Cloudflare: Difference between revisions

From Soyjak Wiki, The Free Soycyclopedia
Jump to navigationJump to search
mNo edit summary
No edit summary
Line 3: Line 3:
'''Cloudflare''' (also known as '''Cuckflare''' and '''Crimeflare''') is an [[CIA|American]] botnet disguised as an affordable reverse-proxy and DDoS-mitigation service. Its business model consists of a campaign of intimidation of DDoS attacks against website administrators, against which, suspiciously, only Cloudflare's protection service is effective. The army of servers is kept well-fed by a steady stream of racket sales. Thus the botnet grows, kind of like homosexuals<ref>[https://stonetoss.com/comic/no-choice/ 'toss/comic/no-choice/]</ref>.
'''Cloudflare''' (also known as '''Cuckflare''' and '''Crimeflare''') is an [[CIA|American]] botnet disguised as an affordable reverse-proxy and DDoS-mitigation service. Its business model consists of a campaign of intimidation of DDoS attacks against website administrators, against which, suspiciously, only Cloudflare's protection service is effective. The army of servers is kept well-fed by a steady stream of racket sales. Thus the botnet grows, kind of like homosexuals<ref>[https://stonetoss.com/comic/no-choice/ 'toss/comic/no-choice/]</ref>.


A website that resorts to those full-page Cloudflare captcha checks is also re-purposed to serve propaganda like ''"Verifying security..."'' and ''"Did you know every third person you meet is actually a botnet?"''. The goal is to make it appear justified to deny access to most websites VPN and TOR users, objectors to Javascript and generally those who run a functioning web browser but don't conform to however way Cloudflare intends to track you, which puts in cause an openness principle of the World Wide Web, while you believe the connection protection is for your protection.
= The Man in the middle =
= The Man in the middle =
Cloudflare-protected servers are instanced across a vast [https://en.wikipedia.org/wiki/Content_delivery_network content-delivery-network], with visitors never interacting with the real server. The unencrypted contents of user's interaction are entirely handled by Cloudflare. This is indistinguishable from a [https://en.wikipedia.org/wiki/Man-in-the-middle_attack man-in-the-middle attack], no more no less. From hosting your bank's website to [[soyjak.party]], Crimeflare dominates the CDN market with an 80% share, ''essentially performing a man-in-the-middle-attack on all of the internet.'' Some have pointed out the colossal [[datamining]] potential of such a position, but the argument loses ground when verified [[science|fact-checkers]] revealed the proponents are [[Schizophrenia|conspiracy theorists]] who should take their [[meds]].
Cloudflare-protected servers are instanced across a vast [https://en.wikipedia.org/wiki/Content_delivery_network content-delivery-network], with visitors never interacting with the real server. The unencrypted contents of user's interaction are entirely handled by Cloudflare.
{{quoting|
For a site to use cloudflare, the owner has to point their DNS records to cloudflare's servers, at which point they effectively handed cloudflare full control of their website (as long as the DNS records point to cloudflare's servers). ...
However, this is not a [https://en.wikipedia.org/wiki/Man-in-the-middle_attack Man-in-the-Middle attack], because the website owner gave cloudflare permission to do all of this. So it's not an attack, it's a secure connection to cloudflare (who the website owner gave permission to serve content at their domain name).
|[https://security.stackexchange.com/a/177301 "dr jimbob" — Information Security Stack Exchange]
}}
This is functionally a man-in-the-middle attack, but it's passively accepted as a fact of using the internet at this point. From hosting your bank's website to [[soyjak.party]], Crimeflare dominates the CDN market with an 80% share, ''essentially performing a man-in-the-middle-attack on all of the internet.'' Some have pointed out the colossal [[datamining]] potential of such a position, but the argument loses ground when verified [[science|fact-checkers]] revealed the proponents are dangerous, [[meds|unmedicated]] [[Schizophrenia|conspiracy theorists]].


<blockquote>
''Note for a site to use cloudflare, the owner has to point their DNS records to cloudflare's servers, at which point they effectively handed cloudflare full control of their website (as long as the DNS records point to cloudflare's servers). They can prove control of a domain to certificate authorities who will issue certificates for your domain to cloudflare.''
''Now cloudflare has control to eavesdrop and log any user interactions with your website or silently tamper content if they please.''
''However, this is not a Man-in-the-Middle attack, because the website owner gave cloudflare permission to do all of this. So it's not an attack, it's a secure connection to cloudflare (who the website owner gave permission to serve content at their domain name).''
''[...]''
''In the end, that's all you have. You have to trust that the organization running the website at the other end is trustworthy with whatever data you give them by browsing there. When visiting websites on the cloudflare CDN part of the trust is in cloudflare.''<ref>https://security.stackexchange.com/a/177301</ref>
</blockquote>


= See also =
= See also =

Revision as of 20:22, 4 August 2023

This page is about the CIA, and may be vandalized by angry chuds from time to time. Remember that the CIA are the good guys, and any slander you read about them is decisively false.

Cloudflare (also known as Cuckflare and Crimeflare) is an American botnet disguised as an affordable reverse-proxy and DDoS-mitigation service. Its business model consists of a campaign of intimidation of DDoS attacks against website administrators, against which, suspiciously, only Cloudflare's protection service is effective. The army of servers is kept well-fed by a steady stream of racket sales. Thus the botnet grows, kind of like homosexuals[1].

A website that resorts to those full-page Cloudflare captcha checks is also re-purposed to serve propaganda like "Verifying security..." and "Did you know every third person you meet is actually a botnet?". The goal is to make it appear justified to deny access to most websites VPN and TOR users, objectors to Javascript and generally those who run a functioning web browser but don't conform to however way Cloudflare intends to track you, which puts in cause an openness principle of the World Wide Web, while you believe the connection protection is for your protection.

The Man in the middle

Cloudflare-protected servers are instanced across a vast content-delivery-network, with visitors never interacting with the real server. The unencrypted contents of user's interaction are entirely handled by Cloudflare.

For a site to use cloudflare, the owner has to point their DNS records to cloudflare's servers, at which point they effectively handed cloudflare full control of their website (as long as the DNS records point to cloudflare's servers). ... However, this is not a Man-in-the-Middle attack, because the website owner gave cloudflare permission to do all of this. So it's not an attack, it's a secure connection to cloudflare (who the website owner gave permission to serve content at their domain name).

"dr jimbob" — Information Security Stack Exchange

This is functionally a man-in-the-middle attack, but it's passively accepted as a fact of using the internet at this point. From hosting your bank's website to soyjak.party, Crimeflare dominates the CDN market with an 80% share, essentially performing a man-in-the-middle-attack on all of the internet. Some have pointed out the colossal datamining potential of such a position, but the argument loses ground when verified fact-checkers revealed the proponents are dangerous, unmedicated conspiracy theorists.


See also

On soyjak.party

Soot enabled Cloudflare in an attempt to stop Colorjak, CP and other types of spam. At first it was accepted, even with some users starting to defend the decision, calling all the Cloudflare detractors as spammers but it quickly became an annoyance to most users as cloudflare requires you to refresh the page every five minutes. Higher protection modes also block archive sites from taking snapshots.

oh yeah and cloudflare makes it so i can't access the website right now this is retarded kuzzy

Citations