Gotta love the completely superfluous dig at Cloudflare. As if providing the client IP is what enabled the attack. That was probably the least interesting part of the attack. Cheap shot Akamai.
> The skimmer uses a Cloudflare API in order to get the end-user IP address.
They described what the script does in detail, and that's part of what it does.
Also no mitigation suggested other than CSP for which "A lot of CSP policies don't..." Which is a suggestion to use CSP correctly, in a backhanded way.
It is a sales pitch plus an info-sec report.
Indeed it's a bit of a cheap shot since they could have gotten the ip via whatismyip.com or any other innumerable ways. It just happened to use CF, which I'm sure they were jumping in joy about since they get to do a direct compare against CF: Akamai has PIM, CF does not.