"List of Sites possibly affected" Sites using Cloudflare, really. However, Cloudflare say that only sites using three page rules were affected - email obfuscation, Server-side Excludes and Automatic HTTPS Rewrites. [1] Is this over-estimating the impact, perhaps? [1] https://blog.cloudflare.com/incident-report-on-memory-leak-c...
No! And this is why cloudfare's poor write up continues to confuse people. Sites with those features triggered the bug. Once the bug was trigerred the response would include data from ANY other cloudfare customer that happened to be in memory at the time. Meaning a request for a page with one of those features could include data from Uber or one of the many other customers that didn't use those features. So the poten…
List of Sites Affected by Cloudflare's HTTPS Traffic Leak
31–40 of 228 posts
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#32I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#33I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#34I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#35I have hundreds of passwords in my password manager. That's going to take a week, considering I also have to work.
Is your password manager 1Password? https://blog.agilebits.com/2017/02/23/three-layers-of-encryp...
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#36I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.
https://www.namecheap.com/support/knowledgebase/article.aspx...
https://blog.namecheap.com/two-factor-authentication/
Here's a list of alternatives someone asked a month ago:
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#37Earlier quoted context omitted.
Is your password manager 1Password? https://blog.agilebits.com/2017/02/23/three-layers-of-encryp...
Even if your password manager is not compromised, the credentials of so many sites is potentially leaked that you should probably still update a substantial number of passwords. I hope 1Password's Watchtower service will soon give hints.