• Hacker News
  • new|
  • comments|
  • show|
  • ask|
  • jobs|
  • celsoazevedo 37 minutes

    Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?

  • purpleidea 35 minutes

    Yikes! I see this too:

    <script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>

  • pudgywalsh 4 minutes

    This is especially hilarious in face of the "HTTPS Everywhere" nonsense, everyone's paranoid of government glowies MITMing traffic to their Magic: The Gathering blog.

    Meanwhile you and every major site out there stick it behind CF and hand them the keys to the back door. Guess who else can snoop that traffic.

    Bet you also trust the valet parking attendant.

  • BorisMelnik 14 minutes

    yep, last website I did was JS free 100% except that pesky cloudflare script

  • ValentineC 24 minutes

    Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.

  • csomar 45 minutes

    To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.

  • minraws 10 minutes

    Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.

  • dchest 17 minutes

    Indeed, https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana...

  • 29 minutes

  • pudgywalsh 17 minutes

    You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.

    If they can inject script, they can also snoop on all your cleartext traffic without you knowing....

    johntash 10 minutes

    Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.

  • moktonar 28 minutes

    Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?

    _def 13 minutes

    If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.

  • windexh8er 43 minutes

    Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.

    JoshTriplett 13 minutes

    They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.

    sscaryterry 8 minutes

    100% But this does not give you any useful personal data :)

    JoshTriplett 6 minutes

    Or data for the increasingly invasive Cloudflare captcha.