Hacker Newsnew | past | comments | ask | show | jobs | submit | CommanderData's commentslogin

Is there any evidence of this

Well it is known SSL termination servers are a popular target: https://arstechnica.com/tech-policy/2013/10/new-docs-show-ns...

The reputational damage for CF would be intense.

Businesses won't tolerate something like this so I find it hard to believe there is any cooperation between the two entities.


They already terminate TLS at their edge. It takes one secret court order for them to start sending data to the NSA.

Maybe that's why the keep hosting extremist content.

I thought Cloudflare generally refuses to serve those kinds of sites. What content is Cloudflare serving that is extremist?

Many torrent sites, that's a kind of extremism.

I have seen this argument on HN before with respect to similar scenarios involving so-called "tech" companies acting as intermediaries

I don't think it's convincing

If this submission and this thread are any indication, it appears the "reputation" that CF customers care about has nothing to do with privacy. It relates to price, ease of use, reliability, etc.

The fact is businesses do "tolerate it"

For example,

https://en.wikipedia.org/wiki/Cloudbleed

The MITM design of CF is what it is

It creates risks, but these risks are tolerated


If the design, e.g., TLS termination by a third party such as CF, allows for spying, then waiting for evidence of spying is not a good strategy to avoid spying

For example, if evidence becomes available that someone (besides CF) is spying on CF's customers,^1 then for those customers it's too late. For the network traffic that flowed through CF before the evidence became available, any privacy, secrecy or confidentiality has been lost

The damage of being spied upon, if there is any, is already done

1. It's not clear why commenters are only concerned about intelligence agencies


They don't have Cloudflare Tunnels which is almost too good to pass up.

I don't particularly understand how CF makes money on it, with the many high traffic sites I have used that I know don't pay CF a dime. Tunnels adds so much more overhead in compute on both ends more than their normal CDN/proxy would.


big corps = big money. they dont make money from your $5/mth static site, its practically free when you're at CF scale

What I was talking about: https://newtrackon.com/

10+ BT trackers using CF likely free tier. Low-end EACH 300-500 MILLION HTTP requests/24hr uncached, some exceed a billion reqs/day (using statistics from other open trackers) 20TB-40TB daily, ~1-3 Gbps sustained.

That's a crap load of transfer and compute to process those tiny network connections. As someone that's run a Tunnel on a normal site in the millions, the daemon uses a sizeable amount of CPU and I can't see any reason why it's not the same on the other end.

Whatever source CF has going on, kudos to them and their engineering team.


Lots of people will run http over the tunnel rather than https, so that actually comes out cheaper for CF overall because they don't have to start new TLS sessions.

If you're not paying, you're not the customer; you're the product.

So how do we stop this? Laws? Who do we write to?

"Samba unites TV, digital, and behavioral data through AI to power faster, more accurate media decisions. We help the world’s leading brands and agencies reach the right audiences, measure real outcomes, and access signals no one else has."

https://samba.com/


Kill it with fire.

Such a pity the name is associated with freeing proprietary software.

The _real_ samba: https://www.samba.org/


Yeah...what the hell even is that "I like that name, mine now" for something that has been around almost as long as I have.

Congratulations but I also dislike this type of comment because that is not a solution, a workaround that doesn't happen for 99% of the population.

Soon you won't be able to IoT network or block these devices as they begin to partner with Amazon and the likes that sell Internet for near-by IoT devices. Then your only option then is physically removing / de soldering radios from the board.

Laws needed, like yesterday.


For now, setting up an IoT network is pretty much best practice, and I'd wager the average Hacker News reader both has the necessary equipment and skills to do it. That may not always be the case.

Assuming they install some 5G modem in the device, which is pretty much dirt cheap these days (our local water utility uses 5G for meter readings, and the cost per meter is something like $1/year), there's literally nothing short of a faraday cage you can do.

The can report on what you watch freely, and only consumer laws can stop them. However, without a wifi connection they can't snoop on your local network, and they probably can't connect the data to you, assuming you don't register the TV for those 3 months of added warranty or whatever they try to get you to register.

I tend to avoid devices that are built to snoop on you, so no Amazon Alexa, no Google Home, no Apple HomePod. Everything I have utilizes local control via Home Assistant, and most of it is actively blocked in the firewall from accessing the internet. It's not hard to implement, and doesn't require a master of IT, but it does remove a lot of the convenience, which I guess is the reason people don't do it.


I posted two comments on similar threads recently. This is only going to get worse.

> Not long until companies partner with Amazon and others to send traffic automatically through their near-by devices like smart speakers, disconnecting will be impossible.

Not surprised if this is happening already. I don't want to remove radios out my TV..

> Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.

Viewer analytics are valuable to companies like Samba, they aren't the only ones. Laws ASAP, these companies will lobby hard to stop anything of the sort.


Not long until these TVs start partnering with Amazon and other providers to send traffic automatically through near-by devices like smart speakers, disconnecting will be impossible.

Vast majority won't know or care.

The way this gets fixed is laws not workarounds unfortunately.


> Vast majority won't know or care.

This, unfortunately, is the biggest problem those of us care about privacy face, especially when trying to warn people about it.


The discussion around privacy is always framed the wrong way.

The authoritarians use the red herring of "nothing to hide", while the liberals only argue on the most sensational abuse cases or somewhat flimsy high-minded principles.

The correct way to get the layperson to care is with a visceral reaction using the relevant buzzwords: "sabotage", "gangstalk", "bully", "witch hunt", etc.

It makes zero sense that the same people who fight so hard over gun rights can completely ignore all the other much uglier ways the powers-that-be can threaten your livelihood.

Nobody ever spells out what "overpolicing" really looks like. Nobody makes clear enough that "the government" is what we call it when we give your literal neighbor special privileges.


Somewhat related: Public-Key Addressable Resource Records (Pkarr) - Fully sovereign, publicly addressable, censorship-resistant top-level domains

https://github.com/pubky/pkdns https://app.pkarr.org/

I discovered this gem through Iroh.


Samba, a media intelligence company have several partnerships with manufacturers to take screenshots and collect metadata.

Who the fuck invited them into the living room? They say it's optional and opt in but I really don't believe that.

Edit: it's called ACR and a much bigger problem then I originally thought. Wow.


I can't imagine it coming to Chromium thus Electron apps, it is only Chrome it seems sadly.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: