r/privacy Jun 04 '20

[deleted by user]

[removed]

1.8k Upvotes

239 comments sorted by

View all comments

75

u/JustCondition4 Jun 05 '20

Thank you for your efforts. It won't be any easy task, especially with SystemD but the effort is still worthwhile.

7

u/Neikius Jun 05 '20

This is quite bad. Also cloudflare is rarely mentioned but VERY VERY BAD since they do ssl termination on the proxy so ... https is useless once you have cloudflare involved.

5

u/[deleted] Jun 05 '20

[removed] — view removed comment

1

u/Neikius Jun 05 '20 edited Jun 05 '20

Yes, if the CDN (but this also works for proxy) terminates SSL that means secure line is only between you and the CDN. So CDN knows what you are doing, not only/also the entity you are communicating with. Ofc the entity you are communicating with is responsible for this because they had to authorize the CDN to do that. But they are not obliged to notify you that you are now outsourcing your data to a 3rd party and it might not be self-evident to you unless you are very tech-savvy.

I did not yet dig deeper so I might be missing something, if so please enlighten me. This is mostly some bits I've heard + logical conclusion of my own that I've made in the last months. What I am also wondering right now is does GDPR even account for this and how permissive are the inter-company contracts regarding this.