upvote
Tell HN: Cloudflare silently injects its analytics when you switch nameservers
Are you using CF as a proxy or only for DNS? I ask because I just went to check my domains on the dashboard (some purchased a few years ago, one purchased just a couple days ago), and none of them have Web Analytics enabled.

I have all my domains set to DNS only, so no CF proxy. Wondering if that is why?

reply
Yikes! I see this too:

<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>

reply
Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
reply
No, I hadn’t enabled for any site. I had to enable first to turn it off.
reply
Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.
reply
Noticed this the other day as well. Sketchy as fuck. I didn't have analytics enabled. I had to go and enable to get access to the option to turn this off
reply
Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.
reply
yep, last website I did was JS free 100% except that pesky cloudflare script
reply
Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.
reply
They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.
reply
100% But this does not give you any useful personal data :)
reply
Or data for the increasingly invasive Cloudflare captcha.
reply
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.

If they can inject script, they can also snoop on all your cleartext traffic without you knowing....

reply
Oh gosh I didn’t enable anything like that also. I just wanted the nameservers in order to serve the bucket under my subdomain. What else is there I wonder?
reply
Ok to turn this off you go Domains → Overview → your.site → DNS → Records → then Edit each entry to DNS Only (gray cloud). MITM gone now (I hope).
reply
Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
reply
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
reply
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
reply
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
reply
Cloudflare is doing this already. Once they had enough monopoly power, they started a program to block all bots that don't undergo invasive KYC procedures. Eventually, they might become a KYC broker for regular browser users too. The free internet is over.
reply
#savetheinternet
reply
deleted
reply
deleted
reply