4 ms·
So you're against all CDNs?
by dbbk 2mo ago
So you're against all CDNs?
- deleted 2mo ago[deleted]
- fc417fc802 2mo agoA CDN doesn't necessarily have to perform a MitM. We really need more nuanced terminology to distinguish the various approaches.
- gruez 2mo agoRight, but practically speaking all CDNs are MITMs. If you're against cloudflare you should be against cloudfront, akamai, etc. as well.
- inigyou 2mo agoCloudflare is egregiously bad because of its marketing strategy. It tried to get everyone with any small website to use it, by selling a vague notion of security and charging no monetary price, and it worked. They'll even sell you a domain name to increase lockin. Many people recommend getting domains from cloudflare because apparently they're cheap. Akamai, Fastly, etc only take big customers who know what they're doing. You need to sign a proper contract with them. They aren't low-friction.
- edaemon 2mo agoHow would they cache and serve responses without decrypting the traffic?
- sandeepkd 2mo agoIdeally yes, the TLS termination does not need to happen for caching purposes. Challenge is that in practice every business wants to be sticky and try to provide more functionalities which do require TLS termination. Most people either trust CDN's or they do not understand MitM so it does not concerns them. Plus they are getting certificate management and DDOS prevention capabilities.
- inigyou 2mo agoHow can you cache without terminating TLS? Remember, every TLS session uses different encryption keys, so encrypted responses cannot be cached.
- ceejayoz 2mo agoMost CDNs aren’t doing as much as Cloudflare. They wanna handle your auth, your analytics, your hosting, your VPN.