Hacker News new | ask | show | jobs
by tgsovlerkhgsel 2657 days ago
Just a note, unless you're also validating the Host: header (and possibly even then), Authenticated Origin Pull can be bypassed if someone does find the right server:

https://medium.com/@ss23/leveraging-cloudflares-authenticate...

(Could have been fixed in the past couple months, but I doubt it.)

Same for Access, by the way.

2 comments

Sometime in 2Q you'll be able to upload your own client certificate (issued under your own CA if you like) to be used with Authenticated Origin Pulls.
Note: This user is a (the?) Director of Product at Cloudflare.
You can also use Argo Tunnel to create a secure tunnel between your origin and Cloudflare.