• 1 Post
  • 18 Comments
Joined 10 months ago
cake
Cake day: November 20th, 2023

help-circle









  • From my observations, my certificate is used between cloudflare and my server and another cloudflare issued certificate is provided to the client’s web-browser.

    In other words, traffic between the browser and CF servers use a CF certificate, then traffic between CF server and my server use my own certificate.

    Another way of putting it is that when I host my site directly, the browser reports the certificate as being generated by LetsEncrypt (by me).

    However, when I add CF to the equation, the browser shows cloudflare as the certificate creator.




  • The question was a more general one, and not specific to my personal data needs.

    The existence of such a ubiquitous centralised service that actually IS a MITM, whether they are malicious or not, seems curious to me.

    As they say, if the product is free, then you are the product. If people accept, but recognise, a loss of privacy when using free services from Google and meta, for example, knowing that the data they provide is used for personalised ads, then how come CF’s free tier isn’t viewed with the same level of scrutiny?