Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

131–140 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#131
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

That seems a lot like something a company which was just implicated in a gigantic leak would say: damage control.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#132
post #95

Earlier quoted context omitted.

Cloudfare has advised that Wave data has not been affected/leaked. We've got engineering and security teams investigating, and we'll keep on it until we're ultra confident in the conclusion. Nonetheless, good practice for everyone to rotate all passwords today, for any services. Good security hygiene any time, and especially now.

How can they know that? A broken web page could have been queried many, many times the last weeks and couldn't one of the responses contain Wave data?

Not 100% sure what their methodology is yet, and we're taking a cautious approach. At minimum, in the data that they've found in the wild, no Wave data was among it.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#133
In an email from Cloudflare sent out this morning they said:

> In our review of these third party caches, we discovered data that had been exposed from approximately 150 of Cloudflare's customers across our Free, Pro, Business, and Enterprise plans. We have reached out to these customers directly to provide them with a copy of the data that was exposed, help them understand its impact, and help them mitigate that impact.

Does this jive at all with the Google or Cloudflare disclosures? They are claiming that across all caches they only found and wiped data from ~150 domains, can that be true?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#135
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

That statement must have given Cloudfare's lawyer an aneurysm.

Seems to me that management's attempt to downplay the problem exposes the company to as much risk as the original technical mistake.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#137
post #99
post #7

I wrote this(1) script to check for any affected sites from local Chrome history. It checks for the header `cf-ray` in the response headers from the domain. It is not an exhaustive list but I was able to find few important ones like my bank site. 1: https://gist.github.com/kamaljoshi/2cce5f6d35cd28de8f6dbb27d...

I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.

Dashlane has that. Doesn't work with all sites though. But all major ones should work. See:

https://www.dashlane.com/features/password-changer

https://csdashlane.zendesk.com/hc/en-us/articles/202699281-H...

Supported sites: https://www.dashlane.com/en/password-changer-list

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#138
post #99
post #7

I wrote this(1) script to check for any affected sites from local Chrome history. It checks for the header `cf-ray` in the response headers from the domain. It is not an exhaustive list but I was able to find few important ones like my bank site. 1: https://gist.github.com/kamaljoshi/2cce5f6d35cd28de8f6dbb27d...

I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.

[deleted]

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#139

In an email from Cloudflare sent out this morning they said: > In our review of these third party caches, we discovered data that had been exposed from approximately 150 of Cloudflare's customers across our Free, Pro, Business, and Enterprise plans. We have reached out to these customers directly to provide them with a copy of the data that was exposed, help them understand its impact, and help them mitigate that imp…

Every single thing Cloudflare has said about impact has sounded very suspiciously optimistic to me. For example, they claim that they would know if an attacker had been intentionally exploiting this bug, but I've seen no details to justify their confidence.

So no, I don't think we can assume that the scope was as limited as they're making out.

Edit: As my coworker points out, as of 2013, they only kept 4 hours of access logs (source: https://blog.cloudflare.com/what-cloudflare-logs/). So basically their existing attack detection infrastructure (built without knowledge of this bug) may not have found anything suspicious, but it appears that that's the extent of what they can say about the last few months. They can claim that they found no evidence within the last week (one hopes that they stopped discarding logs when they found out about the attack), but if they want to convince us that they know this wasn't being exploited as late as two weeks ago, they need to provide specific evidence.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#140
post #99

Earlier quoted context omitted.

I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.

Isn't this what Watchtower is supposed to be for? I have no idea if AgileBits is going to add this list to Watchtower, though.

I never received any notification from Watchtower to change password during linkedin hack, Dropbox hack and Yahoo hack. Apparently Watchtower was only supposed to notify you about Heartbleed vulnerability according to their website.

> 1Password Watchtower is a service that identifies websites that are vulnerable to Heartbleed, and will suggest which sites need to have their passwords changed.

https://watchtower.agilebits.com/

Post reply on HN