I have every confidence that CF doesn't do that today, but since it's the termination point for TLS for a HUGE portion of the internet (including my own sites ;p), that seems like a huge target for feds to try to tap into. I think a lot of peoples' concern is that someday it could happen under a more authoritarian cabinet and court. As long as it can be done, it eventually will.
Absolutely nobody wants that, save for a couple very under-educated and highly powerful individuals. But the rest of us might not have a choice.
But honestly, any casual consideration of Occam's razor with relation to your company's actions would be much more simply understood if we consider that Cloudflare wants to be a monopoly.
Is Cloudflare ever going to stop trying to centralize more and more of the Internet? Please - go ahead and tell me about how, at some point, because you care so much about being trusted, you'll say, "You know what? We're getting too big. Let's pump the brakes on that and help out some other companies so the Internet's resilience won't be harmed."
Could that ever happen? Would that ever happen? Or will you just keep finding excuses and telling lies about how what you're doing for the world is for "everyone's own good"?
- Room 641A wasn't the end of AT&T, and I'm sure the three-letter agencies have a way to make your economic interest align with theirs (e.g. through legal or extralegal threats).
- Even if you personally are trying to prevent it, they can compel employees and plant a backdoor, possibly a non-obvious kleptographic one in the encryption you use in the backbone. You might genuinely not know if it was happening (and if you knew, you'd be forced to deny it, both to preserve the stake you mentioned and presumably due to dire consequences from the three-letter agencies if you talked).
- Snowden revealed the existence PRISM, but the details and level of collaboration are still not really known today. The companies have certainly survived it. All the negatives sides of collaboration only manifest if it is discovered, which is far from guaranteed.
Just to be clear, this is not accusing you of being corrupt, malicious, or a willing participant, just pointing out the harsh reality that your wish to not participate in this may not matter much.
[0] - https://www.theguardian.com/world/2014/sep/11/yahoo-nsa-laws...
And yet AT&T has proven otherwise. [1][2]
[1] https://www.macrotrends.net/stocks/charts/T/at-t/stock-price...
care to elaborate on the interview you mention the DHS hinted to the value of CF (nee honepot)?
was it a formal feedback? from a person related to dhs but in a personal setting? how that happened? and what relationship continued/started from it?
By aggregating the whole internet onto Cloudflare you are creating choke points where fiber taps are far more effective to deploy than the previous situation where they needed to tap hundreds of different regional providers.
Sure you can do encryption for data in flight, but your keys and CA infrastructure now become one of the most valuable intelligence targets. Unless you can attest that not a single CF employee has family in China, or gambling problems here in the US, was born in Russia, etc. there is a weakness somewhere waiting to be exploited.
We don't care what makes financial sense for you now. One day you will be dead, and what you created will be taken private by a well resourced entity with less morals.