Since I mentioned Cloudflare in the OP, I thought I'd note this here: I just learned that Cloudflare's "keyless SSL" feature still allows them to undetectably MITM all traffic. How it apparently works is that you keep the HTTPS key, but session keys are generated in a special way that allows both you and Cloudflare to decrypt the HTTPS traffic. Pretty sneaky, and not at all widely known. My suspicions that Cloudflare exists to spy on encrypted Internet traffic continue to rise.