Post
Topic
Board Meta
Re: DDoS
by
recon_eric
on 22/04/2015, 15:30:25 UTC
Since I mentioned Cloudflare in the OP, I thought I'd note this here: I just learned that Cloudflare's "keyless SSL" feature still allows them to undetectably MITM all traffic. How it apparently works is that you keep the HTTPS key, but session keys are generated in a special way that allows both you and Cloudflare to decrypt the HTTPS traffic. Pretty sneaky, and not at all widely known. My suspicions that Cloudflare exists to spy on encrypted Internet traffic continue to rise.

+1 I noticed that last year... I never bothered with it since that feature was clearly targeted towards "easy mode" types, or those who don't understand how to pass the certificate data into CF.