We're leaving Cloudflare – here's why – Pale Moon
forum.palemoon.org
We're leaving Cloudflare – here's why – Pale Moon
1–10 of 23 posts
Re: We're leaving Cloudflare – here's why – Pale Moon
#2Unfortunately, Cloudfare sides with Firefox and Chrome and does not offer Brotli on HTTP, citing old studies of proxies breaking when exposed to Brotli. They are also telling the author to go away in corporate-speak. The author, however, is unsatisfied and asks:
> What is the real (undisclosed to me) reason they won't consider even the possibility of Brotli being enabled for clients who support it? ... I can only conclude there's some agenda here that I'm being kept in the dark about...
Re: We're leaving Cloudflare – here's why – Pale Moon
#3Re: We're leaving Cloudflare – here's why – Pale Moon
#4i would love to see someone from CF/firefox/chrome team to jump in and share the reason why :)
Re: We're leaving Cloudflare – here's why – Pale Moon
#5i would love to see someone from CF/firefox/chrome team to jump in and share the reason why :)
I wonder if it's as simple as a combo of: http (no s) is essentially going away anyway and they just don't feel like spending engineering effort on even verifying that it won't break anything.
Re: We're leaving Cloudflare – here's why – Pale Moon
#6Summary: the author is worried about Brotli compression (like existing gzip but 20% better) for HTTP protocol. Both Firefox and Chrome require HTTPS for Brotli; but Pale Moon authors disagree and enable Brotli even on plain HTTP connections. Unfortunately, Cloudfare sides with Firefox and Chrome and does not offer Brotli on HTTP, citing old studies of proxies breaking when exposed to Brotli. They are also telling the…
In an internal study (in an enterprise level) and assuming this is HTTP/1.1, that some proxies will either cache only brotli and made it inaccesible to gzip-only clients (even when you bothered with Vary, because they're plain broken in that regard) or just barf with it and time-out not only that particular request but crash a proxy.
The problem for large-scale deployment is that there are transparent proxies in Timbuktu (literally) since data is not cheap there, they need to use HTTP proxies to compress that, not to mention dial-up users in the US! (Good luck, Verizon!)
Re: We're leaving Cloudflare – here's why – Pale Moon
#7Summary: the author is worried about Brotli compression (like existing gzip but 20% better) for HTTP protocol. Both Firefox and Chrome require HTTPS for Brotli; but Pale Moon authors disagree and enable Brotli even on plain HTTP connections. Unfortunately, Cloudfare sides with Firefox and Chrome and does not offer Brotli on HTTP, citing old studies of proxies breaking when exposed to Brotli. They are also telling the…
Or is Moonchild suggesting that Cloudflare is specifically trying to damage Pale Moon by not supporting its unique feature of Brotli over HTTP? That seems unlikely, insofar as it would require them to have an opinion one way or the other about a browser that nobody uses.
Re: We're leaving Cloudflare – here's why – Pale Moon
#8Maybe there is a limitation in the way their caching works that it cant differentiate between different encodings, and therefore just requests and caches the most commonly supported encoding?
Why would this be different over https? Why isn't https == http + s? When did that break, and why did we let it?
If we don't want doubly-compressed content (for security/superior compression/whatever), surely it should be up to the browser not to request that encoding, rather than baking it in at some other layer?
Re: We're leaving Cloudflare – here's why – Pale Moon
#9Is this a case of Cloudflare not honouring/forwarding the content-encoding header? Maybe there is a limitation in the way their caching works that it cant differentiate between different encodings, and therefore just requests and caches the most commonly supported encoding? Why would this be different over https? Why isn't https == http + s? When did that break, and why did we let it? If we don't want doubly-compress…
Brotli and h2 both will break a lot of proxies in the wild, as well as a bunch of web clients. Moonchild/The Palemoon Team do say that the browsers aren't supported by Google/MS/Apple/Moz but the reality is that while those entities do not support those browsers, Cloudflare does.
So from Cloudflare's perspective, the clients they support are likely to break, especially if they might have more middleboxes. Why would they then enable this feature if that is the case?
Moonchild on the other hand seems to want to make a conspiracy out of it.
Re: We're leaving Cloudflare – here's why – Pale Moon
#10Summary: the author is worried about Brotli compression (like existing gzip but 20% better) for HTTP protocol. Both Firefox and Chrome require HTTPS for Brotli; but Pale Moon authors disagree and enable Brotli even on plain HTTP connections. Unfortunately, Cloudfare sides with Firefox and Chrome and does not offer Brotli on HTTP, citing old studies of proxies breaking when exposed to Brotli. They are also telling the…
And what could that agenda possibly be? That they really like encryption and think everyone should use it? They haven't exactly been shy about telling people that. Or is Moonchild suggesting that Cloudflare is specifically trying to damage Pale Moon by not supporting its unique feature of Brotli over HTTP? That seems unlikely, insofar as it would require them to have an opinion one way or the other about a browser th…
Sounds to me like they overestimate they own importance to CF a bit.