They get shit on a lot here. Why? What do they do and how is that different from other companies that offer similar services?

What I know of them: they offer DDS brute force/spam protection for websites.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    125
    ·
    10 months ago

    I wouldn’t call it hate, just concern.

    Cloudflare acts as a front door to many sites and as such your TLS session is terminated at Cloudflare, then CF makes a additional session from themselves to the target site.
    This is concerning as that means CF can see all of your data.

    • kn33@lemmy.world
      link
      fedilink
      English
      arrow-up
      36
      arrow-down
      2
      ·
      10 months ago

      It’s worth mentioning the advantage of why they do this. There are several reasons, but the two most common are:

      • Seeing the data means they can do a better job at detecting attacks and fending them off.

      • They can issue certificates with longer lives from their private CA which simplifies certificate management for their customers.

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        38
        arrow-down
        1
        ·
        10 months ago

        considering they are a US company they are bound by US warrantless wiretapping laws.

      • lemmyng@lemmy.ca
        link
        fedilink
        English
        arrow-up
        21
        arrow-down
        1
        ·
        10 months ago

        Plus other capabilities like injecting banners, caching, etc