logoalt Hacker News

JetSpiegelyesterday at 7:48 AM1 replyview on HN

How is that not a MITM? Just because it's the modern day CryptoAG?


Replies

acdhayesterday at 1:08 PM

Because it’s not an attack but rather a voluntary infrastructure choice by a company. We don’t say that Varnish is a MITM because it’s in front of my application, because it’s intentional and under my control. Misusing the term muddies the topic rather than adding clarity, and while there’s a very useful discussion about centralization or why Cloudflare’s most stringent customers might want to deploy their Keyless SSL service that discussion won’t happen if someone misuses the term.