Live data from Hacker News

Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

bugs.chromium.org

721–730 of 1001 posts

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#722
post #665

Earlier quoted context omitted.

> edit: why the revulsion I'd guess it's because of the crude and reductive way you describe the service cloudflare provides. I don't know what type of programming you do, but many small services don't have the infrastructure to mitigate the kind of attacks cloudflare deals with and they wouldn't be around without services like this. I don't like the internet becoming centralized into a few small places that mitigate…

How about... stop CLOUD THIS and CLOUD THAT. Cloud means extreme centralization. It means giving your data to a third party you don't control. Why? Why does our networked software have to assume a centralized topology? In the days when developed countries had dialup, protocols (IRC, Email, etc.) were all decentralized. Today, all the famous developers live with fancy broadband internet connections and forgot what it'…

Your why questions can all be answered by "It's cheaper than hiring a team to do it in-house". At the end of the day it's all about money and non-techy people are often the people in charge of the money.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#723

Earlier quoted context omitted.

It is far from over, too! Google Cache still has loads of sensitive information, a link away! Look at this, click on the downward arrow, "Cached": https://www.google.com/search?q="CF-Host-Origin-IP:"+"author... (And then, in Google Cache, "view source", search for "authorization".) (Various combinations of HTTP headers to search for yield more results.)

It seems like the reasonable thing for Google to do is to clear their entire cache. The whole thing. This is the one thing that they could do to be certain that they aren't caching any of this.

CF should be thankful Google is doing any of this, clearing their entire cache would cost Google $ to index web from scratch.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#725

Can we start a list of affected right now? I found: OKCupid Uber people claiming 1Password, can't find Reddit Lyft Yelp Pingdom Digital Ocean Montecito Bank and Trust

Patreon 4chan used to use it apparently, don't know if affected kik Zoho CRM change.org Cloudflare itself, of course Feedly

Anyone know if Zoho mail is vulnerable too?

According to doesitusecloudflare.com Zoho isn't using Cloudflare, was it previously?

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#726
post #507

Earlier quoted context omitted.

If I'm understanding correctly, that list would include not only the 3,438 domains with content that triggered the bug, but every Cloudflare customer between 2016-09-22 and 2017-02-18.

Can we trust it was only those domains?

Not really. If a site is using Cloudflare protection for only some of their subdomains they do not show on this list even if the site itself is in the alexa top 10k sites.

And of course all other sites that are not in alexa 10k are not in this list (if they are not on some other lists used, you can see the source of lists in the README of the Github repo).

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#727
post #218

Earlier quoted context omitted.

I would say the crazy thing is a mere t-shirt as their "bug bounty" top tier award given how they've pitched themselves as an extremely secure service. https://hackerone.com/cloudflare I'm sorry but when the reward for breaking into you is basically a massive pinata of personal information...that simply is a bad joke. Security flaws are going to happen and if you aren't going to even offer a reasonable financial rewa…

Nah. Bug bounties don't work for services like CDNs. Maybe they do elsewhere. But for enterprise services, the noise rate is too high, and the very good bug finders are either salaried, free, or working for the adversary.

Facebook and Google have bug bounties. That's pretty big scale.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#728

Holy sh*t. Is this the end of Cloudflare with the trust being absolutely destroyed and lawsuits coming in? Can't say I'm sad for them. Cloudflare sells you DDOS protection, and hosts (eg. masks the IP of) the very DDOSers to protect against themselves, which I find bordering on the criminal. Hosters like Hetzner, OVH have for a year now offered DDOS protection (I'm guessing it's heuristic rate limiting, but they won'…

From https://arstechnica.com/security/2017/02/serious-cloudflare-...:

    A while later, we figured out how to reproduce 
    the problem. It looked like that if an html page
    hosted behind cloudflare had a specific
    combination of unbalanced tags,
    [...]
    The leakage was the result of a bug in an HTML
    parser chain Cloudflare uses to modify Web pages
    as they pass through the service's edge servers.
Ahem, at the risk of sounding pedantic, but this wouldn't have happened when using a proper HTML/SGML parser ([1]).

[1]: http://sgmljs.net/blog/blog1701.html

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#729
From a cloudflare employee:

"We were working to disclose the bug as quickly as possible, but wanted to clean up search engine caches before it became public because we felt we had a duty of care to ensure that this private information was removed from public view. We were comfortable that we had time as Google Project Zero initially gave us a 90 day disclosure window (as can still be seen in their incident tracker), however after a couple of days, they informed us that they felt that 7 days was more appropriate. Google Project Zero ended up disclosing this information after only 6 days."

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#730

Earlier quoted context omitted.

I wonder if archive.org or archive.is have anything cached...

archive.is was red, meaning it uses Cloudflare.... www.doesitusecloudflare.com

No TLS on this site?
Post reply on HN