Cloudflare's privacy promise: audited, but is it enough?
Cloudflare, the ubiquitous content delivery network, is finding itself embroiled in a fresh wave of scrutiny, just as it seemed to weather previous storms. While lauded for its speed and accessibility, the company’s commitment to user privacy is now under the microscope following a recent audit and persistent allegations concerning its role in facilitating piracy.
The laliga controversy and the shadow of piracy
The tempest began with accusations from LaLiga, the Spanish football league, alleging that Cloudflare’s services were inadvertently aiding the proliferation of illegal IPTV streams. The league’s relentless efforts to shut down these pirate operations have put Cloudflare’s free tier—a popular, if controversial, offering—in the crosshairs. Several users have already faced fines of €400 for streaming matches, highlighting the legal ramifications of this ongoing battle.

Dns servers: speed vs. privacy
At the heart of the debate lies Cloudflare’s public DNS servers, accessible via the easily remembered addresses 1.1.1.1 and 8.8.8.8 (a nod to Google’s own DNS offering). These servers, handed over by APNIC in 2018, prioritize speed and ease of configuration across devices. But the convenience comes with a potential cost: user data.
Cloudflare has consistently maintained that it doesn't sell user data or personalize advertising, even claiming to disregard IP addresses. “Frankly, we don’t want to know what you do on the internet—it’s none of our business—and we’ve taken technical measures to ensure we can’t,” the company asserts. However, the reality, as revealed by a recent audit, is more complex.

The kpmg audit: a mixed bag of findings
To celebrate its eighth anniversary, Cloudflare commissioned KPMG, one of the “Big Four” accounting firms, to audit its DNS operations throughout 2024. KPMG had full access to activity logs, and their findings, while largely supportive of Cloudflare’s privacy claims, revealed a crucial detail: Cloudflare does retain IP addresses, albeit in a truncated form. For IPv4 addresses, the final byte is removed (e.g., 192.168.1.1 becomes 192.168.1.x), and 80 bits are stripped from IPv6 addresses. This data is held for a limited period – 25 hours – before being purged.
Furthermore, KPMG confirmed that routers within Cloudflare’s data centers have Syslog disabled, meaning that only a small sample—approximately 0.05%—of network packets are analyzed for cybersecurity threats or network monitoring. Despite this limited sampling, the audit ultimately confirmed Cloudflare’s pledge not to record user browsing data.

The lingering questions
While the KPMG audit provides a degree of reassurance, questions persist. The truncation of IP addresses, even if temporary, raises concerns about potential re-identification and the possibility of correlation with other data sources. The company’s willingness to share data with law enforcement agencies, as demonstrated in past instances, adds another layer of complexity. The inherent tension between facilitating a free service and guaranteeing absolute privacy remains a challenge for Cloudflare, a challenge that will undoubtedly continue to shape the debate surrounding its role in the digital ecosystem.
The fact that a firm of KPMG’s stature found that Cloudflare does, in fact, log IP addresses—even partially—undermines the company’s previous assurances. It's a subtle but significant shift in understanding, and one that users should carefully consider before entrusting their DNS requests to Cloudflare.
