Yet to do so would be to defeat SSL itself, or at least to declare it as insufficient to adequately protect secrets.
What CloudFlare is doing isn't defeating SSL or any kind of attack on it. They are merely working around some prior limitations on requiring access to an organisation's private key.
As a proxy that is charged with DDoS protection (and other types of protection and performance improvements), they are being asked to terminate and work on the unencrypted data to a very strict set of complience by the end organisations, but they need to do this in a way that does not involve possessing or having access to the private key.
Their solution works extremely well given the multiple constraints (technological and legal) that they have.