Some: https://blog.paymium.com/2014/02/19/the-cloudflare-mitm/
Some: https://blog.paymium.com/2014/02/19/the-cloudflare-mitm/
[0] https://www.cloudflare.com/galileo
[1] https://blog.cloudflare.com/kyoto-tycoon-secure-replication/
[2] https://www.cloudflare.com/transparency
Read the statements in there:
CloudFlare has never turned over our SSL keys or our customers SSL keys to anyone.
CloudFlare has never installed any law enforcement software or equipment anywhere on our network.
CloudFlare has never terminated a customer or taken down content due to political pressure.
CloudFlare has never provided any law enforcement organization a feed of our customers' content transiting our network.
[3] https://upload.wikimedia.org/wikipedia/foundation/5/54/Twitt...Statement like these are, frankly, very low quality and add nothing to the discussion. It is just a worst case scenario that seeks to dismiss all opposition with no actual facts or legitimate logic to back it up e.g.: "What good is it if commercial aircraft have ACAS (traffic collision avoidance system), when the wings could just fall off! Or with a tiny fuel leak it could explode! ACAS won't help you then!!!"
I don't really have a horse in this race, but these arguments against CloudFlare are so low quality and thoughtless that I feel I must speak against them.
I think it's not quite fair to say CF is MITMing, but rather there is the possibility of MITM. Still, the biggest problem out there is the vast majority of sites that are still served over HTTP. Any easy and free solution to get more sites to move to HTTPS is well worth the MITM risk. CF is the best one now, and possibly Let's Encrypt when they launch. I would also place more trust in CF than unknown ISPs or people on unsecured networks.