Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

151–160 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#152
post #120

Earlier quoted context omitted.

Isn't this what Watchtower is supposed to be for? I have no idea if AgileBits is going to add this list to Watchtower, though.

Disclaimer: I work for AgileBits, makers of 1Password I am helping comb through a list of sites to see which of those has suggested password updates. I think we've had very few sites suggest updating the password though. Have you all seen any sites explicitly state users should update? If so I'd love a list so we can get them in Watchtower. Kyle

I would subscribe to Watchtower, or, heck, probably even 1Password Famlies, if AgileBits took a more aggressive/proactive approach to password updates: 1. Prompt batch password resets for services whose vulnerabilities have been exposed before those exposed admit their breach to consumers (e.g. All services compromised by the Cloudflare dump - usually consumers are the last to know). 2. Preformed all password resets in a secure AgileBits browser (assuming the browser built-in to 1Password on iOS is secure). 3. Had an optional prompt to prevent unintentionally syncing/backing-up 1Password data, and accessing said secure browser without first confirming VPN status with the operating system (maybe even prompt user to connect to VPN before unlocking if VPN connection isn't established)

Alternatively, I'd subscribe for integration of a 1Password browser extension for a reputable (regularly high, multiplatform AV-Test/NSS performance) internet security service's browser, and Watchtower was as sensitive as mentioned above and integrated with said internet security service.

This is coming from a longtime 1Password Pro user (3-6 yrs) who recently got his family on the 1Password bandwagon.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#153

Earlier quoted context omitted.

Has anything similar to this happened before?

No

How about when Matty got hacked and 4chan was defaced? While the technical details differ, the situation itself was almost equally bad.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#154
post #97

Just got this classy spam from dyn.com. Wonder if they're going through this list emailing every domain contact. > As you may be aware, Cloudflare incurred a security breach where user data from 3,400 websites was leaked and cached by search engines as a result of a bug. Sites affected included major ones like Uber, Fitbit, and OKCupid. > Cloudflare has admitted that the breach occurred, but Ormandy and other securit…

Coming from a company that regularly goes down to DDoS attacks :thinking:

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#155
post #143
post #134

Is there a "standard" in the works for changing a password? Stuff like this is happening rather too frequently for my taste. I need a tool I can use to update all my passwords everywhere automatically and store the new ones in my password manager.

LastPass has auto-password change: https://blog.lastpass.com/2015/05/auto-password-change-now-a...

Dashlane has that feature too.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#156
post #60

That's a wide impact. While any hijacked account is bad, some of these are really bad. For example, https://coinbase.com is on that list! If they haven't immediately invalidated every single HTTP session after hearing this news this is going to be bad. Ditto for forcing password resets. A hijacked account that can irrevocably send digital currency to an anonymous bad guy's account would be target number one for using…

coinbase is certainly one of the most concerning on that list- however they also support 2 factor authentication.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#157

In an email from Cloudflare sent out this morning they said: > In our review of these third party caches, we discovered data that had been exposed from approximately 150 of Cloudflare's customers across our Free, Pro, Business, and Enterprise plans. We have reached out to these customers directly to provide them with a copy of the data that was exposed, help them understand its impact, and help them mitigate that imp…

CloudFlare has no idea of knowing what was in uninitialized memory that was leaked. This is just spin.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#158

Couldn't find a practical description of who is affected anywhere. Is it just the customers who have Cloudflare HTTPS proxy service being affected, or anyone using Cloudflare DNS is affected?

Anyone who passes HTTP or HTTPS traffic via CloudFlare might have had that data leaked into other users sessions.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#159
post #57

Unfortunately this seem to include news.ycombinator.com

> This list contains all domains that use cloudflare DNS, not just the cloudflare SSL proxy (the affected service that leaked data). It's a broad sweeping list that includes everything. Just because a domain is on the list does not mean the site is compromised. In this case, HN , IIRC, does not use the proxy. Checking the certs, CloudFlare reissue using DigiCert, I think, whereas HN is using a Comodo cert.

You can upload your own cert to CloudFlare.

Hacker News does hit the CF proxy and was affected.

  $ host news.ycombinator.com
  news.ycombinator.com is an alias for news.ycombinator.com.cdn.cloudflare.net.
  news.ycombinator.com.cdn.cloudflare.net has address 104.20.44.44
  news.ycombinator.com.cdn.cloudflare.net has address 104.20.43.44

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#160
post #60

That's a wide impact. While any hijacked account is bad, some of these are really bad. For example, https://coinbase.com is on that list! If they haven't immediately invalidated every single HTTP session after hearing this news this is going to be bad. Ditto for forcing password resets. A hijacked account that can irrevocably send digital currency to an anonymous bad guy's account would be target number one for using…

coinbase is certainly one of the most concerning on that list- however they also support 2 factor authentication.

If you captured the right cookies though, you wouldn't need to log in with a password and be subject to OTP. That's why this is so problematic. Caveat: I haven't actually checked the details of Coinbase's session/security tokens.
Post reply on HN