Use LetsEncrypt and CloudFlare to secure any Heroku app for free
github.com
github.com
If your threat model differs, this is cool.
* Cloudflare
* DNSMadeEasy
* DNSimple (my company)
* easydns
* PointDNS
I'm certain more will support it as open source name servers add support.
"[The Cloud] is essentially a consensual man-in-the-middle and for certain threat models is not compatible with the 'secure' modifier."
"The Cloud" isn't a company that has direct access to a certificate authority.
"The Cloud" doesn't produce a valid TLS certificate for YOUR website, to encrypt the connection between them and your visitors, but not necessarily between them and your server.
"The Cloud" is a vague term for "other people's computers".
CloudFlare is better than plaintext HTTP, but if your goal is confidentiality, then CloudFlare is probably worse than direct HTTPS with no intermediaries.
Again, threat models differ. For most people, CloudFlare is probably just fine.
Both of them you have to trust to do the right thing and that is an exercise left to the individual thinking of using either service. So lets not pretend that CloudFlare is a special case.
If you need to trust the none of your service providers can MITM your site then you can't use any PaaS or CDN, you need to terminate the SSL yourself, that includes for all static assets you use. No more jQuery from Google CDN, no more analytics/exception tracking/fonts from your favoured provider and no more advertising conversion tracking.
But then do also remember that it's possible for any web host to take over their customers site as long as they own the IP address. They just point the IP to another server, configure it to respond to the hostname and they can then even use any SSL certificate provider who validates the domain name with a file at a specific URL to grab a certificate.
Everyone has to make their own judgment on who they can trust. CloudFlare is no different.
Those all sound like reasonable best practices for building a website.
As someone running an ecommerce website without using advertising conversion tracking from to our various advertising networks it would simply not be measurable or cost effective. It is an essential part of how the systems works.
[0] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Heroku owns your server and can just as easily read your database off disk and/or your webserver process's memory. If you don't want to trust an infrastructure provider, you need to have physical control of your server. Such quibbles about architecture are deck chairs on the Titanic.
You don't have to trust the CDN for any static resource you load as long as you use the subresource integrity feature of modern browsers[1]. You basically include the hash of the content on your main domain and the browser will validate it when it loads it from CDN. So you only need to trust your main site.
[1] https://developer.mozilla.org/en-US/docs/Web/Security/Subres...
Edit: It was already mentioned by michaelmior https://news.ycombinator.com/item?id=12138277
Is it possible to create a new certificate without restarting all the servers each time a new client signs up?
You'd have to store them in a database for example to avoid having to restart the app. But that wouldn't be a good solution either, as letsencrypt will not allow you to have more than 100 domains under the same certificate.
[0] - https://github.com/joeblau/gitignore.io/wiki/System-Architec...
[1] - https://blog.cloudflare.com/introducing-universal-ssl/
It is trivial however to setup CloadFlare to have encrypted traffic to your Heroku app for free when using their cdn/webapp firewall service as your app is on https://appname.herokuapp.com which CloudFlare proxy.