They are orders of magnitude more important than compression. 99.99% of requests hit a local cache. (1)
Compression is important too.
(1) I worked in a telco. Check it out for yourself!
They are orders of magnitude more important than compression. 99.99% of requests hit a local cache. (1)
Compression is important too.
(1) I worked in a telco. Check it out for yourself!
So then people complain "oh but The Illuminati can see what websites I'm going to!" Yeah, and they still can with HTTPS, it's called statistical network traffic analysis. Decades of research papers show you can uniquely identify a client going to a random internet server (and the page they're browsing) just by sniffing a bunch of POPs. It's used by law enforcement and Five Eyes to identify internet users around the world. Even protocols that have countermeasures (TOR) don't stand up to it.
Also, a lot of ISPs blackbox caching proxies were buggy and breaking websites.
A browser could render a similar security warning to what it already does, if the signature doesn’t match or if the hash is wrong.
I don’t think the kind of traffic analysis you mention works as well as you think it does for identifying individual pages e.g. which tweet someone is viewing. Moreover it requires a level of technical sophistication that is beyond all but the most advanced countries, countries that tend to have some measure of rule of law.
Second, totalitarian regimes around the world don't sit on their hands just because you use HTTPS. If they want to know who a dissident is, they go find out. Bribery, tips, intimidation, torture, spy cameras, facial recognition, etc. They also know that everyone who reads a tweet isn't automatically a dissident.
Third, no, it's not hard at all to do statistical traffic analysis, it's part of basic DPI packages shipped with commercial network gear for about a decade. All you need to identify the user is the destination and the source, and the signature of similar connections to specific hosts with specific traffic. You compare the traffic from the target user to the traffic you monitor or simulate with known destinations and content, and highest probability wins. It's child's play.
Indeed... When one lives in such regimes, to say that appears to be an utter truism.
Compared to transit, last mile bandwidth is effectively limitless and free. Cache fill at the edge is important, last mile caching not so much.
2. Wasn't there some work on serving presigned HTTPS requests? The one everyone blamed Google (?) for cause they wanted it to put slices of other websites inside the search results. Might make sense to resurrect that work.
We instead now see (proprietary?) cache boxes by big players like YouTube and Netflix that ISPs can install in their DCs, but that seems less elegant, even though it gives the content providers much greater control over what, when and how much gets cached. Still, as a smaller fish, without going with cloudflare, there's no caching involved anymore, probably not even if I decide to run my site on HTTP only.
Yes, still
The internet is "driven" by web/mobile which is driven by multimedia, which lives and dies on compression / codecs.
I'm not sure what that would mean...
Maybe if you're website is unpopular we move your server to North Korea since no one is accessing it anyways?