frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Ask HN: Are you concerned by TLS-terminating proxies like Cloudflare Tunnels?

2•thom-gtdp•1h ago
I believe many services rely on Cloudflare Tunnels or similar products that lets you proxy web requests from the public internet to your server without opening any port.

This kind of proxy handles TLS (HTTPS), it's not possible to use Cloudflare Tunnels for raw TCP/UDP passthrough. This is convenient because it makes it more simple to use, but may be concerning because Cloudflare technically has access to all the plain-text traffic, even though seen from the end user the connection is HTTPS and looks perfectly normal

This is even more concerning to me given it's now public that most of internet traffic is automatically stored (see Wikipedia article "Room 641A for a good start)

What are your opinions about this? Are this kind of proxy a no-go for any serious web service?

Comments

zhouzhao•1h ago
For European web services it should be a no-go.

I understand the easiness of that approach, but companies should realize that relying on a giant American company for stuff like that, is going to bite them in the ass, eventually.

andy_pl•1h ago
Same trust assumption as any reverse-proxied or CDN-fronted service. CF terminates TLS for Tunnels, Workers, the regular proxy, and Pages alike — if CF is in your threat model, the issue isn't Tunnels specifically, it's the entire CF surface you've accepted by being on their network. The honest framing isn't "no-go for serious services" but "what does your data residency / DPA / SCC posture look like."
thom-gtdp•35m ago
Yup Workers has similar risks as Tunnels. Cloudflare Pages isn't the same threat as Tunnels, as Pages only gives CF public data access. On Pages you trust Cloudflare for not altering the data served, while on Tunnels you trust CF for handling secret data. I actually don't really have a data residency / DPA / SCC policy because I was considering using Tunnels for my homelab only
andy_pl•42s ago
Right, the Pages vs Tunnels split is real — different threat surfaces. For a homelab the GDPR/SCC scaffolding doesn't apply; the practical question becomes "do I trust CF more than my own ISP for opportunistic snooping," and on that axis CF's incentive structure is reasonably well-aligned.

TidesDB – Fast, persistent, scalable key-value storage for modern systems

https://tidesdb.com
1•alexpadula•49s ago•1 comments

Show HN: Implit – A CLI that catches AI-hallucinated NPM packages

https://github.com/Neurall-build/implit
1•neurall-build•4m ago•0 comments

Shellora: SSH terminal, AI help, and server tools

https://holding.vc/shellora/
1•yaseral•5m ago•0 comments

Can We Vibe Code a Smart Home Device with Matter?

https://dunkels.com/adam/vibe-code-smart-home-matter-device/
2•adunk•10m ago•0 comments

Samsung Galaxy S24 and S25: April update causes battery problems

https://www.heise.de/en/news/Samsung-Galaxy-S24-and-S25-April-update-causes-battery-problems-1127...
1•aureliusm•11m ago•0 comments

Show HN: Agent Context – let your AI coding tools see your reference projects

https://github.com/gmarland/Agent-Context
1•gamerdrome•13m ago•0 comments

Ask HN: Should HN have a new top category – Prompt HN?

1•jharohit•13m ago•0 comments

A hallucination engine. Typed pseudorandom data via LLM

https://pypi.org/project/grievous-mcp/
1•basyt•20m ago•1 comments

Oracle cutting thousands in latest layoff round, continues to ramp AI spending

https://www.cnbc.com/2026/03/31/oracle-layoffs-ai-spending.html
2•sparin9•21m ago•0 comments

Ask HN: What domain have you been sitting on for a while?

2•msuniverse2026•22m ago•0 comments

Healthcare Price Transparency

https://marginalrevolution.com/marginalrevolution/2026/04/on-health-care-price-transparency-from-...
1•barry-cotter•26m ago•0 comments

Moleskine's AI Lord of the Rings collection can only mock

https://cjleo.com/blog/moleskine-ai-lord-of-the-rings-collection-can-only-mock/
2•lentil_soup•34m ago•0 comments

Trump turns the WHCD shooting into a pitch for the White House ballroom

https://www.theverge.com/policy/918843/trump-whcd-attack-white-house-ballroom
1•eternalreturn•35m ago•0 comments

Show HN: Building a SQL analyst agent from scratch

https://raminmousavi.dev/blog/building-a-sql-analyst-agent
2•ramin2nt2•45m ago•0 comments

Ubuntu 26.10 could drop btrfs, ZFS and LUKS support from GRUB

https://www.omgubuntu.co.uk/2026/03/ubuntu-grub-secure-boot-luks-changes
2•mariuz•47m ago•0 comments

BSI (Germany) defines when a cloud is sovereign

https://www.heise.de/en/news/BSI-defines-when-a-cloud-is-truly-sovereign-11272828.html
2•pros•48m ago•0 comments

Queen

https://medium.com/the-hitmagist/queen-2a8c2d9da9f5
2•bryanrasmussen•48m ago•0 comments

An attempt at explaining bipolar disorder and psychosis

https://osf.io/preprints/psyarxiv/w28g9_v1
2•anon1253•52m ago•0 comments

Quarkdown – Markdown with Superpowers

https://quarkdown.com/
3•amai•58m ago•0 comments

Show HN: Defeating AI by making knowledge accessible to Humans

https://github.com/tnelsond/peakslab
2•tnelsond4•58m ago•0 comments

China Blocks Meta's $2B Acquisition of AI Firm Manus

https://www.bloomberg.com/news/articles/2026-04-27/china-blocks-meta-s-2-billion-acquisition-of-a...
4•limoce•58m ago•1 comments

China blocks Meta's $2B purchase of AI startup Manus

https://finance.yahoo.com/sectors/technology/articles/china-blocks-foreign-acquisition-ai-0825482...
3•jmsflknr•59m ago•0 comments

Notes on Serial Experiments Lain

https://jordanmatthiass.net/essays/serial_experiments_lain
2•lilytweed•59m ago•0 comments

Open Source Mintlify Alternative

https://doccupine.com
1•luangjokaj•59m ago•1 comments

Open CoDesign: Open-source, local-first alternative to Claude Design and v0

https://firethering.com/open-codesign-ai-design-tool-open-source/
2•steveharing1•1h ago•0 comments

Tell HN: Ebay.com Is Down

4•NKosmatos•1h ago•1 comments

Enhancing Server Availability and Security Through Failure-Oblivious Computing [pdf]

https://people.csail.mit.edu/rinard/paper/osdi04.pdf
1•pabs3•1h ago•0 comments

The "Connectivome Theory": A New Model to Understand Autism Spectrum Disorders

https://pmc.ncbi.nlm.nih.gov/articles/PMC8892379/
1•AndrewDucker•1h ago•0 comments

Recursive Acronym

https://en.wikipedia.org/wiki/Recursive_acronym
1•Quizzical4230•1h ago•0 comments

Soulful Sites

https://app.paradigmai.com/sheets/76210606-6ce4-4ccc-a005-fb1cf6984a45
1•sauravmaheshkar•1h ago•0 comments