Top
Best
New

Posted by stagas 3 hours ago

Tell HN: Cloudflare silently injects its analytics when you switch nameservers

A few hours ago I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site textlog.cc — I had to go to the Analytics dashboard, Add the site to the analytics and then disable the snippet. I find this approach entirely invasive, you should opt-in to features like that not have to opt-out. Just a warning out there to folks who might not be aware of this.
114 points | 31 commentspage 2
pudgywalsh 2 hours ago|
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.

If they can inject script, they can also snoop on all your cleartext traffic without you knowing....

stagas 1 hour ago||
Oh gosh I didn’t enable anything like that also. I just wanted the nameservers in order to serve the bucket under my subdomain. What else is there I wonder?
temp0826 19 minutes ago|||
The main reason anyone chooses cloudflare is for their CDN (which I suppose is a "reverse proxy"...not a way I'd refer to it but technically yes that's essentially what it's doing). If you don't need the CDN or any of the other fancy features there are plenty of straight DNS providers out there (and often provided by the registar these days).
kazinator 22 minutes ago||||
OK, how can Cloudfare edit your HTML without it passing through your server?

If the browser connects directly to your web server, how can there be Cloudfare's analytics stuff?

Check what IP address you are connecting to when you load textlog.cc. Is that an address that you control? If it's not an address that you control, where is it getting your page, and is that not called proxying?

stagas 1 hour ago|||
Ok to turn this off you go Domains → Overview → your.site → DNS → Records → then Edit each entry to DNS Only (gray cloud). MITM gone now (I hope).
johntash 2 hours ago||
Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
csomar 2 hours ago||
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
yogorenapan 1 hour ago||
Noticed this the other day as well. Sketchy as fuck. I didn't have analytics enabled. I had to go and enable to get access to the option to turn this off
moktonar 2 hours ago||
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
_def 2 hours ago|
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
Bender 56 minutes ago|||
I don't know what would give anyone that idea. [1]

[1] - https://www.youtube.com/watch?v=a3Xxi0b9trY

LoganDark 1 hour ago||||
Cloudflare is doing this already. Once they had enough monopoly power, they started a program to block all bots that don't undergo invasive KYC procedures. Eventually, they might become a KYC broker for regular browser users too. The free internet is over.
sssilver 1 hour ago||
#savetheinternet
cryo32 23 minutes ago|||
That's exactly what they are.

And they can fuck off.