Skip to content

Comment on Serverless DTLSparent

Comments

Actually, you could proxy based on SNI alone

If you assume the origin speaks TLS and holds the cert/private key, and isn't using ESNI/ECH, then I suppose in a limited way it's possible. But...

because they want to intercept all your traffic so the NSA gets a copy.

I don't believe that is the reason. I believe it's for features.

You need actual TLS termination to do most things CDNs and reverse proxies offer, such as:

- caching and compression

- WAF / bot detection

- URL-based routing

- header manipulation and redirects

- application-layer DDoS filtering

- analytics

- edge functions and content transformation

Why would an origin be unable to speak TLS? An ESP can speak TLS. A RP2040 can speak TLS. My watch can speak TLS. TLS even is implemented on the Commodore 64 by now.

For the features you mention: Yes, you need meta-data for this. But you don't need to see the payload, a picture of my naked 4 year old kid.

I didn't mean it so much as a physical constraint, but an operational one.

Not everyone wants to (or their policy allows them to) manage TLS certs directly on their origin servers, and some services only allow plaintext HTTP origins, like AWS ALB/ELB. In that particular case it's "ok" because the load balancer is placed inside your VPC, so cleartext traffic is not visible to other customers or networks.

Also, ESNI/ECH would make TLS passthrough problematic.

Then probably a hybrid approach would make sense. Public non-confidential data can be Man-in-the-middled, but confidential data must be e2ee.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.