iirc, custom DNS at CF refers to using your own subdomains as name servers for CF instead of the regular *.ns.cloudflare.com. Basically a form of whitelabelling.
Specifying 3rd party name servers as your domain’s name server was (still is?) not possible with Cloudflare Registrar.
Actually, you can assign (not transfer) IP ranges and the one advertising it does not need to own it, but would need a Letter of Authorization (LoA) or similar.
Google now has a publicly available ACME-compatible CA. For CF’s Universal SSL (default/free) Cloudflare may use Google’s CA. But may choose other providers. For Advanced Certificate Manager (paid addon), you can choose Google or other CAs for Cloudflare.
But basically Google would be the one that is issuing an SSL cert for a website. Same as LetsEncrypt.
Swapfiets builds their own bikes and does not - never ever - sell them. If one gets stolen, it can‘t be resold without one noticing it’s stolen, as these are not in circulation in the first place and still owned by the company that built them
The cheapest over time will be .de with as less as 4€ a year depending on the registrar. The cheapest first year domain used to be .xyz with 0.99$ at Namecheap
For CF, we send out these status pages manually. It's usually delayed due to wording, but not to tamper with the SLA. We do keep track of the accurate times AFAIK.
That’s what Certificate Transparency is for. If CT is required by the client, then the wrongfully issued certificate could be detected and the CA be reported for that.
What I did after having argued several times is to straight up let them know that this isn’t true, told one or two examples on why these arguments are fake most of the time and that if they want to find arguments against it, that they would find some. Then I stop talking about such topics with them.
In my opinion, it‘s just not worth after having spent some time trying to discuss it with them. Especially when they don’t provide any backed arguments but just „random“ statements
Depending on what you’d like to do with it, you could get a server at a hosting provider that allows you to send in USB sticks with data and uploads it for you (makre sure the content is encrypted though) or get a colo with your own server which you then would have access to.
If you just need it as a cache as mentioned in another comment, you can go with a VPS
Subdomain points to a hosting provider. Hosting doesn’t know who the owner is (yet) and waits for someone to sign up/register. Attacker signs up before the real owner does, is lucky that the hosting provider does not verify ownership, and is able to serve whatever they want on the domain, for example a fake website or fake verification files.
I think one of the major advantages a tech company can have against their competitors is their culture and recently, Google seems to be losing out on this a lot. IMHO there is a huge difference between companies that just have workers and companies that are a group of people working towards a common goal/vision