Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers. Cloudflare is the LG TV of websites, but it's worse because we've known it has an always-on microphone and speech-to-text for over a decade and we still keep using it for some reason.
 help



> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers

You're replying to a comment talking about migrating from Google, so I assume you're claiming this is more of a risk with Cloudflare than Google (or other American providers like AWS)?

If so, what's your source for that claim?


Heck the NSA backdoored our head of states phones - if “NSA wants my data” is your threat model you are pretty much cooked everywhere. Even if you host on your own server and operate everything yourself it’s no big secret that the NSA is listening in on the node/isp level

"The “threat model” section of a security paper resembles the script for a telenovela that was written by a paranoid schizophrenic: there are elaborate narratives and grand conspiracy theories, and there are heroes and villains with fantastic (yet oddly constrained) powers that necessitate a grinding battle of emotional and technical attrition. In the real world, threat models are much simpler (see Figure 1). Basically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them." -- James Mickens

Man, can I get that as a telenovela? I want to hear my mother in law explain the plot.

I remember my mom watching novelas in the 2000s they were something else, nowadays they're all over the place.


Yeah but like, they still have to do that, we don't put our own uranium lumps in our cellphones like we do with cloudflare.

l2paragraph, aint nobody reading dat

> "it’s no big secret that the NSA is listening in on the node/isp level"

The NSA is doing deep packet inspection at every "node/isp" in the world? That's a pretty amazing claim. How are they managing that?


Isn’t their whole thing supposed to be spying on foreigners? They seem to be quite successful. There aren’t that many exchanges [1]. Could probably manage with cash, guns, and some know-how.

[1]: https://en.wikipedia.org/wiki/List_of_Internet_exchange_poin...


If you just look at the largest 4 of those, you'd have 100Tbps of traffic to monitor, with an average throughput of roughly half of that.

That's ~540PB ((50 Tbps / 8 bits) * 86400 seconds/day) of traffic a day with just those four. Add in the rest and you're likely talking ~Exabytes of data each day. And that has to all be processed on site.

If someone wants to argue that the NSA is in these facilities I'd be 100% onboard. But inspecting it all would be nearly impossible, let alone capturing it all and sending it back to some datacenter somewhere, which is a physical impossibility.


That's nothing a rack full of fast switches can't handle. A rack full of fast switches already does handle it - where do you think the original copy came from?

They will get a copy of the whole feed, but not store all of it - they will have heuristics for selecting interesting traffic.


Switches handle data at far faster rate than any hardware can actually inspect it, store it, process it, etc.

But yeah, just a rack of "fast switches" is all it takes to route hundreds of petabytes of data each day. You should let the data center operators know. They'd save billions.


Switches do inspect it. They also have a feature designed for wiretapping, which copies a percentage of traffic to another port. They may have a feature to copy 100% of traffic matching a certain filter. Managed switch ASICs have this feature even though it's usually not exposed in the CLI.

see https://en.wikipedia.org/wiki/XKeyscore for the sota from 20 years ago

Yes, I'm well aware of XKeyscore.

If it required ~700 servers in ~150 locations (mostly US military bases and embassies) to surveil a small slice of internet and other traffic back then, how many would it require now? How many locations would those servers need to be situated? And how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

Just think through the logistics of all of this and try to think of a way that any agency could accomplish it in 2026. And now think of all the people in the industry who would have to have at least some knowledge of it, or be able to discover a part of it.

Those are just some of the things one would need to explain and rationalize to even suggest that the NSA is doing what some of the people here are claiming.


You’re talking about two different things.

One is where their hardware for storing data is. The other commenter was talking about global taps (the sources for the data), of which the Wikipedia article is not speculating the number of.

> how would NSA positions situated in embassies capture all of that Internet traffic in a foreign country without getting noticed?

ISP taps globally, undersea cable taps, the list goes on.


Most Tier 1 network owners are U.S. companies or U.S. friendly companies, tapping undersea cables is not necessary in many cases, just ask the owner.

You think the politicians are going to say "The career employees made some convincing arguments about why this is impractical / immoral, guess we'll give up our unregulated power/omniscience"? Or, they will raise the military budgets and continue skipping the audits.

You may as well make them work hard to get it. The NSA can only get metadata from your ISP.

This is a joke. If it's electronic the NSA can hack it with impunity, including your ISP. And that's assuming your ISP won't just give them whatever they ask for (unlikely).

There is nothing magical about these NSA hacks:

NSA putting implants into Cisco equipment before delivery to the customer.

https://www.certificationkits.com/nsa-upgrade-process-cisco-...

ANT catalogue from 2008 with hacking equipment:

https://dcssproject.net/ant-catalogue/index.html


I did once theorise that Cloudflare would be a fantastic NSA front.

That's why it is one.

The NSA couldn't care less about you and your customers, nor do they have any interest whatsoever in the megaton of worthless internet traffic that goes through Cloudflare.

This article, from over a decade ago now, explains how they actually operate. Gobbling up all the traffic is a 20+ year old idea that never bore any fruit and is amazingly pointless. Instead, they might drop an implant in the SSD firmware of devices they actually care about, and they're not burning that to see if you sold X widgets to someone in Alberta.

https://blog.thinkst.com/2015/08/if-the-nsa-has-been-hacking...


If I was the director of an agency of the size of the NSA and was evaluating the options purely from that perspective, I'd aim at creating a file on every living citizen on earth, including their social network topology and their activities. Basically a Google search engine that includes information not publicly accessible. I'd create much larger files for persons of interest and authorize targeted surveillance of them, of course, but with today's means to collect data a complete world database on every living and many dead persons is well within the technical capabilities. It also makes sense and is rational, if you put aside moral considerations.

That's how I evaluate these things. If it makes sense and can be useful, it's likely going to be done. Notice that there is no law against this in the US if you exclude US citizens. It's perfectly legal and within their mission parameters to do it for non-US citizens. I used to think my judgments were a bit too much on the paranoid side but when Snowden published his leaks it turned out that I was roughly right about every capability the NSA had except for their internal security.


Yeah, I'm sure some system like that exists, although I'd assume that would be more in the CIA's purview. I'd be surprised if they kept a broad swath of data for most people though as the tech companies already do it and it's constantly up to date. If needed, a fed lawyer can work through the FISA court and the tech companies are obliged to provide the records.

According to the information I have, the CIA is unlikely to be involved with SIGINT of that type. It's just not their role. I agree that most of the information the NSA might collect will come from publicly available sources like data brokers, particularly if US citizens are involved. However, what I was talking about concerns real-time capabilities and predictive power, it's very different from targeted surveillance and anything involving courts.

Isnt that basically Palantirs business model?

There's a lot of important data that runs through Cloudflare, so I think it's a bit naive to think that there's nothing interesting for the NSA there.

Of course, but the comment I was replying to stated:

"the NSA learns everything there is to know about you and your customers"

Which implies that they are looking at it all and records it.

The vast, vast majority of Cloudflare's traffic is worthless to an intelligence agency.


They are actively scanning all of it, looking for interesting stuff.

How do you do DPI on hundreds of PBs a day? Explain the process that would allow you to "look for interesting stuff".

I'm more concerned about crimeflare's own incentive to analyze our traffic that people already willingly let them MITM, and somehow sell it to the highest bidder.

If you care about security and specifically NSA, don't use US clouds (owned or hosted), period. There is not a single one they don't have full access to, why should there be one.

Or clouds in general, its all wishful thinking and pinky promises.


What about the Chinese clouds? It’s hard to imagine Alibaba etc being cooperative with western intelligence

You have to be a registered Chinese business entity with a CCP director on your board to legally use that

One of them is just another arm of the government so all data is defacto government data, and the other releases transparency reports[1]

[1]https://archive.dni.gov/files/CLPT/documents/2026_ASTR_for_C...


Pick your poison

> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

I doubt the NSA is gobbling up all the CF traffic because maybe, maybe they will find something of interest.

Can the NSA make CF "mirror" your website traffic to them if you are of interest to them, most likely yes.

I am not that paranoid to think that my website of a few corporate pages is of interest to the NSA.


The NSA collects and archives all internet traffic it can access for future analysis. It's the purpose of the Utah Data center.

https://en.wikipedia.org/wiki/Utah_Data_Center


There’s no way a single datacenter costing a couple of billion dollars can store “all Internet traffic the NSA can access”, unless the traffic the NSA can access is a microscopic fraction of the total Internet traffic.

Think about it. The Internet runs on tens of thousands of massive datacenters. Thousands are being built as we speak. Obviously a single datacenter cannot hold an appreciable fraction of that.

BTW, the total budget of the NSA is less than the R&D budget of a FAANG company, so if you find yourself believing that they might have alien-level technology far beyond Google and AWS, you’re watching too much TV.


https://en.wikipedia.org/wiki/Fairview_%28surveillance_progr...

https://en.wikipedia.org/wiki/Room_641A

Public information shows that the NSA has been active intercepting as much data as possible.

It doesn't require the budget of a FAANG to peek through a significant volume of internet data.


That’s not what the GP comment said though. They claimed that they are storing everything they can intercept, which is weapons grade horseshit.

People said/wrote in the past that what NSA and other intelligence agencies did was to gather data and store the meta data. The actually traffic got processed for the meta data, and small amount of the traffic got sorted out and also stored.

I would suspect that today they also process the traffic for llms and thus store a bit more of the traffic as weight and biases. All that can be done distributed and to different degrees based on how much access they got and under what operational conditions.


Regarding storage, a single data center using only slow but dense storage (magnetic tapes) can store far more data than a data center providing regular web services.

“They’re not as good at violating your civil liberties as you think they are” isn’t very comforting. They are still doing it at scale and i’m not too keen on opening the back door for them myself.

> The Internet runs on tens of thousands of massive datacenters.

"The Internet" would require 1000 times less servers if it wasn't running off Python scripts in Docker containers in VMs in a virtual overlay network. (I'm exaggerating these numbers only slightly.)


Sure. But a government agency has secretly rebuilt all the same infrastructure without Python, on a shoestring budget compared to what Big Tech is spending, yet it’s a lot more efficient than what they use, right?

Caveat: I have zero experience with USA government agencies. The spying tech from other countries I'm familiar with are beige box routers made by network engineering types with embedded firmware written in C inside.

I think spying on traffic is just a massively simpler task than generating content.


It doesn't need to store the payloads itself. It stores the metadata of connections and probably the fingerprints of the content passing through the Internet. "The headers of the whole Internet" could be physically stored in a single datacenter.

Not all traffic, but any.

I agree it doesn't matter for most smaller entities, but it's relevant for larger entities and as the US does not anymore intend to be allied with Europe, the Western world, or anybody really, there's now actual incentive to move away from such systemic risks.


They also certainly have many heuristics running. Your corporate website is interesting because it reveals who your suppliers and customers are, and all of your passwords. They don't have the manpower to scrape this manually so they scrape it automatically

That doesn't seem unique to Cloudflare though

No, but nothing comes close to their breadth and scale.

Amazon and Akamai is their scale, maybe Fastly too

They are serving big commercial enterprises, ones the government already has direct access to. Cloudflare is serving the long tail.

Last I heard (was a few years back) Cloudflare had more enterprise customers than Fastly

Should be relatively easy to work out who uses what CDN

I get your point about the long tail but what’s the value in a government MITM those?


  > The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.
That depends heavily on the kind of site you're hosting there.

I have a small site on Cloudflare that lists a brief introduction of a sawmill, its operating hours and contacts, and a map that advises which roads to take to reach it. Everything's public already. There's some very modest value in tracking who visits the site, but with popular operating systems leaking like a sieve on the client side, that fight was lost a long time ago.


Do you really need Cloudflare for something like this?

It's free hosting. Push to github and changes to the website appear in 30 seconds. Even the build step for the static site is handled by Cloudflare.

And I'm satisfied with Cloudflare's explanation to the free hosting: the more sites are on Cloudflare, the more are ISPs interested in having good connections to Cloudflare. Makes sense.


He doesn't, but someone told him it was good so he uses it. This is Cloudflare's main audience, just like McAfee's.

Unfortunately my proposal to set up a K8s cluster to host 5 HTML pages and a dozen jpegs was not approved, so I had to make some compromises this time.

Who told you you need a k8s cluster to serve 5 HTML pages?

I believe this was a joke.

Poe's law applies. Many people actually think that.

> The hidden cost, of course, is that the NSA learns everything there is to know about you and your customers.

I think it’s fair to assume that for most companies, cost is essentially zero on the company’s side.


"We've known it has an always-on microphone and speech-to-text for over a decade"

Literally? What is the reference here?



Yeah, about those I know, but what about cloudflare?

They hold your tls keys and can decrypt all your traffic. They're MITM as a service, by definition. They have to be able to in order to cache and forward appropriately.

Also to do DDoS mitigation. Being able to see the HTTP request, at least headers and path, greatly helps with distinguishing attackers from legitimate traffic.

It's a tragedy that there's no standard to allow partial decryption/nested encryption in HTTP, which would allow intermediate proxies like Cloudflare to e.g. only validate a first-level authentication token and rate-limit access to a given endpoint, but not decrypt the actual request body, backend authentication token, or response.

Also desperately missing: Authenticated static file caching (think: cdn.foo.com serves files authenticated/signed by foo.com). Subresource integrity only works for HTML use cases and is clearly not ergonomic enough to make a difference.


And the best way to get people to let you do bad things, is to offer them something good, that uses the same mechanism. If I want to MITM the whole internet, what better way than offering free caching and bot blocking?

I even get to charge the bots extra to bypass the block, and then charge the customers extra to block the bots that are paying extra to not be blocked!


Also CF adds extra waiting with checkbox and I see it more often than cookie confirmation dialog. Also CF raise checks on pages that I opened few hours ago and reload.

if your threat model includes the NSA i don't think your choice of CDN is going to make a difference

Is there any evidence of this

Well it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...

The reputational damage for CF would be intense.

Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.


They already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.

Maybe that's why the keep hosting extremist content.

I thought Cloudflare generally refuses to serve those kinds of sites. What content is Cloudflare serving that is extremist?

Many torrent sites, that's a kind of extremism.

I have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries

I don't think it's convincing

If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.

The fact is businesses do "tolerate it"

For example,

https://en.wikipedia.org/wiki/Cloudbleed

The MITM design of CF is what it is

It creates risks, but these risks are tolerated


If the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying

For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost

The damage of being spied upon, if there is any, is already done

1. It's not clear why commenters are only concerned about intelligence agencies


>talks about how bad Cloudflare is with imaginary threats

>doesn't offer an alternative and leaves

Every. Single. Time.


The alternative is nothing. You don't actually need cloudflare.

And get hammered by bots, scrapers, and bad actors?

It's not like cloudflare blocks them either. Have you tried?

Yeah and it works, that's why I keep using it

Or they will dump your secrets into all Internet caches...

"Cloudflare Reverse Proxies Are Dumping Uninitialized Memory" - https://news.ycombinator.com/item?id=13718752




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: