Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Which is precisely why you should not use an MITM network.


What precisely? I don't see a counter-argument.

If you're saying not to use any CDNs then that's not very reasonable considering the service that CDNs provide.


The benefit of CDNs is increasingly questionable, but you can still realize them by managing it yourself. What I'm saying is to never use a third-party network that subverts your own security. I would try harder to nail that point in, but I don't think Cloudflare's coffin has room for any more.


Questionable? There is no shortcut for the speed of light, regardless of how optimized the HTTP and TLS protocol gets. Building your own CDN is no easy feat if you want the performance, security, scale and reliability that you get from a focused vendor.

Everything on the internet is a product of thousands of vendors, hardware equipment and software components working together. There are millions of factors that can and may be compromised so the only realistic approach is risk management.

It's far better to rely on a well funded, staffed and capable vendor rather than building your own version. This is solid advice for everything outside of the expertise of your business so I'm not sure why a CDN is anything different. Assess the risk and do what works for you.


Cloudflare is not a shortcut for the speed of light in this case. You load static assets/video streams/whatever from CDNs. Things that contain sensitive content like account pages, messages, etc should go directly to the server since that is exactly what cloudflare will do as well.


CDNs still provide a better experience by having faster open connections to the origin, local TLS termination, security/DDOS/WAF protections, and more.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: