Ideally yes, the TLS termination does not need to happen for caching purposes. Challenge is that in practice every business wants to be sticky and try to provide more functionalities which do require TLS termination. Most people either trust CDN's or they do not understand MitM so it does not concerns them. Plus they are getting certificate management and DDOS prevention capabilities.
It's a cache. My tiny websites couldn't survive getting hammered by AI bots without them.
Are you sure? Have you tried, or did Cloudflare just tell you that?
I wouldn't need a cache if my $6 server could handle 1M hits a day.
2 replies →
So you're against all CDNs?
Most CDNs aren’t doing as much as Cloudflare. They wanna handle your auth, your analytics, your hosting, your VPN.
A CDN doesn't necessarily have to perform a MitM. We really need more nuanced terminology to distinguish the various approaches.
Right, but practically speaking all CDNs are MITMs. If you're against cloudflare you should be against cloudfront, akamai, etc. as well.
1 reply →
Ideally yes, the TLS termination does not need to happen for caching purposes. Challenge is that in practice every business wants to be sticky and try to provide more functionalities which do require TLS termination. Most people either trust CDN's or they do not understand MitM so it does not concerns them. Plus they are getting certificate management and DDOS prevention capabilities.
1 reply →
How would they cache and serve responses without decrypting the traffic?