Cloudflare pledges to double SSL usage on the web in 2014(theverge.com)
theverge.com
Cloudflare pledges to double SSL usage on the web in 2014
http://www.theverge.com/2013/12/17/5217800/cloudflare-pledges-to-double-ssl-usage-on-the-web-in-2014
3 comments
Is there a link to the primary source? I see nothing about it on the CloudFlare blog.
I can confirm. We'll put something up on our blog later today.
>give secret ssl key to cloudflare
meh
meh
What are you quoting from? That text doesn't appear in the linked article.
This is how SSL works if you use Cloudflare. You have to hand them your private key. Also the article doesn't state this, I would guess they mean that everyone on their service should use ssl (maybe they will enable ssl on their free plan or something). I may be wrong, lets see what they will write on their blog.
My understanding is that they generate their own ssl key and certificate to use on your site. So they mitm your site, yes (I don't see how their service could work otherwise). If you're worried that they could enable the NSA to decrypt all your site's traffic: yes, they could do that.
But if you're worried that they could enable the NSA to decrypt all your site's past traffic: no, I don't see how they could do that.
But if you're worried that they could enable the NSA to decrypt all your site's past traffic: no, I don't see how they could do that.
What is CloudFlare's request rate, and how did they arrive at the five percent estimate?