From cdabe7a75ea14f14ca8d4cd3bf9ac36cb1817531 Mon Sep 17 00:00:00 2001 From: neodarz Date: Fri, 28 Apr 2017 19:05:18 +0200 Subject: Delete some usless file --- ...6-09-01-this-blog-is-now-behind-cloudflare.html | 54 ---------------------- 1 file changed, 54 deletions(-) delete mode 100644 build/blog/2016-09-01-this-blog-is-now-behind-cloudflare.html (limited to 'build/blog/2016-09-01-this-blog-is-now-behind-cloudflare.html') diff --git a/build/blog/2016-09-01-this-blog-is-now-behind-cloudflare.html b/build/blog/2016-09-01-this-blog-is-now-behind-cloudflare.html deleted file mode 100644 index 9f87bab9..00000000 --- a/build/blog/2016-09-01-this-blog-is-now-behind-cloudflare.html +++ /dev/null @@ -1,54 +0,0 @@ - - - - - - - -This blog is now behind CloudFlare - - - - - - - - -
This blog has been archived.
Visit my home page at zhimingwang.org.
- -
-
-

This blog is now behind CloudFlare

- -
-

Back in July I registered the domain zhimingwang.org and pointed this GitHub Pages-powered blog at it. Since then I have lost the HTTPS badge due to GitHub Pages not supporting HTTPS on custom domains (see isaacs/github#156).

-

There have been a lot of discussions on isaacs/github#156 (and stupid +1's too). Among the proposed solutions is putting the website behind CloudFlare. I carefully investigated this option and read almost all the arguments against it. I fully understand CloudFlare's SSL models (summarized in the image below), and I do realize most if not all of the limitations of CloudFlare, including CloudFlare being a huge MITM (which is inevitable for a CDN anyway), as well as most if not all of its annoyances, including CAPTCHAs which I myself would occasionally run into when I'm browsing with PIA VPN, and JavaScript-based browser checks.

-
-CloudFlare's SSL modes. I use the Full SSL mode so that both ends of the connection are encrypted. Again, I know CloudFlare is a big MITM and could be a high profile target. Credit: CloudFlare. -

CloudFlare's SSL modes. I use the Full SSL mode so that both ends of the connection are encrypted. Again, I know CloudFlare is a big MITM and could be a high profile target. Credit: CloudFlare.

-
-

After careful evaluation, I decided that CloudFlare's SSL model is good enough for me. After all, this is just a damn blog, with nothing sensitive. TLS is still nice because it guards against prying eyes and unethical ad-injecting ISPs or Wi-Fi hotspots, but other than that, it isn't necessary.

-

End result: this blog is now behind CloudFlare. Readers should now see that green HTTPS badge again (note that I'm enforcing HTTPS — without HSTS though). As for CAPTCHAs, I have adjusted the firewall settings on CloudFlare's dashboard — "Security Level" to "Essentially Off" and "Challenge Passage" to 1 year, so hopefully it won't be too annoying.1

-

09/01/2016 Update. I just realized that CloudFlare supports whitelisting Tor traffic. Did that.

-
-
-
    -
  1. I don't use Tor, and don't intend to raise Big Brother's suspicion by using it, so I have no idea of the actual Tor experience.â†Šī¸Ž

  2. -
-
-
-
- - - -- cgit v1.2.1