| ▲ | Tell HN: Cloudflare silently injects its analytics when you switch nameservers | |||||||
| 69 points by stagas 2 hours ago | 13 comments | ||||||||
A few hours ago I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site textlog.cc — I had to go to the Analytics dashboard, Add the site to the analytics and then disable the snippet. I find this approach entirely invasive, you should opt-in to features like that not have to opt-out. Just a warning out there to folks who might not be aware of this. | ||||||||
| ▲ | minraws a minute ago | parent | next [-] | |||||||
Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade. | ||||||||
| ▲ | purpleidea 26 minutes ago | parent | prev | next [-] | |||||||
Yikes! I see this too: <script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script> | ||||||||
| ▲ | ValentineC 16 minutes ago | parent | prev | next [-] | |||||||
Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service. | ||||||||
| ▲ | celsoazevedo 29 minutes ago | parent | prev | next [-] | |||||||
Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains? | ||||||||
| ▲ | dchest 9 minutes ago | parent | prev | next [-] | |||||||
Indeed, https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana... | ||||||||
| ▲ | windexh8er 35 minutes ago | parent | prev | next [-] | |||||||
Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise. | ||||||||
| ||||||||
| ▲ | BorisMelnik 6 minutes ago | parent | prev | next [-] | |||||||
yep, last website I did was JS free 100% except that pesky cloudflare script | ||||||||
| ▲ | pudgywalsh 9 minutes ago | parent | prev | next [-] | |||||||
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required. If they can inject script, they can also snoop on all your cleartext traffic without you knowing.... | ||||||||
| ||||||||
| ▲ | csomar 37 minutes ago | parent | prev | next [-] | |||||||
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript. | ||||||||
| ▲ | moktonar 20 minutes ago | parent | prev [-] | |||||||
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember? | ||||||||
| ||||||||