Hacker News new | ask | show | jobs
by h4waii 1587 days ago
No no, it's encrypted so you can just completely ignore the security of your web service.

* Broken auth? Doesn't matter, encrypted.

* IDOR? Encryption takes care of it!

* Blind SQL or something from the 90s? EEENNNNCCCRRYYPPPTTIIOOONN!

3 comments

To be fair, this feature is part of Cloudflare's ZeroTrust offering, so you're meant to put a policy in front of it and forget it. This is great for getting extremely old legacy services that previously relied on VPN network trust onto an actual SSO provider instead.
They probably use military-grade hashes too. So you know it is very secure indeed.
> ... you can just completely ignore the security of your web service

Be weary of such absolute statements -- especially when it comes to security.

you are replying to a sarcastic comment that agrees with you..