https://www.zdnet.com/article/equifax-confirms-apache-struts...
https://www.zdnet.com/article/equifax-confirms-apache-struts...
This often doesn't apply in cryptography; where adding two separate functions may result in a system that is actually weaker to attack.
This only applies to apps for internal use like Confluence or Jenkins, not publically accessible websites.
Now, if the attacker has access to the proxy authentication, all of this doesn’t help much, but at least you could track and limit who can access what chunks.
I have other proxies which require OIDC authentication before passing any packets on
Now sure, I'm still vulnerable to internal attackers from my company, but that's an audited trail to a real specific user, not just a random botnet on the internet.
An unauthenticated attacker can no longer simply rely on a vulnerability in the application or underlying framework, but must first obtain an employee's credentials, or find another vulnerability in the proxy or authentication infrastructure.
This isn't a false sense of security. It is a concrete additional layer of security which has tangible benefits.
The real problem is if there only one wedge, you need to combine that strategy with multiple layers of security to get anywhere, otherwise the first hole is the last.