Earlier quoted context omitted.
I found: FitBit Hacker News Stack Overflow Zendesk Discord FastMail (not really see below)
We, FastMail, are not affected by this. We do not proxy TLS connections via any third party. We use CloudFlare for DNS distribution only, which is not part of this issue.
Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
561–570 of 1001 posts
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#562Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#563Has anybody else actually received an email from Cloudflare about this? I'm a paying customer, but haven't heard anything from them yet. I hope they don't expect they can leave it at a random blog post that will go by unnoticed?
Another paying customer here. No email communication from CloudFlare. Found out about this on HN.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#564What is the optimal solution???
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#565>Cloudflare pointed out their bug bounty program, but I noticed it has a top-tier reward of a t-shirt. Considering the amount and sensitivity of the data they handle, I'm not sure a t-shirt is an appropriate top-tier reward.
Not only that, but the "reward" in the program is laughable and frankly insulting to any serious researcher considering the scope of CF. Bug bounty platforms are already becoming the fiverr of ITSEC (that's not a good thing), CF just made an extra effort do diminish the value for researchers. Management: "Why do we offer $5k for a small bug again? Look at CF, they don't offer any money!"
But, Taviso is probably contractually prohibited from accepting money from CF as a Google employee. Many large companies have 'outside activity' clauses and Google seems to be paying him already for that.
However, it will affect others whom are fully freelance.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#566Earlier quoted context omitted.
How did you find that IP?
I used Censys to search for the IPv4 addresses of servers serving matching TLS certificates: https://censys.io/ipv4?q=443.https.tls.certificate.parsed.na...
Uh, asking for a friend.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#567Earlier quoted context omitted.
Because you'll make much more working for people who specifically hire you instead of doing a bunch of risky work on spec.
The point of bug bounties isn't to attract the interest of people who are working to find bugs . It's to make sure that if someone is finding bugs for fun or stumbles over bugs by accident , it's worth their time to report the bugs.
>> top-tier reward of a t-shirt.
A t-shirt still seems entirely too small; closer to insulting than motivating.Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#568Step 1) MITM the entire Internet, undermining its SSL infrastructure, build a business around it Step 2) leak cleartext from said MITM'd connections to the entire Internet I recently noted that in some ways Cloudflare are probably the only entity to have ever managed to cause more damage to popular cryptography since the 2008 Debian OpenSSL bug (thanks to their "flexible" ""SSL"" """feature"""), but now I'm certain o…
They also actively deter Tor use. I've cancelled subscriptions with Cloudflare-hosted sites because they make securely and anonymously browsing their sites a pain.
Sure, the proportion of requests passing through Tor are more likely to be malicious, but given the bandwidth constraints the adversary seems limited.
The costs aren't only the lost business from people like you, but people who should use Tor giving in. There's some wisdom to people even researching something as mundane as what their dog ingested using anonymized services, much less other medical questions.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#569Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#570Cloudflare is MitM by design. Chrome and others must not tolerate it. This vulnerability is just another reason to do it asap.