Celebrating CloudFlare's 4th Birthday
blog.cloudflare.com
blog.cloudflare.com
StartSSL is nice because you don't need create a csr. But Cloudflare could make it simpler still, since you've already got domain-level verification through them implicitly. And if you need a better trust chain for your certs, then you can provide your own.
This just got even more exciting!
You should though.
> Finally, for people who like puzzles we've left a clue to our announcement right here on this page. With a little lateral thinking you may be able to figure it out.
This is a grave conflict of interest for Cloudflare, they have no incentive to stop them, after all, it generates more business for Cloudflare.
This absolutely needs to be addressed.
http://krebsonsecurity.com/2013/05/ddos-services-advertise-o...
Hostname: direct.titaniumstresser.net IP Address: 153.31.25.12 Organization: FBI Criminal Justice Information Systems
Many automated scripts script kiddies use to DDoS will do a basic check for subdomains like "direct.domain.com" and "direct-connect.domain.com" if the target domain is behind Cloudflare, and the scripts are naive and immediately assume that's the server's real IP.
Setting it to the IP of a site they dislike is also a popular choice.
Censorship-resistant networks are an incredibly powerful tool, for good and bad uses alike. We shouldn't criticize the tool just because some choose to use it in a way we disagree with.
Seriously? So now I have to buy into the corrupt CA system in order to rank well in searches? :/
http://googleonlinesecurity.blogspot.com/2014/08/https-as-ra...
They may be compelled to do that. It was actually a European directive, and subsequent regulations in each member state, that forced providers to retain data pre-emptively, and even that didn't require them to record all traffic.
We are very thankful to CloudFlare! Happy birthday!
GlobalSign also has an unlimited SSL cert offering, but it doesn't come with SANs (they could have arranged something though).
An intermediary created by a partner would solve the problem but would require a partnership.
Free SSL would not be practical with their old method.
Also updated my comment with a better estimate of the pricing (we've talked w/ GlobalSign about this before actually)
http://www.theverge.com/2013/12/17/5217800/cloudflare-pledge...