2 ms·
But do they actually alter the architecture of the internet? Or rather, how is Cloudflare making things worse or substantially different? Example plausible fl
by DanielDent 10y ago
But do they actually alter the architecture of the internet?
Or rather, how is Cloudflare making things worse or substantially different?
Example plausible flows in the life of a packet or HTTP transaction:
Before: Packet goes Comcast->Level3->HE->Destination
After: Packet goes Comcast->Cloudflare->HE->Destination
Note that Destination is the one choosing to replace Level3 with Cloudflare. If Cloudflare ceases to be a good choice, Destination can swap Cloudflare for an alternate provider.
The use case where Cloudflare handles the HTTPS decryption (MITM-as-a-service) is a little bit different. Although it's become quite common, that's not the only way Cloudflare can be used. And I agree that's something where it changes things for the worse in some cases (but if it's a case of "Amazon's machines decrypt it for you" vs "Cloudflare's machines decrypt it for you", I'm less clear that a new problem is being introduced by Cloudflare).
- mindslight 10y agoIt's not a simple rerouting of a packet. It's a complete L5 decode/proxy/recode, inherently supporting only a few protocols. Putting this kind of functionality into the network is exactly what the end to end principle was reacting against.
- DanielDent 10y ago(1) Cloudflare does do BGP-based protection (rerouting of a packet) on their enterprise tier. (2) They really aren't adding functionality into the network. If I put a cluster of Nginx servers in front of my web server, or if I have Cloudflare do it for me, I don't see how that fundamentally changes anything. (3) The Cloudflare approach of an application layer proxy is feasible for any protocol which can be proxied. I've worked on SMTP proxies which do to SMTP what Cloudflare does to HTTP. Cloudflare also has a DNS proxy. Proxying is a perfectly valid and often incredibly useful technique.
- mindslight 10y ago1. Sure, they can do multiple things. When most people talk about Cloudflare, they're referring to the L5 interdiction. 2. You could make a similar argument about network gear having code to facilitate streams. Having a third party provide this functionality is further down the path of centralization. 3. Sure. The point is that to create/tweak protocols, you have to convince Cloudflare (etc) to implement. It's the end to end principle for a reason. It's not a hard and fast rule, in fact there are many immediate reasons for wanting centralization. It's just unsustainable in the far term.