Every root domain also has a subdomain wildcard line (*.example.com), which we deleted to save space.

We compiled this list by attempting a handshake with the Cloud Flare domains in our database.

But imagine that you are a government regulator in a country where a big ISP hosts a Cloud Flare "data center." Your job is to consider the Internet in terms of public safety and current laws, and you go to that ISP with a list of Cloud Flare-user domains you want blocked.

The ISP replies that everything is encrypted, and Cloud Flare traffic cannot be intercepted.

By now we're wondering if there's a plaintext Ethernet port at the back of their equipment rack that makes interception easy and convenient.

If so, it would make no difference whether the origin server has its own certificate.

Almost everyone who browses a https domain reached from Cloud Flare is unaware that just half of the route is encrypted.

When they see the padlock on their screen, they feel that everything is safe. It's easy to use for a cybercriminal with numerous domains hidden behind the privacy services of various registrars.

The "standard" certificates on this page (with "ssl" in front of the number instead of "sni") mean that the domain has a paid account at Cloud Flare.Paid accounts make up about five percent of the domains that use Cloud Flare, according to news reports.

