Earlier quoted context omitted.
It is far from over, too! Google Cache still has loads of sensitive information, a link away! Look at this, click on the downward arrow, "Cached": https://www.google.com/search?q="CF-Host-Origin-IP:"+"author... (And then, in Google Cache, "view source", search for "authorization".) (Various combinations of HTTP headers to search for yield more results.)
> The infosec team worked to identify URIs in search engine caches that had leaked memory and get them purged. With the help of Google, Yahoo, Bing and others, we found 770 unique URIs that had been cached and which contained leaked memory. Those 770 unique URIs covered 161 unique domains. The leaked memory has been purged with the help of the search engines. So I tried it too, and there's still data cached there. Am…
Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
291–300 of 1001 posts
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#292Anyone know which password manager uses Cloudflare? Just trying to figure out if I'm affected.
Thankfully it looks like it's not 1Password, who seem to use AWS CloudFront.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#293Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#294Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#295Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#296Can we start a list of affected right now? I found: OKCupid Uber people claiming 1Password, can't find Reddit Lyft Yelp Pingdom Digital Ocean Montecito Bank and Trust
I found: FitBit Hacker News Stack Overflow Zendesk Discord FastMail (not really see below)
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#297Earlier quoted context omitted.
Can you think of an existing system (let's go with websites) that meets your standards?
There isn't an automated system that can tell you whether it's safe to give data to a website, just like there's no automated system which can tell you a given vendor/service provider in general is reputable. All you've got is regulations, human-based reputation ranking, and public shaming.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#298Step 1) MITM the entire Internet, undermining its SSL infrastructure, build a business around it Step 2) leak cleartext from said MITM'd connections to the entire Internet I recently noted that in some ways Cloudflare are probably the only entity to have ever managed to cause more damage to popular cryptography since the 2008 Debian OpenSSL bug (thanks to their "flexible" ""SSL"" """feature"""), but now I'm certain o…
Step 0) Obtain black funding from NSA budget to start and "VC invest" in a global CDN company... (Now I'm trawling Crunchbase to see if I can work out which investors are NSA front companies, then I'm gonna look to see what _else_ them and their partners have invested in...)
I once came up with that exact concept for a nation-state subversion. It would even pay for itself over time. I kept thinking back to it seeing the rise of the CDN's and the security approaches that trust them.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#299So time to reset password and logout of all mobile apps to get new authorization tokens?
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#300Earlier quoted context omitted.
Good. They're trying to clean up all the private data leaked everywhere. I tempted to say "why couldn't they figure out this google dork themselves" but they've probably been slammed for the past 7 days cleaning up a bunch of stuff anyway.
You have no idea.
"CF-RAY" "CF-Force-Miss-TS"
"X-SSL-Server-Name"
"Internal Upstream Server Certificate0"