Two use cases if it is allowed
Two use cases if it is allowed:
1. Phishing. This could be used for malicious actors to make users think they're streaming to the correct account when they're really streaming somewhere else. If the only thing that differentiates between which account a stream goes is the stream key then it would be easy to trick users. Example: If live.securemedicalstreams.com is CNAMEd as a Cloudflare Stream domain. A malicous user finds that out via a simple DNS scan. So they add the domain to their account too. They can phish a user giving them the real domain, just with their own stream key. If that's possible both live.securemedicalstreams.com/1111111111 and live.securemedicalstreams.com/2222222 could go to separate stream accounts with one potentially being malicious.
2. Shared vanity domain. A use case for allowing it would be to let multiple users use custom domains. I have ingest.stream and rtmps.stream which make good ingest domains imo. I don't care if others use them.
1 Reply
Unknown User•14mo ago
Message Not Public
Sign In & Join Server To View