Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Are you using CF as a proxy or only for DNS? I ask because I just went to check my domains on the dashboard (some purchased a few years ago, one purchased just a couple days ago), and none of them have Web Analytics enabled.
I have all my domains set to DNS only, so no CF proxy. Wondering if that is why?
by outlines - Hacker News already knows, nobody gave shit when they first announced it. I assume because it didn't have AI in the title?by ChoGGi
- This reminds me of the old free hosts that would inject their own scripts/ads on pages hosted by them, but their implementation would do it only after detecting the closing HTML tag (either </body> or </html>, can't remember) and the various tricks to get around it, including omitting the tag (browsers don't care), rAnDoM case tags (some were hardcoding lower or upper and comparing case-sensitively), and messing with the content type and relying on the browser to detect correctly since it didn't inject into other types (not sure how the current browsers will handle that).by userbinator
- If you're only using Cloudfare for DNS, but HTTPS connections go directly to your server, how does it inject HTML?
You must be allowing Cloudfare to terminate your HTTPS connections; i.e. using them for actual proxying.
by kazinator - by dchest
- I have "Enhanced Tracking Protection" strict mode enabled in Firefox and surprise surprise it is allowing `static.cloudflareinsights.com` not blocking it.
So much for "Firefox shields you as you browse, blocking trackers automatically so you’re in control of your digital trail" Mozilla.....
Edit to add:
I have been doing a little experimenting, it looks like there might be some sort of hardcoded whitelist somewhere in Firefox ?
When I first wanted to check, I visited `cloudflare.com` as it seemed the obvious place to find `static.cloudflareinsights.com` and Firefox shield blocks nothing there (hence I made this post)
However, then I tried to find a different site, and after a bit of random searching/clicking around I found `www.tenforums.com` and `static.cloudflareinsights.com` is blocked on there.
Its not a first-party domain thing, since cloudflare.com != cloudflareinsights.com.
Surely `static.cloudflareinsights.com` should be blocked everywhere in strict mode, no exceptions ?
Interestingly, when testing other sites, I have also been discovering other things Firefox shield is failing to block, e.g. `browser.events.data.microsoft.com` (tested on a non microsoft.com site)
by traceroute66 - An alternative: <meta http-equiv="Content-Security-Policy" content="script-src 'self' https://only-scripts-allowed-from-here.com">
This makes the client only load self-hosted scripts, or scripts only from the specified origins, among the other directives CSP allows (e.g. restricting styles, images, frames, etc.): https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP
by okzgn - You are right that Cloudflare enabled these analytics by default for our free plans in Septemeber of last year.
We built Real User Measurement (RUM) into our free plans because it gives site owners actionable performance data they would not otherwise have. It is on by default for free sites fr the reasons we wrote about in the blog post below. It is easy to disable if you don't want it on. All of our paid plans are opt-in only.
This also gives free plans access to our Observatory product at no cost. Observatory is a performance-monitoring tool inside the Cloudflare dashboard that combines real user data with simulated lab tests to help you measure and improve your website speed.
Blog post: https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana...
by leinwand