Tell HN: Cloudflare silently injects its analytics when you switch nameservers
68 points by stagas 2 hours ago | 12 comments
A few hours ago I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site textlog.cc — I had to go to the Analytics dashboard, Add the site to the analytics and then disable the snippet. I find this approach entirely invasive, you should opt-in to features like that not have to opt-out. Just a warning out there to folks who might not be aware of this.

ValentineC 15 minutes ago
Took me a minute to realise this isn't 1.1.1.1 (which Cloudflare also runs), but their original website DNS hosting service.
reply
celsoazevedo 28 minutes ago
Yes, they add the js if "web analytics" is enabled. I believe I had to manually enable it on my old sites though. Maybe it's enabled by default when adding new domains?
reply
purpleidea 26 minutes ago
Yikes! I see this too:

<script type="module" src="https://static.cloudflareinsights.com/beacon.min.js/v4513226..." integrity="sha512-ZE9pZaUXND66v380QUtch/5sE9tPFh2zg45pR2PB0CVkCtOREv2AJKkSidISWkysEuQ0EH8faUU5du78bx87UQ==" data-cf-beacon='{"version":"2024.11.0","token":"c0859b51a7804ab5a9cc8e9e2b2c4cde","r":1}' crossorigin="anonymous"></script>

reply
BorisMelnik 5 minutes ago
yep, last website I did was JS free 100% except that pesky cloudflare script
reply
windexh8er 34 minutes ago
Isn't this well known when using CF as a proxy? Not sure how they would provide traffic / DDoS telemetry otherwise.
reply
JoshTriplett 4 minutes ago
They're serving the HTML, they have every ability to track individual web requests without modifying the content they're serving.
reply
pudgywalsh 8 minutes ago
You left out the part about how you use them as a reverse proxy, which is decoupled from DNS. One is coincidental; the other required.

If they can inject script, they can also snoop on all your cleartext traffic without you knowing....

reply
johntash 24 seconds ago
Indeed. I have several domains using cf for dns only and they don't/can't inject anything into those sites.
reply
csomar 37 minutes ago
To add to your experience: It was also very hard, for me, to find the setting that disables this JavaScript.
reply
moktonar 19 minutes ago
Surprise! The man in the middle man-in-the-middles! This is only the beginning, when you’ll get used to this they’ll do worse and worse, enshittification, remember?
reply
_def 4 minutes ago
If I wouldn't know it better I'd sometimes think some of the big tech shops are just fronts for centralizing the net.
reply