PSA: There's no longer any benefit in terms of caching to using public CDNs. Caches are partitioned based on ancestor origins now for privacy.
Conversation
Notices
-
Embed this notice
Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Sunday, 07-Jul-2024 22:14:40 JST Ryan Castellucci :nonbinary_flag: -
Embed this notice
ciara (doti@pl.catboyindustries.co)'s status on Monday, 08-Jul-2024 01:49:15 JST ciara @ryanc wdym ancestor origin? -
Embed this notice
SpaceLifeForm (spacelifeform@infosec.exchange)'s status on Monday, 08-Jul-2024 03:56:42 JST SpaceLifeForm Got a link?
A CDN is still a MITM.
-
Embed this notice
Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Monday, 08-Jul-2024 06:34:39 JST Ryan Castellucci :nonbinary_flag: @SpaceLifeForm If you look up "cache partitioning" you'll find more details.
Subresource integrity can prevent a lot of naughty CDN behaviour.
-
Embed this notice