<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: burdock</title><link>https://news.ycombinator.com/user?id=burdock</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 04 Oct 2026 00:46:22 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=burdock" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by burdock in "Cloudflare OHTTP gateway"]]></title><description><![CDATA[
<p>Cloudflare Proxy, which is required for their ddos protection - and which as I recall accounts for like half of internet traffic - handles TLS termination at CF servers.<p>When you capture traffic at internet backbones, which the NSA does (Room 641A), you don't get to middle-man the encrypted traffic. Cloudflare gets access to unencrypted traffic, because they act as the TLS termination.<p>Most companies take this trade-off because "we can trust cloudflare", or "the data isn't that important, and besides it's encrypted the rest of the way anyway."</p>
]]></description><pubDate>Sat, 03 Oct 2026 19:54:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=49947217</link><dc:creator>burdock</dc:creator><comments>https://news.ycombinator.com/item?id=49947217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49947217</guid></item></channel></rss>