.
They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.
But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.
I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.
NSA putting implants into Cisco equipment before delivery to the customer.
https://www.certificationkits.com/nsa-upgrade-process-cisco-...
ANT catalogue from 2008 with hacking equipment:
This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.
https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...
"the NSA learns everything there is to know about you and your customers"
Which implies that they are looking at it all and records it.
The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.
That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.
Or clouds in general, its all wishful thinking and pinky promises.
[1]https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_C...
I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.
Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.
I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.
Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.
BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.
https://en.wikipedia.org/wiki/Room_641A
Public information shows that the NSA has been active intercepting as much data as possible.
It doesn't require the budget of a FAANG to peek through a significant volume of internet data.
"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)
I think spying on traffic is just a massively simpler task than generating content.
I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.
I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.
Should be relatively easy to work out who uses what CDN
I get your point about the long tail but what’s the value in a government MITM those?
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.
And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.
I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.
Literally? What is the reference here?
It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.
Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.
I even get to charge the bots extra to bypass the block, and then charge the customers extra to block the bots that are paying extra to not be blocked!
Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.
I don't think it's convincing
If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.
The fact is businesses do "tolerate it"
For example,
https://en.wikipedia.org/wiki/Cloudbleed
The MITM design of CF is what it is
It creates risks, but these risks are tolerated
For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost
The damage of being spied upon, if there is any, is already done
1. It's not clear why commenters are only concerned about intelligence agencies
>doesn't offer an alternative and leaves
Every. Single. Time.
"Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752