Nearly every website today seems to be hosted behind Cloudflare which is really concerning for the future of privacy on the internet.

Cloudflare no doubt logs, stores, and correlates network telemetry that can be used for a wide array of deanonymization attacks. Not only that, but Cloudflare acts as a man-in-the-middle for all encrypted traffic which means that not even TLS will prevent Cloudflare from snooping on you. Their position across the internet also lends them the ability to conduct netflow and traffic correlation attacks.

Even my proposed solution to use archive.org as a proxy is not a valid solution since I found out today that archive.org is also hosted behind Cloudflare… edit: i was wrong

So what options do we even have? What privacy concerns did I miss, and are there any workaround solutions?

  • @tiny_electron
    link
    56 months ago

    Cloudflare provides anti ddos protection, aws provides cloud computing for online services

    • El Barto
      link
      fedilink
      36 months ago

      But does everything on the internet require anti ddos protection?

      • @[email protected]
        link
        fedilink
        English
        16 months ago

        From corporate perspective, if the ddos protection is cheaper than potential ddos attack, yes.

        • @[email protected]
          link
          fedilink
          1
          edit-2
          6 months ago

          Of course it’s important to note that business case relies on users being uninformed. If a billion or more users suddenly became informed about this along with the fact that the business does not disclose it (not even in the fine print of the privacy policy), your business case would need to account for a PR backlash variable.