[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology

Name
Options
Comment
Verification
4chan Pass users can bypass this verification. [Learn More] [Login]
File
  • Please read the Rules and FAQ before posting.
  • You may highlight syntax and preserve whitespace by using [code] tags.

08/21/20New boards added: /vrpg/, /vmg/, /vst/ and /vm/
05/04/17New trial board added: /bant/ - International/Random
10/04/16New board for 4chan Pass users: /vip/ - Very Important Posts
[Hide] [Show All]


[Advertise on 4chan]


File: Cloudflare_Logo.png (21 KB, 960x318)
21 KB
21 KB PNG
Why do people on /g/ accuse Cloudflare of being a "MITM"? Obviously an HTTP reverse proxy needs to be able to process HTTP requests to function. Also, if someone is paranoid, they can use the Web Crypto API.
>>
>why do people accuse something of doing what it does
>>
>>107846473
Saying "MITM" implies they are a cyberattacker
>>
>>107846507
Saying "MITM" implies they are the man in the middle, which they are
>>
>>107846515
"man in the middle" has always referred to an unknown impersonator, not to reverse proxies
>>
>>107846467
because it is?
>>
>>107846467
>>
>>107846533
well people on /g/ use it differently, i don't know what to tell you ¯\_(ツ)_/¯
>>
>>107846467
As long as your certs aren't hosted by Cloudflare, then you're probably fine.
However, I wouldn't be surprised if Cloudflare had access to some of the private keys for CAs.
>>
It's not a MITM attack, people are retards and don't understand how reverse proxies work.
>>
>>107846653
Other than the implied malice in everyday use of "MITM", how does the technological aspect itself differ from MITM?
>>
american corporations are satanic and should be punished at every opportunity
>>
>>107846743
you don't even believe in God
>>
>>107846689
Cloudflare isn't impersonating the client
>>
>>107846533
that's your misinterpretation
>>
>>107846847
they literally are impersonating the server
>>
>>107847251
Yes, they are publicly presenting themselves as the server on behalf of the origin server. Nothing nefarious about that.
>>
>>107847295
>nefarious
you're the only one claiming that itt
btw how's the benefits working at cloudflare? I always wondered about that
>>
>>107846847
What difference does it make which party they're impersonating? Does a MITM stop being a MITM once you're pretending to be the server?
>>107847295
There's nothing nefarious in and of itself with any machine relaying info. The implied nefariousness doesn't come from this factor, so why are you underlining that?
>>
>>107846593
I relented and just gave in, their free SSL is handled by them, I don't have to do a gay "fake purchase of your free ssl" cert once a year anymore. I'm finally free, god damn it.
>>
>>107847309
>>107847315
An actual MITM does not operate with the consent of the server owner.
>>
>>107847352
let's encrypt has been a thing for a long time
>>
File: waow.png (18 KB, 640x591)
18 KB
18 KB PNG
>>107847421
>Let's HECCIN encrypterino
>>
>>107846467
>>107846533
jfc, how fucking retarded are you?
>>
>>107846467
>>107847722
also
>Web Crypto API
>just enable javascript in a security-sensitive context, bro. what could go wrong?
>what do you mean glowies use 0days to compromise your system?



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.