I semi-regularly see it on Cloudflare sites because their customers haven't bothered to send their own keys to Cloudflare.
I thought it was ironic than article about SSL security was doing something that is less secure than possible (from the end user's point-of-view).
Just to be clear, yes, I understand that the operator of brainsmith.org isn't gaining any more security by sending CF the private key to their own cert vs. using CF's G2 cert. With the first approach the end user of brainsmith.org has better security since he can view the site without having to trust an MITM-capable certificate.