4 ms·
As a strong believer in the end-to-end principle, I don't understand what you mean. They have: * A reverse proxy service, open to anyone * A network-level tr
by DanielDent 10y ago
As a strong believer in the end-to-end principle, I don't understand what you mean.
They have:
* A reverse proxy service, open to anyone
* A network-level traffic volume management system, open to those that can afford it
I can come up with a ton of scenarios where both of these services actually help with the whole 'end-to-end' issue.
- mindslight 10y agoIt doesn't really matter who they'll provide service to, it matters how they alter the architecture of the network. The two ends in a communication are the user and the site publisher [0]. Cloudflare inserts an intermediate proxy. It doesn't matter that it's woven in using IP, just how it doesn't matter that CableCo's proprietary VoD service delivers over IP. [0] Or even two users wishing to chat or whatever - the same applies to the whole "web 2.0" bubble, but slightly less egregious than Cloudflare.
- DanielDent 10y agoBut do they actually alter the architecture of the internet? Or rather, how is Cloudflare making things worse or substantially different? Example plausible flows in the life of a packet or HTTP transaction: Before: Packet goes Comcast->Level3->HE->Destination After: Packet goes Comcast->Cloudflare->HE->Destination Note that Destination is the one choosing to replace Level3 with Cloudflare. If Cloudflare ceases to be a good choice, Destination can swap Cloudflare for an alternate provider. The use case where Cloudflare handles the HTTPS decryption (MITM-as-a-service) is a little bit different. Although it's become quite common, that's not the only way Cloudflare can be used. And I agree that's something where it changes things for the worse in some cases (but if it's a case of "Amazon's machines decrypt it for you" vs "Cloudflare's machines decrypt it for you", I'm less clear that a new problem is being introduced by Cloudflare).
- mindslight 10y agoIt's not a simple rerouting of a packet. It's a complete L5 decode/proxy/recode, inherently supporting only a few protocols. Putting this kind of functionality into the network is exactly what the end to end principle was reacting against.
- DanielDent 10y ago(1) Cloudflare does do BGP-based protection (rerouting of a packet) on their enterprise tier. (2) They really aren't adding functionality into the network. If I put a cluster of Nginx servers in front of my web server, or if I have Cloudflare do it for me, I don't see how that fundamentally changes anything. (3) The Cloudflare approach of an application layer proxy is feasible for any protocol which can be proxied. I've worked on SMTP proxies which do to SMTP what Cloudflare does to HTTP. Cloudflare also has a DNS proxy. Proxying is a perfectly valid and often incredibly useful technique.
- mindslight 10y ago1. Sure, they can do multiple things. When most people talk about Cloudflare, they're referring to the L5 interdiction. 2. You could make a similar argument about network gear having code to facilitate streams. Having a third party provide this functionality is further down the path of centralization. 3. Sure. The point is that to create/tweak protocols, you have to convince Cloudflare (etc) to implement. It's the end to end principle for a reason. It's not a hard and fast rule, in fact there are many immediate reasons for wanting centralization. It's just unsustainable in the far term.