CloudFlare adds TLS 1.3, automatic HTTPS rewrites and opportunistic encryption upgrades as default for all its client websites
HTTPS Everywhere is a Firefox, Chrome … Sean Michael Kerner / eWeek : CloudFlare Implementing Latest Draft of TLS 1.3 Charlie Osborne / ZDNet : CloudFlare tackles unencrypted internet with new features Lily Hay Newman / Wired : Cloudflare Launches a Three-Pronged Attack to Encrypt the Entire Web
Context & Ripple Effects
CloudFlare is flipping its defaults: every website on its network now gets the draft TLS 1.3, automatic rewrites of insecure HTTP links, and opportunistic encryption upgrades without the site owner doing anything. The move builds on two prior steps in this arc — CloudFlare's rollout of HTTP/2 to all users a year earlier, and Mozilla's decision to enable opportunistic encryption by default in Firefox 37 — both of which treated encryption as something the platform ships rather than something each publisher configures.
The significance is scale: because CloudFlare terminates connections for a large share of the web's sites, changing its defaults changes what 'normal' looks like for the whole ecosystem, ahead of browsers and certificate authorities rather than waiting on them.
First-order effects
- Millions of CloudFlare client sites become HTTPS-capable overnight with no certificate work or code changes from their owners, and pages mixing secure and insecure resources get silently rewritten to HTTPS.
Second-order effects
- Browsers face pressure to match the CDN's pace — Chrome and Firefox went on to ship the finalized protocol two years later once the IETF released the final version of TLS 1.3 — while certificate authorities and hosting providers see demand shift toward automated, default-on encryption they must replicate to stay relevant.
Third-order effects
- If platform-level defaults keep outrunning per-site configuration, encryption stops being a publisher decision entirely and becomes an infrastructure property — the foundation on which later privacy work like Cloudflare and Apple's Oblivious DNS-over-HTTPS protocol was built.
The trend: Web encryption is shifting from an opt-in choice made site by site to a default enforced by the platforms — CDNs and browsers — that sit between publishers and users.