news.volyx.in

A public letter to CloudFlare to fix their snoopy vendor (github.com)

417 points by captn3m0 · 1715 days ago · 104 comments on HN

Article summary

A public letter to Cloudflare highlights an issue where websites hosted on GitHub Pages and fronted by Cloudflare are being blocked in India due to a misconfigured network by Airtel, a Cloudflare peering partner. The problem occurs when websites use Cloudflare's Flexible SSL or No SSL options, which don't encrypt the connection between Cloudflare and the origin server. This has been an ongoing issue for years, affecting many websites and disproportionately impacting the developer community. The letter calls on Cloudflare to resolve the issue by getting Airtel to fix the misconfiguration or switching to a different upstream provider.

Main themes

  • Cloudflare and Airtel issue
  • Internet censorship in India
  • SSL and security
  • IPv6 support
  • GitHub Pages and Cloudflare
  • Transparency and notification

What commenters say

  • Cloudflare's Flexible SSL option is misleading and insecure, and the company should not offer it.
  • The issue is not Cloudflare's fault, but rather a result of local laws and internet censorship in India.
  • Cloudflare has a responsibility to fix the issue and notify its impacted customers, given its commercial relationship with Airtel.
  • The problem can be resolved by switching to Full SSL or Strict SSL options, which ensure a secure connection between Cloudflare and the origin server.
  • IPv6-only users exist and are common in certain parts of the world, particularly in Asia, and Cloudflare should support them.
  • Cloudflare's lack of IPv6 support is a significant issue, especially for paying customers with IPv6-only users.
  • The use of Cloudflare in front of GitHub Pages is no longer necessary, as GitHub Pages now supports SSL on custom domains.
  • Cloudflare should provide more transparency and notification to its customers about the issue and its impact on their websites.