Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, it's fundamentally impossible - as far as the browser is concerned it's talking to a server that's speaking HTTPS (CloudFlare's server) and it can't possibly know what that server's doing behind the scenes.

If I see HTTPS in the title bar I expect the owner of that certificate to be responsible for the content I'm seeing. It's utterly irresponsible of CloudFlare to enable this kind of configuration.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: