Regardless of whether or not you provide your own SSL certificates, cloudflare still uses their own between their servers and client browsers. So any SSL encrypted traffic is unencrypted at their end before being re-encrypted with your certificate. How can such an entity be trusted?

You are viewing a single thread.
View all comments
1 point

I mean, we trust Root Certification Authorities, which are basically self-proclamed-as-trusted entities. At least CF became widespread and is community-trusted :)

permalink
report
reply
1 point

Good point. Who’s to say that LetsEncrypt doesn’t keep a copy of my private keys?

permalink
report
parent
reply
3 points

A certificate authority doesn’t have a copy of your private key, you send them a certificate signing request. The private key never leaves your system. That’s the whole point of public key encryption.

permalink
report
parent
reply
0 points

Then trusting root CAs is a non-issue?

permalink
report
parent
reply
1 point

Because that’s not how certificates work?

Your private key is never sent to the CA with you submit a Certificate Signing Request, only the public key and a bunch of metadata.

(The exception being code signing certs that are delivered on an HSM but the key never leaves the HSM)

permalink
report
parent
reply

Self-Hosted Main

!main@selfhosted.forum

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

For Example

  • Service: Dropbox - Alternative: Nextcloud
  • Service: Google Reader - Alternative: Tiny Tiny RSS
  • Service: Blogger - Alternative: WordPress

We welcome posts that include suggestions for good self-hosted alternatives to popular online services, how they are better, or how they give back control of your data. Also include hints and tips for less technical readers.

Useful Lists

Community stats

  • 23

    Monthly active users

  • 1.8K

    Posts

  • 11K

    Comments

Community moderators