I doubt the jannies themselves are the spooks on 4chans. There is no way in hell that 4chan is free from spook monitoring.
That’s where you get into this idea that a website isn’t necessarily a honeypot. Not intentionally anyway. But they can subpoena cloudflare and get everything and the site owner might not even know.
If you’re too poor or lazy or don’t know how to do your own SSL and you run http , allowing cloudflare to manage and issue your certs and do http-> https , they’re a MITM and have access to everything in unencrypted form. While your visitors are lulled into a false sense of security because it’s “https.”
But then nothing’s encrypted between cloudflare and the website. At all. Even if your site admins would never willingly cooperate with LEO or give out your info, if they’re on cloudflare , they’re just never going to know.
Now that they’re turning the screws tighter and making SSL certs expire in 43 days , even more site admins will just go “oh how nice. cloudflare just does it for me and It Just Works(tm).” They can do flexible SSL that basically never expires, or full SSL that expires in 20 years but your options are “it’s not even encrypted at ALL” or “they generate the certs and still have the keys to decrypt everything!”
4chan doesn’t have private messaging and everything you post there is out there for everyone to read publicly anyway. But I just think it’s a little too pat and convenient that most of the Internet flows through and can be intercepted at Cloudflare and they don’t care if someone like me running a box on my shitty $5 VPS knows about or cooperates with a fishing expedition. To LEO, I’m more likely to roll my eyes, tell them to suck it, or tip off the subject of their investigation than CF is.
So Cloudflare kicked kiwifarms off their platform but Null is free to tell them to suck it or post about it. they can’t just go around him to CF anymore. Or intercept your private messages on kiwifarms, which would have been theoretically possible.