• chicken@lemmy.dbzer0.com
    cake
    link
    fedilink
    arrow-up
    38
    ·
    2 months ago

    If you set up a website with cloudflare, their user interface has a lot of tracking stuff on by default to be injected into it. It also encourages you to use their https service where the traffic is not actually encrypted from the user to your server, but man-in-the-middle’d by cloudflare. But the interface makes it super easy to do and refers to it like a good and normal default option.

    So yeah I think they really want your data.

    • cryptix@discuss.tchncs.de
      link
      fedilink
      arrow-up
      3
      ·
      2 months ago

      I accedently turned on the orange cloud and mitm myself accedently. It was later some day when I checked my SSL cert that I found google certificate instead of let’s encrypt that I realized the traffic is not terminating at my server.

    • ComradePenguin@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      2 months ago

      Thanks for the info about HTTPS. I have used it a lot in the past, since its so incredibly easy and reliable

  • doodoo_wizard@lemmy.ml
    link
    fedilink
    arrow-up
    14
    arrow-down
    1
    ·
    2 months ago

    Lots of stuff breaks when you block cloudflare so a better way to avoid its data collection is to use a vpn and clear your browsing data.

  • Aria@lemmygrad.ml
    link
    fedilink
    arrow-up
    6
    ·
    2 months ago

    Is this even the privacy forum? A lot of people here implying OP should consent to the spying for better service. Cloudflare absolutely does gather as much as Google, and with much deeper access. If you can go without those websites, then block Cloudflare.

    • ScoffingLizard@lemmy.dbzer0.comOP
      link
      fedilink
      arrow-up
      2
      ·
      2 months ago

      So it looks like I’m only blocking subdomains for the challenges, ajax, and some other CDN stuff. I could try blocking the whole domain for a while and see what happens. It will probably result in the same access since I blocked challenges.

    • themurphy@lemmy.ml
      link
      fedilink
      arrow-up
      19
      arrow-down
      1
      ·
      2 months ago

      Privacy policies doesnt mean anything, if it’s a US based company. Doesnt matter if the servers are in the EU. They steal it anyway.

      Look US Cloud Act.

  • FriendBesto@lemmy.ml
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    I am of the habit that I block it globally on the browser. Until perhaps a website that I have to use needs it.