Hey, crypto-trade.net
I've just been reading up on how Cloudflare's SSL works. It looks like crypto-trade.net doesn't have its own dedicated SSL certificate, so it's using one from Cloudflare. If I understand correctly, this means that by default, only the traffic between the user's browser and Cloudflare is encrypted HTTPS; the connection between Cloudflare and the web site's web server is standard HTTP, which can be sniffed or altered without the end user or site they're accessing being aware of it.
"CloudFlare offers three modes for HTTPS: Flexible, Full and Strict. In Flexible mode, traffic from browsers to CloudFlare is encrypted, but traffic from CloudFlare to a site's origin server is not. In Full and Strict modes, traffic between CloudFlare and the origin server is encrypted. Strict mode adds validation of the origin servers certificate. We strongly encourage customers to select Strict mode for their websites to ensure their visitors get the strongest data security possible."
Can you please confirm that you're NOT using the default "Flexible" configuration at Cloudflare? In other words, is the traffic between Cloudflare and your server encrypted? If so, why don't you have a dedicated certificate for crypto-trade.net?
Thanks.
Hello. Traffic between CloudFlare and crypto-trade.net also encrypted, we have a own SSL certificate.
