My discussions with Mathjax developers led me to post a question on
security.stackexchange, and I am now satisfied that what Cloudflare is
doing with SSL certificates, although it is somewhat out of the ordinary,
does not allow someone controlling one of those sites to MITM requests to
another of them. So if we load Mathjax over HTTPS, we are only trusting
mathjax.org and Cloudflare.

https://github.com/mathjax/MathJax/issues/885
http://security.stackexchange.com/q/64738/53098

