TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

On superfish and cloudflare

19 pointsby xai3luGiover 10 years ago

8 comments

ceejayozabout 10 years ago
&gt; advertising SSL MITM as a service, for free<p>A service you can choose to use. Lenovo was installing malware without the knowledge of their users.<p>&gt; doing MITM on a much larger scale that superfish will ever do<p>Again, optional, and for reasons beneficial to those utilizing the service.<p>&gt; managed by people who&#x27;s previous business was the project honeypot<p>This is oddly presented as a negative.<p>&gt; monitoring and modifying traffic of websites it protects<p>As requested by the owner of the website. Adding the site&#x27;s GA code without having to install it on the site itself is hardly the same as serving malware.<p>&gt; apparently hosting several ISIS websites, while being an US-based company. How many other ones could afford that?<p>Fundamentalist propaganda shows up on plenty of sites like YouTube. CloudFlare&#x27;s pro-free-speech attitude is pretty clear and results in things akin to KKK marches being allowed in the US despite the ugliness of their beliefs.<p>&gt; controling several high-profile foreign websites<p>&#x2F;me clutches pearls
评论 #9081426 未加载
Tobaniover 10 years ago
Except cloudflare doesnt give away a private key that can allow any arbitrary person to do this for any arbitrary site with little effort on affected machines.
评论 #9082606 未加载
bauerabout 10 years ago
This article is terrible. Just a bunch of ranting with no citations to the points the author brings up.
bradleylandabout 10 years ago
This article misses the point entirely. Anyone running a load balancer in their production environment is &quot;MITM&quot; their SSL. The difference between CloudFare and Superfish is that A) as the site operator, I&#x27;m electing (opt-in) to use CloudFares service, and B) and configuring CloudFare to use SSL is something that is very apparent during the setup process. There&#x27;s a huge green button.<p>In the case of Superfish, the software is opt-<i>out</i>. It comes pre-installed, and there&#x27;s no giant green button that says &quot;enable SSL through this service&quot;.<p>The two couldn&#x27;t be more different.
pXMzR2Aabout 10 years ago
Too superficial of an analysis to be taken seriously. There is a reason children are taught how to write an article with a proper introduction (introduce the problem and provide a map of the article body), body (explain the problem, provide proof and&#x2F;or proof of concept plus examples, and propose solution if possible), and conclusion (summarize arguments) sections.
scosmanabout 10 years ago
Link to the tech they are complaining about, since the article doesn&#x27;t even include it. <a href="https://www.cloudflare.com/keyless-ssl" rel="nofollow">https:&#x2F;&#x2F;www.cloudflare.com&#x2F;keyless-ssl</a>
natvertabout 10 years ago
What was the CA thinking when they said, &quot;Sure we&#x27;ll give you a wildcard cert for any domain!&quot;<p>I&#x27;ve un-trusted their cert... <a href="http://nathan.vertile.com/blog/2015/02/20/untrust-cloudflare-mitm/" rel="nofollow">http:&#x2F;&#x2F;nathan.vertile.com&#x2F;blog&#x2F;2015&#x2F;02&#x2F;20&#x2F;untrust-cloudflare...</a>
评论 #9081659 未加载
ikeboyabout 10 years ago
To everyone complaining about the writing; yes, they need writing lessons, but it&#x27;s not like you don&#x27;t know what they mean. I&#x27;d like to see responses to the points they raise, rather than criticism of the style. It&#x27;s a rant, with some value in it.