Well done, I guess?
I did it!
With the thing about SSL certificates having a cost, you can use Cloudflare to get free SSL to cover your whole domain. Though it does mean adjusting your nameservers to point to Cloudflare.
Any time I see CF mentioned, I feel obligated to share my thoughts.
Any time that you use Cloudflare, they set a very strong expectation that you will use
their proxy service.
For example, here's Cloudlfare's
SSL/TLS page. When we click the "View Docs" button, we're greeted with this:
SSL/TLS certificates encrypt traffic between visitors and your website, preventing eavesdropping and data tampering. Because Cloudflare sits between your visitors and your origin server, two certificates can be involved in a single request[...]
Wait, what? There's nothing about TLS that
requires a random mega-corp to intercept all of your traffic. They're immediately operating on the expectation that you
will give them that access. And if you went to CF simply trying to understand how to add TLS to your site, you
are going to end up using their proxy service because
they typically avoid telling you that there's any alternative.
Now, their proxy service can offer some awesome benefits if you're hosting your own website, like bypassing NAT and local firewall rules, but their position as a man-in-the-middle also has certain privacy and security implications, which tend to get glossed over.
In order to provide their services, they need to terminate TLS (decrypt) the data passing through them. While it's incredibly unlikely that they would ever abuse this ability, it does,
in theory, allow them to alter and censor your page's content without the knowledge of you or your users. I created a demonstration of this on my blog,
here.
Now, it's totally fair to trust Cloudflare. They're a massive company, and they have huge profits that could be seriously jeopardized if they began to misuse or abuse their customers* trust; in other words, there's no benefit to them to risk their reputation just to screw with your personal site... But, if you're someone who enjoys the smaller-web because you value privacy, security, and freedom of expression, then it's worth at least considering whether you want to intentionally give them that trust.
* It's potentially questionable whether you're actually their customer in this situation. As the saying goes, if you're not paying for a service, then you're not the customer --you're the product.