List of Sites Affected by Cloudflare's HTTPS Traffic Leak
51–60 of 228 posts
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#52Earlier quoted context omitted.
> If you are a verified victim of this bug CloudFlare will contact you. Where do you have that info from?
We are in the process of contacting customer who we are able had information cached by a search engine.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#53Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#54I'm confused by the "not affected" remarks. I thought the issue was any site which passes data through cloudflare could be leaked by requests to a different site, due to their data being in memory. Have I misunderstood?
Inside of TLS, 1Password uses an additional SRP handshake that negotiates a static secret (like a DHE), which 1Password uses to both authenticate the user and set up an additional AES-GCM transport encryption. So even a full memory dump of what's transported in TLS should, as long as it's properly implemented, only reveal an SRP authentication session and subsequently symmetrically encrypted data. (And inside that SR…
I wonder which password manager the original Project Zero thread referred to then if not 1Password.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#55Earlier quoted context omitted.
> If you are a verified victim of this bug CloudFlare will contact you. Where do you have that info from?
We are in the process of contacting customer who we are able had information cached by a search engine.
If you think this is implausible, consider just one persona who could do this;
- Someone turns clouflare https service on their website
- They check their pages and see some random data in the middle of a
tag
- They reproduce the bug. Then they reproduce it again. Then they script it.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#56Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#57Unfortunately this seem to include news.ycombinator.com
In this case, HN , IIRC, does not use the proxy.
Checking the certs, CloudFlare reissue using DigiCert, I think, whereas HN is using a Comodo cert.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#58Earlier quoted context omitted.
We are in the process of contacting customer who we are able had information cached by a search engine.
@jgrahamc: If this problem doesn't justify emailing all proxy service customers, what problem would?
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#59Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#60For example, https://coinbase.com is on that list! If they haven't immediately invalidated every single HTTP session after hearing this news this is going to be bad. Ditto for forcing password resets.
A hijacked account that can irrevocably send digital currency to an anonymous bad guy's account would be target number one for using data like this.