Live data from Hacker News

Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

bugs.chromium.org

41–50 of 1001 posts

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#41
post #10

Neither this thread nor the Cloudflare blog post include concise steps for customers who were exposed. There's an argument for changing secrets (user passwords, API keys, etc.) for potentially affected sites, plus of course investigating logs for any anomalous activity. It would be nice if there were a guide for affected users, maybe a supplemental blog post. (and yet again: thank you Google for Project Zero!)

What can they even say? "Change everything" doesn't really work. Any potentially secret data to or from a server could have been exposed.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#44
My first thought was relief, thank god I'm not using Cloudflare.

Where would you even start to address this? Everything you've been serving is potentially compromised, API keys, sessions, personal information, user passwords, the works.

You've got no idea what has been leaked. Should you reset all your user passwords, cycle all or your keys, notify all your customers that there data may have been stolen?

My second thought after relief was the realization that even as a consumer I'm affected by this, my password manager has > 100 entries what percentage of them are using CloudFlare? Should I change all my passwords?

What an epic mess. This is the problem with centralization, the system is broken.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#47
post #10

Neither this thread nor the Cloudflare blog post include concise steps for customers who were exposed. There's an argument for changing secrets (user passwords, API keys, etc.) for potentially affected sites, plus of course investigating logs for any anomalous activity. It would be nice if there were a guide for affected users, maybe a supplemental blog post. (and yet again: thank you Google for Project Zero!)

What can they even say? "Change everything " doesn't really work. Any potentially secret data to or from a server could have been exposed.

Yes, but in general keys provide ongoing access; sensitive data itself is more limited in scope. Keys, auth tokens, etc. would be what I'd focus on.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#48
post #39

Earlier quoted context omitted.

This has nothing to do with logging.

The quoted part that specifically mentions logged urls containing query strings has nothing to do with logging?

That's Google logging stuff
Post reply on HN