Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

161–170 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#161

Earlier quoted context omitted.

I typically think of "encryption inside of encryption" as a boondoggle more likely to somehow break things than make things stronger. My confidence in that has dropped slightly in the past day.

I'm no expert, but intuitively it would seem that encryption-inside-encryption would be snake oil when they're meant to guard against the same layer/attack vector/threat model: for example, if you nest Serpent inside AES for a single local file encryption operation ( ahem , TrueCrypt), that seems very gimmicky. But if the encryption are supposed to protect separate and independent OSI layers or operation steps, then…

>for example, if you nest Serpent inside AES for a single local file encryption operation (ahem, TrueCrypt), that seems very gimmicky.

I take it to be insurance against a future vulnerablility discovered in one of the algorithms. For some scenarios it seems like the cost can be worth it.

On the other hand, nested hashing has always seemed counter productive as it seems plausible that nesting hash functions can decrease the randomness of the image.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#162
Just received an email from Glidera, a Bitcoin exchange. This is the first service to ask me to reset my password. I wonder why Uber, NameCheap, FitBit, and many others have yet to warn their users? Is Cloudflare downplaying this?

> Hi [Username],

> A bug was recently discovered with Cloudflare, which Glidera and many other websites use for DoS protection and other services. Due to the nature of the bug, we recommend as a precaution that you change your Glidera security credentials:

> Change your password > Change your two-factor authentication

> You should similarly change your security credentials for other websites that use Cloudflare (see the link below for a list of possibly affected sites). If you are using the same password for multiple sites, you should change this immediately so that you have a unique password for each site. And you should enable two-factor authentication for every site that supports it.

> The Cloudflare bug has now been fixed, but it caused sensitive data like passwords to be leaked during a very small percentage of HTTP requests. The peak period of leakage is thought to have occurred between Feb 13 and Feb 18 when about 0.00003% of HTTP requests were affected. Although the rate of leakage was low, the information that might have been leaked could be very sensitive, so it’s important that you take appropriate precautions to protect yourself.

> The actual leaks are thought to have only started about 6 months ago, so two-factor authentication generated before that time are probably safe, but we recommend changing them anyway because the vulnerability potentially existed for years.

> Please note that this bug does NOT mean that Glidera itself has been hacked or breached, but since individual security credentials may have been leaked some individual accounts could be vulnerable and everyone should change their credentials as a safeguard.

> Here are some links for further reading on the Cloudflare bug:

> TechCrunch article: https://techcrunch.com/2017/02/23/major-cloudflare-bug-leake... > List of sites possibly affected by the bug: https://github.com/pirate/sites-using-cloudflare/blob/master...

> If you have any questions or concerns in response to this email, please contact support at: support@glidera.io

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#163

Just received an email from Glidera, a Bitcoin exchange. This is the first service to ask me to reset my password. I wonder why Uber, NameCheap, FitBit, and many others have yet to warn their users? Is Cloudflare downplaying this? > Hi [Username], > A bug was recently discovered with Cloudflare, which Glidera and many other websites use for DoS protection and other services. Due to the nature of the bug, we recommend…

Namecheap: https://blog.namecheap.com/cloudflare-security-incident/

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#164
post #116
post #114

Something I have a hard time understanding, is how Cloudfare's cache generator page had access to sensitive information ? Were the 2 things running on the same process? If they were not, there's no way that the buffer overrun could read an other process memory, right? it would have failed with a segfault type of error. If so, shouldn't Cloudfare consider running the sensitive stuff on a different process, so that no…

SSL connections were terminating at the proxy, so the proxy used plain HTTP to the web service backends.

Unsure about the random downvotes. It's CloudFlare's "Flexible SSL" offering. Granted, sibling non-speculative comments elaborate more thoroughly for the "non-flexible" cases.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#165

Authy is on the list. It would be really nice if they confirmed whether they are vulnerable or not, considering they hold all of my 2FA tokens. Otherwise I'll have to re-key the database.

Wouldn't you rather just do that as a precaution? Then you won't be constantly worried that they might have had their data leaked.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#166
post #41

Earlier quoted context omitted.

Can you explain how 2FA would have helped?

Unless the web site was paranoid enough to encrypt your password client-side before sending it to the server, it's possible the password was leaked. With 2FA, your password and a one-time code were leaked and cached somewhere, but in order to log in as you today, an intruder would need to know a new code. And they wouldn't, unless you happened to set up your time-based one-time password (TOTP, e.g. Google Authenticat…

What is the timeframe where setting up TOTP is vulnerable? I haven't been able to find an indication of how long this bug has been in production.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#167
post #77

Earlier quoted context omitted.

Sites using Cloudflare in DNS only mode won't have sent any requests that could be leaked.

Indeed, and it's pretty annoying having my site in that list despite not using CloudFlare's reverse proxy service. If my website handled user logins or sensitive data no doubt I'd have customers contacting me or shying away from my site now. This list needs more vetting.

Do you have a concrete suggestion for the list maintainer to better vet the list?

Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#168
post #97

Just got this classy spam from dyn.com. Wonder if they're going through this list emailing every domain contact. > As you may be aware, Cloudflare incurred a security breach where user data from 3,400 websites was leaked and cached by search engines as a result of a bug. Sites affected included major ones like Uber, Fitbit, and OKCupid. > Cloudflare has admitted that the breach occurred, but Ormandy and other securit…

I suppose it could be seen as a response in kind after: https://blog.cloudflare.com/dyn-issues-affecting-joint-custo... I would consider an email a bit of an escalation though, as opposed to a blog post.

The DYN attack affected Cloudflare customers, and we received a lot of support tickets that day. The blog post was more than warranted. The CEO and managers made sure the sales people weren't scummy in their tactics.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#169
post #97

Just got this classy spam from dyn.com. Wonder if they're going through this list emailing every domain contact. > As you may be aware, Cloudflare incurred a security breach where user data from 3,400 websites was leaked and cached by search engines as a result of a bug. Sites affected included major ones like Uber, Fitbit, and OKCupid. > Cloudflare has admitted that the breach occurred, but Ormandy and other securit…

It's clever but feels at least a 3/10 shitty. Dyn is an old company and back in the day they provided free subdomains while nobody else did. I haven't used them recently because their pricing seems so high. How do others feel about them?

> I haven't used them recently because their pricing seems so high. How do others feel about them?

I feel about them that the free dynamic DNS option with a Namecheap registration offers everything Dyn did except built in options on cheap home routers.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#170
post #148
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

*Article says COO, but Twitter says CTO. Strange. And he's fairly active on these forums. That seems like such an odd thing to say given how important security is/should be at CF...curious if jgrahamc would further clarify his position here.

Agreed on the importance of security, but if his credentials from outside their network are able to be used in any significant way to impact their services or systems then they're doing something tragically wrong. For that matter if his credentials can be used anywhere to impact their services it's a failure.
Post reply on HN