Proxylity brings DTLS encryption to serverless UDP without changing your datagram model
Serverless DTLS
Proxylity's new DTLS Listeners add TLS-style encryption and authentication to UDP applications while preserving datagram boundaries. Clients establish DTLS 1.2 or 1.3 sessions; Proxylity decrypts payloads and forwards them to AWS Destinations. Authentication supports server certificates or pre-shared keys, with optional cookie protection and 0-RTT session resumption. DTLS 1.2 Connection IDs let sessions survive NAT rebinding. The first transport layer on Proxylity's roadmap to WebRTC Data Channels, it's available today for native DTLS clients.
Early data reduces latency, but applications must treat it as replayable even though Proxylity applies a shared anti-replay filter.
- freeone3000
Like. It’s already over the internet. If I have to send it unencrypted to you, why not just send it unencrypted to the destination? The cat’s already out of the bagel, so to speak.
- Fischgericht
"Clients establish a DTLS 1.2 or DTLS 1.3 session with the Listener's assigned domain and port."
"Every DTLS Listener receives a server certificate and private key managed by Proxylity."
I don't get it. Why would anyone want to send all their private information unencrypted to your serverless server?
"Get fired from your Organization for sending company or private data unencrypted to some random guys on the Internet" as a Service? Based on lossy UDP?
...What? Why would anyone do that?
I don't get it.
- mlhpdx
Founder of Proxylity here. I'm happy to answer questions about how this works, why we built it, and where it is (and isn't) a good fit.