3 ms·
What's the likelihood of actually seeing a change?
by epoch1970 10y ago
What's the likelihood of actually seeing a change?
- prdonahue 10y agoPM here—he's already brought to me to discuss :)
- DenisM 10y agoAnd is tree cert pinning for self-sign veers? If not, why not?
- dsl 10y agoCan you please also include an HTTP response header that tells us the level of verification of the connection to the origin? If CloudFlare wants to live dangerously with origin connections, fine... but give end users a way to drop the connection if it isn't secure, like our browsers would normally.
- toast0 10y agoBy the time you've gotten this response header, the request has already been sent over the connection that you don't trust, and at least part of the response.
- dsl 10y agoBut at least you can cease further communications. Feel free to suggest a better idea.
- toomuchtodo 10y agoI love your suggestion, with the caveat that browsers send a pre-flight interrogation request (similar to OPTIONS with CORS) to determine if the origin connection is secure before sending a legitimate request (containing potentially sensitive data).