Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

31–40 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#31

"List of Sites possibly affected" Sites using Cloudflare, really. However, Cloudflare say that only sites using three page rules were affected - email obfuscation, Server-side Excludes and Automatic HTTPS Rewrites. [1] Is this over-estimating the impact, perhaps? [1] https://blog.cloudflare.com/incident-report-on-memory-leak-c...

No! And this is why cloudfare's poor write up continues to confuse people. Sites with those features triggered the bug. Once the bug was trigerred the response would include data from ANY other cloudfare customer that happened to be in memory at the time. Meaning a request for a page with one of those features could include data from Uber or one of the many other customers that didn't use those features. So the poten…

Ah, that makes sense. Thanks for clearing it up for me.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#32

I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.

Can you explain how 2FA would have helped?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#33

I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.

2FA doesn't protect you against cookie/token stealing. The website owners need to invalidate all of that on their ends.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#34

I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.

If you setup TOTP (Authenticator) while this bug was out in the wild your shared secret key could have leaked. SMS would actually be safer than TOTP in this scenario.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#35
post #8

I have hundreds of passwords in my password manager. That's going to take a week, considering I also have to work.

Is your password manager 1Password? https://blog.agilebits.com/2017/02/23/three-layers-of-encryp...

No, it's keepassx on my laptop. I don't trust my passwords to somebody else.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#36

I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.

Good luck with that, people have been requesting for TOTP support on Namecheap for the past 3 years.

https://www.namecheap.com/support/knowledgebase/article.aspx...

https://blog.namecheap.com/two-factor-authentication/

Here's a list of alternatives someone asked a month ago:

https://news.ycombinator.com/item?id=13484739

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#37

Earlier quoted context omitted.

Is your password manager 1Password? https://blog.agilebits.com/2017/02/23/three-layers-of-encryp...

Even if your password manager is not compromised, the credentials of so many sites is potentially leaked that you should probably still update a substantial number of passwords. I hope 1Password's Watchtower service will soon give hints.

[deleted]

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#38
For what it's worth, as part of work on the effects of DNS on Tor's anonymity [1] we visited Alexa top-1M in April 2016, recording all DNS requests made by Tor Browser for each site. We found that 6.4% of primary domains (the sites on the Alexa list) were behind a Cloudflare IPv4-address. However, for 25.8% of all sites, at least one domain on the site used Cloudflare. That's a big chunk of the Internet.

[1]: https://nymity.ch/tor-dns/

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#40
That list isn't that useful... First of all, there is a LOT of pages hosted by CloudFlare @taviso acknowledged that in the original bug report. (https://bugs.chromium.org/p/project-zero/issues/detail?id=11...) Furthermore, you can't say which sites were hit by this bug and simply listing all CloudFlare sites is more or less fearmongering. If you are a verified victim of this bug CloudFlare will contact you. Lastly, if you want to be sure to mitigate effects of the attack just do it... If you want to be absolutely sure that your session keys etc will remain uncompromised simply repeal all active session cookies.
Post reply on HN