Tracking you by monitoring the network traffic between CF (or other connection aggregator) and the origins is possible, but usually significantly more effort. Those with reason to be concerned about true end-to-end encryption will know that seeing any CF artefacts means they need to investigate to know if they are getting e2ee or just end-to-proxy.
• consistent • not overly serious, so users who end up trained to ignore this new signal don't automatically ignore more significant warnings • (and this is the fun part) communicate this new semaphore signal to the general public without confusing them…
To head off one cynical question: “Why worry about the general public when they wouldn't care anyway and just click through warnings with wreckless abandon already?” - if not the general public then who would this be for? Those who might need to care are already checking if their data is going through CF and so might not to under true E2EE.
cf-http-endpoint: 1
or if you want it to match their own terminology[0], it could be: cf-encryption-mode: off/flexible/full/full-strict/strict
[0]: https://developers.cloudflare.com/ssl/origin-configuration/s...