27 Mar

When they see the padlock on their screen, they feel that everything is safe. It's easy to use for a cybercriminal with numerous domains hidden behind the privacy services of various registrars.

Moreover, the subdomain wildcard option on each domain is handy for obscuring a URL in a phishing email.

(Their "data centers" are typically a rack or two of equipment that Cloud Flare ships to a real data center, along with installation instructions.) We asked Cloud Flare to confirm that sniffing is possible at these so-called "data centers," but they didn't respond.

By now we're wondering if there's a plaintext Ethernet port at the back of their equipment rack that makes interception easy and convenient.

This is why Cloud Flare will add a plaintext port to their own hardware someday, if they haven't already.

The Cloud Flare certificates below encrypt the traffic only between the browser and Cloud Flare.

All you need for a free Cloud Flare account is a domain and an email address.

The "standard" certificates on this page (with "ssl" in front of the number instead of "sni") mean that the domain has a paid account at Cloud Flare.If those IPs change, then block Cloud Flare's entire IP space, and continue to monitor the situation.If Cloud Flare's traffic still gets through, you ask the ISP to pull the plug on Cloud Flare's racks.Then they scrape your zone file from whatever dubious nameservers are listed at your dubious registrar.Without asking, they assign you a dubious "universal" SSL certificate.