A few hours ago I switched my nameservers to Cloudflare in order to enable R2 bucket serving through my own subdomain, and I found out that it silently had injected a JS analytics snippet in my HTML-only JS-free site textlog.cc — I had to go to the Analytics dashboard, Add the site to the analytics and then disable the snippet. I find this approach entirely invasive, you should opt-in to features like that not have to opt-out. Just a warning out there to folks who might not be aware of this.
Tell HN: Cloudflare silently injects its analytics when you switch nameservers
Why This Matters
This incident highlights concerns over transparency and user control when major providers like Cloudflare introduce features that can impact website privacy and performance without explicit user consent. It underscores the importance for developers and consumers to stay vigilant about changes in service behavior that may affect their sites or data. As the industry evolves, prioritizing clear communication and opt-in mechanisms becomes crucial for maintaining trust.
Key Takeaways
- Cloudflare silently injects analytics code when switching nameservers.
- Users must manually disable the injected code via the Analytics dashboard.
- The incident raises broader concerns about transparency and user control in web services.
Get alerts for these topics