CF is amassing a lot of power. With 30% of all Internet Traffic going through CF and them decrypting all HTTPS traffic at the Edge...and able to change any or all of it transparently. This extract from CF's blog reads like a Government/Thread Actor's dream come true....
@thc if they modify the continent and re-sign the HTTPS, will the certificate signature be for them rather than the source site?

@guigsy Your question is misguided.

Despite the original architecture, most present-day SSL certificates used for HTTPS don't certify an entity but an endpoint.

@thc