Cloudflare

I have too much about Cloudflare, so it’s time to give it a page of its own.

We don’t use external services like CloudFlare (here’s one reason – and another page too). In addition to the reasons given in the link, Cloudflare, etc., often screw up previews in social media due to their faulty bot detection. There are alternatives when (if) we get busy enough to need them.


from simplified privacy:

Cloudflare & CDNs

In our previous article, we learned that Cloudflare is a CDN or Content delivery network. And most websites point their domain to it. This means they see all your passwords (breaking SSL encryption) and browser fingerprint all visitors. This has undeniable relevance for both free speech and privacy, because they may likely see the sum of all activity in your life.


They see ALL passwords and ALL data, but they’ve been hacked.

From SecurityWeek:

But it’s not just data for governments…

Cloudflare can leak users’ locations on Signal, Discord, or other apps

An attacker can send you a unique image, and then can figure out which CF location you download it from. We covered this in an earlier article


Cloudflare decides what you can say

They have a history of dropping DDoS protection for controversial speech. Do you want this company to decide your fate? Even though it’s your website, it’s on their servers. Yet when you ask “freedom tech” influencers about it, they love being controlled so much, you’d think their servers were a dominatrix.


Cloudflare decides what software you can use

They block certain web browsers so you’re easier to fingerprint. Get on your knees and obey.


[source]

Cloudflare is a US company, making your website subject to US law even if it’s hosted overseas.

For example they doxxed an anonymous UK blogger, because a UK citizen filed with the US courts.


[source]

If it knows the server is ok, why won’t it just let the server send the page?