I’ve never understood the evil MITM endgame here. Cloudflare’s ToS and contracts prevent them from doing nastiness with your data without breach, and approximately all their revenue comes from large enterprises that will leave in droves (and some will actually sue them) if they started exploiting it.
The thing where they let DDoSers use them to protect their public sites from rival DDoSers is sketchy as hell, but doesn’t rely on having your data.
Sure, they could try adding “your data is our data” on the renewal of a few million dollar enterprise contract and see how that goes - probably a redline with a nasty Zoom call attached. They could rug-pull this on free and small business users to a degree, but I don’t even see how it would be worth it. It’s such a small proportion of their traffic, and the fact that this is even a thing on their platform would scare away regulated customers for sure.
>Cloudflare’s ToS and contracts prevent them from doing nastiness
Crypto AG's ToS also presumably said "we pinky promise not to backdoor our devices" when selling it to foreign governments, and look how they ended up.
The thing where they let DDoSers use them to protect their public sites from rival DDoSers is sketchy as hell, but doesn’t rely on having your data.