Cloudflare automatically adds analytics tracking to websites when users switch their nameservers to the service, requiring manual opt-out rather than opt-in. The discovery has raised concerns about consent and privacy practices.
A user reported that Cloudflare silently injected a JavaScript analytics snippet into their HTML-only, JavaScript-free website after switching nameservers to enable R2 bucket serving. The user had to manually navigate to Cloudflare's Analytics dashboard, add their site, and disable the snippet to remove the tracking code.
The incident highlights a broader concern about default-enabled features. Cloudflare's approach requires users to actively opt-out rather than opt-in, a distinction privacy advocates argue should be standard practice for tracking and analytics tools.
The user called the approach "entirely invasive," emphasizing that analytics features should require explicit user consent before deployment. While Cloudflare provides tools to disable the snippet, the automatic injection means many users may remain unaware their sites are being tracked.
This practice may prompt questions about Cloudflare's data collection policies and whether similar automatic features exist elsewhere in its service offerings.
Cryptocurrency hardware wallet provider SafePal disclosed a data breach affecting nearly 40,000 customers after a vulnerability was exploited to steal order information. A threat actor is now selling the compromised data.
Google has built theft-detection features into Android to help protect your phone. Activating these settings can prevent unauthorized access if your device is stolen.
French Prime Minister Sebastien Lecornu will hold a crisis meeting Monday to address a cyberattack on France's tax collection agency disclosed last week. The breach compromised approximately 678,000 individual and business accounts.
Most Android users don't need dedicated antivirus apps, thanks to built-in security features. However, certain usage patterns may warrant additional protection.