When the classic rate-limiting plugin is added, headers are returned to the client with names such as X-RateLimit-Remaining-<time> and X-RateLimit-Limit-<time> where <time> is the configured time span for the limit, for example seconds, minutes, hours, etc. Since these headers were standardized, Kong also adds a second, IETF-draft-style set of headers alongside them: RateLimit-Limit, RateLimit-Remaining, and RateLimit-Reset (and Retry-After once the limit is exceeded). Any header-hiding/renaming recipe needs to account for both sets, or the second set will still leak the same rate-limit information.
Also Kong adds latency headers to the response such as X-Kong-Upstream-Latency and X-Kong-Proxy-Latency.
These headers have fixed names that cannot be altered via a configuration. How can they be changed to different values for the names? This renaming is desirable in some circumstances to limit the information provided to potential hackers.