Web Security is Too Hard
Cloudflare’s launch of a new “Cloudflare Wallet” product on the separate domain cloudflare.pay sparked concern because it looked indistinguishable from a phishing site, highlighting how marketing-driven domain choices can undermine security norms. Commenters argue that organizational incentives, bureaucracy around creating official subdomains, and the proliferation of third-party or throwaway domains all contribute to an ecosystem where users cannot reliably tell legitimate services from scams. The conversation broadens into critiques of weak customer-support chatbots, legacy web security models, and the growing difficulty of establishing trustworthy online identity.
Marketing Domains & Phishing Confusion
- Many see using
cloudflare.payinstead of acloudflare.comsubdomain as indistinguishable from a phishing campaign. - Commenters list similar anti-patterns across the industry (banks, shipping, email surveys, app listing sites) where third-party or off-brand domains normalize scam-like UX.
- Some argue this is a recurring “marketing vs security” failure: campaigns that bypass established domains, branding, and navigation paths.
Org Process, Subdomains, and Security Tradeoffs
- Several speculate that internal controls make adding a subdomain on
cloudflare.comslow and bureaucratic, pushing teams to buy new domains instead. - Others counter that this organizational dysfunction is precisely the problem that needs fixing, not routed around with new TLDs.
- There’s debate over security differences between subdomains vs separate domains:
- Subdomains can inherit cookies and pose extra risk.
- But separate domains can be forgotten, lapse, or be more opaque to internal oversight and users.
AI Chatbots and Support Quality
- The product chatbot denying the existence of the new wallet is used to criticize “AI support” that isn’t wired into real product knowledge.
- Some say this simply replaces equally underinformed, under-resourced human support; others insist even cheap human support usually hears about major launches faster.
- Chatbots are described as cost-cutting, investor-pleasing, and increasingly a “social signal” (like carousels once were), often with low real utility.
Web Security, Identity, and the Modern Web
- Several argue the core issue is digital identity: it’s increasingly hard to know who’s behind a site or message.
- There’s a side debate over whether “web as app platform” and JavaScript worsened security, vs being a necessary evolution for billions of users.
- Multiple readers admit they initially assumed the wallet site was a scam, then realized it was legitimate—seen as proving the article’s point.
Cloudflare’s Reputation and Certificates
- Commenters express disappointment that a security-branded company shipped something that looks like phishing on day one.
- Others note that hiring top talent or providing infrastructure doesn’t guarantee moral choices or good UX.
- Examination of TLS and WHOIS shows only domain-validated certs with redacted owner info, so certificates do little to help users connect
cloudflare.paytocloudflare.com.