Hacker News new | ask | show | jobs
by Dylan16807 1053 days ago
Do you want a similar warning on every site that the server might be compromised? Because I don't think that risk is smaller than the CloudFlare MITM risk.
1 comments

I want a similar warning on any provider that is known to routinely MITM and send data unencrypted across the Internet. As far as I know that would only be sites hosted by Cloudflare and sites using certificates issued by the government of Kazakhstan. There's a difference between screwing up (and I wouldn't be against holding companies liable for that) and wilfully setting up a https:// URL that sends your requests unencrypted over the public Internet.
That's fair. It would be good for CloudFlare to force backend encryption.