3 ms·
(1) Cloudflare does do BGP-based protection (rerouting of a packet) on their enterprise tier. (2) They really aren't adding functionality into the network. If
by DanielDent 10y ago
(1) Cloudflare does do BGP-based protection (rerouting of a packet) on their enterprise tier.
(2) They really aren't adding functionality into the network. If I put a cluster of Nginx servers in front of my web server, or if I have Cloudflare do it for me, I don't see how that fundamentally changes anything.
(3) The Cloudflare approach of an application layer proxy is feasible for any protocol which can be proxied. I've worked on SMTP proxies which do to SMTP what Cloudflare does to HTTP. Cloudflare also has a DNS proxy. Proxying is a perfectly valid and often incredibly useful technique.
- mindslight 10y ago1. Sure, they can do multiple things. When most people talk about Cloudflare, they're referring to the L5 interdiction. 2. You could make a similar argument about network gear having code to facilitate streams. Having a third party provide this functionality is further down the path of centralization. 3. Sure. The point is that to create/tweak protocols, you have to convince Cloudflare (etc) to implement. It's the end to end principle for a reason. It's not a hard and fast rule, in fact there are many immediate reasons for wanting centralization. It's just unsustainable in the far term.