Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
This is especially hilarious in face of the "HTTPS Everywhere" nonsense, everyone's paranoid of government glowies MITMing traffic to their Magic: The Gathering blog.
Meanwhile you and every major site out there stick it behind CF and hand them the keys to the back door. Guess who else can snoop that traffic.
Surprise! The man in the middle man-in-the-middles!
This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
Yikes! I see this too:
<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>
Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.
Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.
Indeed, https://blog.cloudflare.com/the-rum-diaries-enabling-web-ana...
Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.
They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.
100% But this does not give you any useful personal data :)
Or data for the increasingly invasive Cloudflare captcha.
yep, last website I did was JS free 100% except that pesky cloudflare script
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.
If they can inject script, they can also snoop on all your cleartext traffic without you knowing....
Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
This is especially hilarious in face of the "HTTPS Everywhere" nonsense, everyone's paranoid of government glowies MITMing traffic to their Magic: The Gathering blog.
Meanwhile you and every major site out there stick it behind CF and hand them the keys to the back door. Guess who else can snoop that traffic.
Bet you also trust the valet parking attendant.
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.