4 ms·
Slightly OT: CDNs basically perform a MITM to do what they do. The destination site's certificate (www.destination.com) is deployed throughout the CDN's server
by fivedogit 12y ago
Slightly OT: CDNs basically perform a MITM to do what they do. The destination site's certificate (www.destination.com) is deployed throughout the CDN's servers and when DNS lookups are performed, the end user is directed to the IP address an optimal edge server where the certificate is waiting to greet them warmly. On the other side (first mile), the CDN then connects via a second SSL certificate (say, origin-www.destination.com) to the origin's datacenter(s) to retrieve the necessary data.
When I worked at a CDN company, we frequently got inquiries from customers saying that a security audit they ran threw up a red flag for MITM. And it was my job to tell them why it wasn't anything to worry about.
PS, most origin-www.destination.com origins are extremely vulnerable to DDoS since, at that hostname, there is no CDN to protect them.
- general_failure 12y agoWhile what you explain is correct, willfully giving/deploying your certificates in another server probably doesn't count as MITM
- Xorlev 12y agoAgreed. It's only MITM if it's unauthorized IMO. If I deploy my cert to a CDN its just legitimate handshakes so I'm not sure where the man in the middle comes in.
- skuhn 12y ago> On the other side (first mile), the CDN then connects via a second SSL certificate (say, origin-www.destination.com) to the origin's datacenter(s) to retrieve the necessary data. Perhaps. Not all CDNs require TLS to be used to connect to backends when the frontend is encrypted. This is completely obscured from the requesting client, and is a breach of user trust in my opinion. > PS, most origin-www.destination.com origins are extremely vulnerable to DDoS since, at that hostname, there is no CDN to protect them. This is a big problem that is rarely addressed until it bites you. When you're accustomed to a >90% hit rate and all of the nastiness of the Internet being handled upstream, you aren't going to be prepared for even a slight uptick in origin traffic. I saw one place whose site was served via Akamai DSA (http acceleration service), and routinely served >5Gbps. The origin consisted of two machines behind a Cisco ASA with a 100Mbit Ethernet port.