Hacker News new | past | comments | ask | show | jobs | submit login

It's especially important to realize that Cloudflare offering free TLS for everyone isn't enough to prevent javascript-based DDOS, if you don't make sure that third-party resources are also behind TLS.



I think "use our free TLS" is directed towards the people who host scripts that get embedded by people, like baidu.

Embedding scripts that are hosted behind cloudflare is a terrible idea though.


It does a lot considering the fact that most resources on a page served over HTTPS also have to be served over HTTPS.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: