Another implication of this result is: even if the transport layer security appears to be secure, it's possible that it only indicates the CDN setup, and the actual upstream servers are insecure.
Which means, a latest and greatest TLSv1.3 server you see may be ultimately backed by a vulnerable TLSv1.0 upstream server (or even unencrypted HTTP!).
Great news for the NSA indeed!