Web Security is Too Hard

Cloudflare’s launch of a new “Cloudflare Wallet” product on the separate domain cloudflare.pay sparked concern because it looked indistinguishable from a phishing site, highlighting how marketing-driven domain choices can undermine security norms. Commenters argue that organizational incentives, bureaucracy around creating official subdomains, and the proliferation of third-party or throwaway domains all contribute to an ecosystem where users cannot reliably tell legitimate services from scams. The conversation broadens into critiques of weak customer-support chatbots, legacy web security models, and the growing difficulty of establishing trustworthy online identity.

Marketing Domains & Phishing Confusion

  • Many see using cloudflare.pay instead of a cloudflare.com subdomain as indistinguishable from a phishing campaign.
  • Commenters list similar anti-patterns across the industry (banks, shipping, email surveys, app listing sites) where third-party or off-brand domains normalize scam-like UX.
  • Some argue this is a recurring “marketing vs security” failure: campaigns that bypass established domains, branding, and navigation paths.

Org Process, Subdomains, and Security Tradeoffs

  • Several speculate that internal controls make adding a subdomain on cloudflare.com slow and bureaucratic, pushing teams to buy new domains instead.
  • Others counter that this organizational dysfunction is precisely the problem that needs fixing, not routed around with new TLDs.
  • There’s debate over security differences between subdomains vs separate domains:
    • Subdomains can inherit cookies and pose extra risk.
    • But separate domains can be forgotten, lapse, or be more opaque to internal oversight and users.

AI Chatbots and Support Quality

  • The product chatbot denying the existence of the new wallet is used to criticize “AI support” that isn’t wired into real product knowledge.
  • Some say this simply replaces equally underinformed, under-resourced human support; others insist even cheap human support usually hears about major launches faster.
  • Chatbots are described as cost-cutting, investor-pleasing, and increasingly a “social signal” (like carousels once were), often with low real utility.

Web Security, Identity, and the Modern Web

  • Several argue the core issue is digital identity: it’s increasingly hard to know who’s behind a site or message.
  • There’s a side debate over whether “web as app platform” and JavaScript worsened security, vs being a necessary evolution for billions of users.
  • Multiple readers admit they initially assumed the wallet site was a scam, then realized it was legitimate—seen as proving the article’s point.

Cloudflare’s Reputation and Certificates

  • Commenters express disappointment that a security-branded company shipped something that looks like phishing on day one.
  • Others note that hiring top talent or providing infrastructure doesn’t guarantee moral choices or good UX.
  • Examination of TLS and WHOIS shows only domain-validated certs with redacted owner info, so certificates do little to help users connect cloudflare.pay to cloudflare.com.