news.volyx.in

Tell HN: Cloudflare silently injects its analytics when you switch nameservers

660 points by stagas · 10 days ago · 202 comments on HN

Article summary

The author switched their nameservers to Cloudflare to enable R2 bucket serving and discovered that Cloudflare had injected a JavaScript analytics snippet into their HTML-only website without their consent. The author had to enable analytics and then disable the snippet to remove it. This experience led the author to warn others about Cloudflare's opt-out approach to features like this. The incident raises concerns about data tracking and user consent.

Main themes

  • Cloudflare analytics
  • Data tracking
  • User consent
  • CDN and proxy services
  • DNS and nameserver configuration

What commenters say

  • Cloudflare's injection of analytics scripts without user consent is an invasive and unacceptable practice.
  • The company's approach to features like analytics should be opt-in, rather than opt-out, to respect user privacy.
  • Some users argue that Cloudflare's actions are not surprising, given their role as a proxy and CDN provider, and that users should be aware of the potential for data tracking.
  • Others believe that Cloudflare's behavior is a sign of a larger problem with the centralization of the internet and the erosion of user privacy.
  • There are concerns that Cloudflare's actions could be a precursor to more invasive data collection practices in the future.
  • Some users have reported difficulty in finding and disabling the analytics script, highlighting the need for greater transparency and control over website configuration.
  • The incident has led some to question the trustworthiness of Cloudflare and the trade-offs involved in using their services.
  • Disabling the analytics script requires changing the DNS configuration to 'DNS only' mode, which may not be immediately apparent to all users.