A few virtual servers with honest gigabit as caching proxies here and there connected to a central server over VPN. There is no true "Non-Pozzed" way of doing (D)DoS protection because of how computer networks are designed. Https is not really needed to be honest, not for public content, but in fact it only needs a way of signing information, so that client software and user would get proof of validity. We have to invent a system to receive central server's keys proxied through caching servers while keeping the load low on the main server, and then fetching signed bulk content from distributed swarm of caching servers. It's not possible with traditional networks, but some alternatives like GNUNet are working in the right direction.