3 ms·
Because it's legitimate to have values before the request gets to CloudFlare, for instance if it was routed out through a corporate proxy, etc..
by modoc 6y ago
Because it's legitimate to have values before the request gets to CloudFlare, for instance if it was routed out through a corporate proxy, etc..
- MuffinFlavored 6y agoOuch. I wonder if it's time to cryptographically sign those values or add a checksum or something.
- acdha 6y agoBasically this is why you want to go full zero trust: if you use mutual authentication over TLS, this becomes much less of a concern since you’re not trying to craft policies based on IP addresses with multiple intermediaries.
- ec109685 6y agoOnly possible if non-TLS or the company is man in the middling TLS (and certificate pinning isn’t enabled).
- allending 6y agoSo... completely possible then.