Chrome is about to start warning users that non-HTTPS sites are insecure

Hopefully Google/Chrome has the guts to start flagging CDN’s bogus man-in-the-middle SSL certs. Most people don’t realize that many CDNs fundamentally break the HTTPS/SSL system in the very way that SSL is supposed to prevent.

https://scotthelme.co.uk/tls-conundrum-and-leaving-cloudflare/

Not to mention all the ads, malware, and other bad actors that use CDNs to get around being blocked. I hate having to clear 5 random CDNs from my browser block just to view a webpage. ugggh. HTTP 2 makes the only real benifit to CDNs reduced server load and geographic distribution. With HTTP 2/HTTPS we no longer see blocking connections or the restrictive connection limit per domain, which was one of their original primary advantages.

3 Likes