upvote
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers

You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?

If so, what's your source for that claim?

reply
That doesn't seem unique to Cloudflare though
reply
No, but nothing comes close to their breadth and scale.
reply
> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.

reply
If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.

Or clouds in general, its all wishful thinking and pinky promises.

reply
"We've known it has an always-on microphone and speech-to-text for over a decade"

Literally? What is the reference here?

reply
reply
Yeah, about those I know, but what about cloudflare?
reply
They hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache appropriately.
reply
Is there any evidence of this
reply
Well it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...
reply
The reputational damage for CF would be intense.

Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.

reply
They already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.
reply