Posted By: Uniken | Posted On: February 27, 2017
TLS when used with a CDN doesn't provide any privacy, data integrity or authentication.
To be fair, CDN's terminate the TLS sessions so that they can do TCP and TLS protocol break, content inspection and traffic analysis. These networks also add TLS to TCP sessions as well. But, unfortunately both these types of services breaks three core features of TLS end-to-end protections: data privacy, data integrity and how its most often used server side authentication. The only solution is for apps to implement their own end-to-end, at the process level, protocol that can put these key protections back in place.
arstechnica.com/security/2017/02/
https://www.linkedin.com/pulse/tls-when-used-cdn-doesnt-provide-any-privacy-data-integrity-levine