Hacker News new | ask | show | jobs
by telgareith 674 days ago
Cloudflare publishes a certificate pair you can pin to your origin servers.

They also offer CloudflareD (Tunnels, formerly Argo), which connects origin directly to their network- so no chance of interception or Bypassing their services.

So, as long as it's set up correctly- theres no opportunity to MitM between Origin and Cloudflare.

Do people set it up correctly? I doubt it. I've seen several companies think they were using CF's WAF product, when all they really setup was DNS.