Furthermore, using a CDN in this way may be a good idea because you don't have to worry about front end server noise/internet traffic. Cloudfront does have a good record of keeping up to date with SSL, and other various upgrades. By using Cloudfront's behavior rules I can have some requests go to backend servers via an ELB, others go to S3 and still others to go to other places. The end user has no idea, the simply see the same URL that they always do. It is nice to have everything all neatly wrapped under one URL structure and not to have to worry about DNS or cross domain antics.
And if I wanted to do access control I can easily use Cloudfront's support for signed requests[1]. That way if a request comes into to a particular URL path I can require that it be signed or not. Hence eliminating requests to resource intensive parts of the application.
[1] - http://docs.aws.amazon.com/AmazonCloudFront/latest/Developer...