Tell HN: Cloudflare silently injects its analytics when you switch nameservers

A few hours ago I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site textlog.cc — I had to go to the Analytics dashboard, Add the site to the analytics and then disable the snippet. I find this approach entirely invasive, you should opt-in to features like that not have to opt-out. Just a warning out there to folks who might not be aware of this.

147 points | by stagas 3 hours ago

21 comments

  • dchest 1 hour ago
  • okzgn 35 minutes ago
    An alternative: <meta http-equiv="Content-Security-Policy" content="script-src 'self' https://only-scripts-allowed-from-here.com">

    This makes the client only load self-hosted scripts, or scripts only from the specified origins, among the other directives CSP allows (e.g. restricting styles, images, frames, etc.): https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CSP

  • purpleidea 2 hours ago
    Yikes! I see this too:

    <script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>

    • kevincox 47 minutes ago
      Yup, I explicitly had all anaytics turned off. But had a few sites using Cloudflare for caching. Now I'm checking and seeing this on all of them. This is gross and unacceptable. "Caching" does not mean "modifying my site".
  • Animats 1 hour ago
    > injected a JS analytics snippet in my HTML-only JS-free site textlog.cc

    Cloudflare injected hostile code into a site they are not even hosting? If it's HTTPS, how do they even do that?

    Does it violate the "exceeds authorized access" provision in the Computer Fraud and Abuse Act?

    • bawolff 48 minutes ago
      The most likely answer is the person accidentally enabled the cloudflare reverse proxy without understanding what they were doing.

      It seems incredibly unlikely cloudflare does this when just DNS hosting, if for no other reason then that this would break so many things.

      • stagas 46 minutes ago
        I can’t recall if there was a setting to enable reverse proxy, if there was it was On by default since I didn’t expect to have reverse proxy enabled as well. But you can also rp without injecting a script. That’s overdoing it.
      • dboreham 13 minutes ago
        I don't know what happened in this situation but beware that CF and similar providers are not true DNS hosting providers. They do DNS, but only so their CDN stuff works, and to lock their customers from using whatever DNS hosting they want. Various things that one might reasonably want to do with your DNS zone are not possible with their product. So use it only because you need to do so in conjunction with their core services.
    • Touchnow 37 minutes ago
      [dead]
  • celsoazevedo 2 hours ago
    Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
    • stagas 1 hour ago
      No, I hadn’t enabled for any site. I had to enable first to turn it off.
  • outlines 1 hour ago
    Are you using CF as a proxy or only for DNS? I ask because I just went to check my domains on the dashboard (some purchased a few years ago, one purchased just a couple days ago), and none of them have Web Analytics enabled.

    I have all my domains set to DNS only, so no CF proxy. Wondering if that is why?

    • stagas 1 hour ago
      I just went and switched them to DNS only, they were on Proxy by default, that also should have been opt-in. Maybe I missed the option while switching the nameservers because I did it in a hurry but still.
      • TiredOfLife 39 minutes ago
        > that also should have been opt-in.

        The proxy is like 99% of why people use Cloudflare

        • stagas 33 minutes ago
          A simple screen when I did the switch that requires explicitly ‘Enable Proxy’ or ‘skip for now’ would have been enough. Also for ‘Enable Analytics’. None of these existed, or not very obvious otherwise I’d seen them.
  • ValentineC 1 hour ago
    Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.
  • windexh8er 2 hours ago
    Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.
    • JoshTriplett 1 hour ago
      They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.
      • sscaryterry 1 hour ago
        100% But this does not give you any useful personal data :)
        • JoshTriplett 1 hour ago
          Or data for the increasingly invasive Cloudflare captcha.
  • jjcm 22 minutes ago
    Thank you for this. I indeed had it up on mine. Cloudflare has switched defaults a couple times now, which honestly is wild to me.
  • Symbiote 31 minutes ago
    It's not necessary to use Cloudflare hosted DNS to use R2 with a custom subdomain.

    Make a CNAME record the same way you would for a CDN subdomain.

    (I am not yet running this in production, YMMV.)

  • BorisMelnik 1 hour ago
    yep, last website I did was JS free 100% except that pesky cloudflare script
  • p0w3n3d 15 minutes ago
    Spies. Spies everywhere
  • monitorion 48 minutes ago
    We use Cloudflare tunnels for connecting distributed workers to central infrastructure. Haven't seen this on tunnel traffic, but good to know it happens on nameserver-managed sites. Another reason to audit what your CDN injects — same applies to checking your security headers regularly.
  • minraws 1 hour ago
    Is there an opt-out mechanism at least? CF is burning goodwill in months it built over the last decade.
  • csomar 2 hours ago
    To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
  • pudgywalsh 1 hour ago
    You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.

    If they can inject script, they can also snoop on all your cleartext traffic without you knowing....

    • stagas 1 hour ago
      Oh gosh I didn’t enable anything like that also. I just wanted the nameservers in order to serve the bucket under my subdomain. What else is there I wonder?
      • stagas 1 hour ago
        Ok to turn this off you go Domains → Overview → your.site → DNS → Records → then Edit each entry to DNS Only (gray cloud). MITM gone now (I hope).
    • johntash 1 hour ago
      Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
  • moktonar 1 hour ago
    Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
    • _def 1 hour ago
      If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
      • Bender 24 minutes ago
        I don't know what would give anyone that idea. [1]

        [1] - https://www.youtube.com/watch?v=a3Xxi0b9trY

      • LoganDark 1 hour ago
        Cloudflare is doing this already. Once they had enough monopoly power, they started a program to block all bots that don't undergo invasive KYC procedures. Eventually, they might become a KYC broker for regular browser users too. The free internet is over.
  • yogorenapan 1 hour ago
    Noticed this the other day as well. Sketchy as fuck. I didn't have analytics enabled. I had to go and enable to get access to the option to turn this off