Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
Yikes! I see this too:
<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>
This is especially hilarious in face of the "HTTPS Everywhere" nonsense, everyone's paranoid of government glowies MITMing traffic to their Magic: The Gathering blog.
Meanwhile you and every major site out there stick it behind CF and hand them the keys to the back door. Guess who else can snoop that traffic.
Bet you also trust the valet parking attendant.
yep, last website I did was JS free 100% except that pesky cloudflare script
Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.
If they can inject script, they can also snoop on all your cleartext traffic without you knowing....
Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.
They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.
100% But this does not give you any useful personal data :)
Or data for the increasingly invasive Cloudflare captcha.