Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611
List of Sites Affected by Cloudflare's HTTPS Traffic Leak
131–140 of 228 posts
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#132Earlier quoted context omitted.
Cloudfare has advised that Wave data has not been affected/leaked. We've got engineering and security teams investigating, and we'll keep on it until we're ultra confident in the conclusion. Nonetheless, good practice for everyone to rotate all passwords today, for any services. Good security hygiene any time, and especially now.
How can they know that? A broken web page could have been queried many, many times the last weeks and couldn't one of the responses contain Wave data?
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#133> In our review of these third party caches, we discovered data that had been exposed from approximately 150 of Cloudflare's customers across our Free, Pro, Business, and Enterprise plans. We have reached out to these customers directly to provide them with a copy of the data that was exposed, help them understand its impact, and help them mitigate that impact.
Does this jive at all with the Google or Cloudflare disclosures? They are claiming that across all caches they only found and wiped data from ~150 domains, can that be true?
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#134Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#135Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611
Seems to me that management's attempt to downplay the problem exposes the company to as much risk as the original technical mistake.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#136Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#137I wrote this(1) script to check for any affected sites from local Chrome history. It checks for the header `cf-ray` in the response headers from the domain. It is not an exhaustive list but I was able to find few important ones like my bank site. 1: https://gist.github.com/kamaljoshi/2cce5f6d35cd28de8f6dbb27d...
I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.
https://www.dashlane.com/features/password-changer
https://csdashlane.zendesk.com/hc/en-us/articles/202699281-H...
Supported sites: https://www.dashlane.com/en/password-changer-list
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#138I wrote this(1) script to check for any affected sites from local Chrome history. It checks for the header `cf-ray` in the response headers from the domain. It is not an exhaustive list but I was able to find few important ones like my bank site. 1: https://gist.github.com/kamaljoshi/2cce5f6d35cd28de8f6dbb27d...
I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#139In an email from Cloudflare sent out this morning they said: > In our review of these third party caches, we discovered data that had been exposed from approximately 150 of Cloudflare's customers across our Free, Pro, Business, and Enterprise plans. We have reached out to these customers directly to provide them with a copy of the data that was exposed, help them understand its impact, and help them mitigate that imp…
So no, I don't think we can assume that the scope was as limited as they're making out.
Edit: As my coworker points out, as of 2013, they only kept 4 hours of access logs (source: https://blog.cloudflare.com/what-cloudflare-logs/). So basically their existing attack detection infrastructure (built without knowledge of this bug) may not have found anything suspicious, but it appears that that's the extent of what they can say about the last few months. They can claim that they found no evidence within the last week (one hopes that they stopped discarding logs when they found out about the attack), but if they want to convince us that they know this wasn't being exploited as late as two weeks ago, they need to provide specific evidence.
Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak
#140Earlier quoted context omitted.
I wish 1Password had a feature where you could put in a list of domains like this or a "Auto Change Possibly Compromised Passwords" feature.
Isn't this what Watchtower is supposed to be for? I have no idea if AgileBits is going to add this list to Watchtower, though.
> 1Password Watchtower is a service that identifies websites that are vulnerable to Heartbleed, and will suggest which sites need to have their passwords changed.