Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

171–180 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#171
post #113

Earlier quoted context omitted.

It's clever but feels at least a 3/10 shitty. Dyn is an old company and back in the day they provided free subdomains while nobody else did. I haven't used them recently because their pricing seems so high. How do others feel about them?

I still have a lifetime standard DNS subscription with them from back in the day when they were dyndns.org and you could physically mail them cash. The DNS hosting has been very solid (except for the day Mirai took them offline) but the standard query limits are way too low for any moderately trafficked website. All the managed DNS providers I looked at seem to have very restrictive query limits without a "enterprise…

Why not he.net?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#172
post #97

Just got this classy spam from dyn.com. Wonder if they're going through this list emailing every domain contact. > As you may be aware, Cloudflare incurred a security breach where user data from 3,400 websites was leaked and cached by search engines as a result of a bug. Sites affected included major ones like Uber, Fitbit, and OKCupid. > Cloudflare has admitted that the breach occurred, but Ormandy and other securit…

They are strong competitors to each other, don't trust a word they say.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#173
post #33

I would like to point out that, if most sites used two-factor authentication, this leak would be at most a minor inconvenience. Maybe we should push for that more. Just days ago I talked to Namecheap about its horrible SMS-only 2FA and asked them to implement something actually secure, maybe contact your favorite site if they don't have 2FA yet.

2FA doesn't protect you against cookie/token stealing. The website owners need to invalidate all of that on their ends.

It does and you don't even need real 2FA for it.

Any non-trivial auth token comes with device or host fingerprinting. That's enough to stop this attack scenario in most cases.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#174
post #148
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

*Article says COO, but Twitter says CTO. Strange. And he's fairly active on these forums. That seems like such an odd thing to say given how important security is/should be at CF...curious if jgrahamc would further clarify his position here.

As far as I can tell he's basically 2nd-in-command.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#175
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

That's terrible... he may as well say "As a representative of the company, I want it to be made clear that I don't treat security seriously".

In trying to downplay it, he's making the matter even worse.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#176
post #113

Earlier quoted context omitted.

I still have a lifetime standard DNS subscription with them from back in the day when they were dyndns.org and you could physically mail them cash. The DNS hosting has been very solid (except for the day Mirai took them offline) but the standard query limits are way too low for any moderately trafficked website. All the managed DNS providers I looked at seem to have very restrictive query limits without a "enterprise…

Why not he.net?

I use he.net DNS quite a lot for personal projects. I've had a few instances where DNS was not resolving that make me a bit cautious to move larger sites onto their service.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#177
post #160

Earlier quoted context omitted.

coinbase is certainly one of the most concerning on that list- however they also support 2 factor authentication.

If you captured the right cookies though, you wouldn't need to log in with a password and be subject to OTP. That's why this is so problematic. Caveat: I haven't actually checked the details of Coinbase's session/security tokens.

This is true- but I'd assume all of these sites have flushed their session/cookie data by now.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#178
post #167

Earlier quoted context omitted.

Indeed, and it's pretty annoying having my site in that list despite not using CloudFlare's reverse proxy service. If my website handled user logins or sensitive data no doubt I'd have customers contacting me or shying away from my site now. This list needs more vetting.

Do you have a concrete suggestion for the list maintainer to better vet the list? Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live?

> Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live?

This is a scenario where it's impossible to prove innocence. Even if somebody provided you with the logs of their DNS server to show that the website never pointed to CloudFlare, I doubt these logs were stored in a way that their authenticity could be proved. In any case, the onus of proof should almost always be on the accuser, not the accused.

Since you pressure me for a suggestion: my suggestion would have been to only list websites that were using the reverse proxy service (as opposed to DNS) at the time the data was captured. This can be done by inspecting the http response headers, or maybe even just checking the DNS records against known CloudFlare servers (as opposed to checking the DNS provider).

But since you point out the transience of this, this method, as well as the method used to gather the list as-is are fundamentally flawed. I think a better way would be to locate DNS dumps throughout the vulnerability period & apply the above method to those.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#179
post #118

Worth noting this statement by Cloudflare CTO: "I am not changing any of my passwords. I think the probability that somebody saw something is so low it's not something I am concerned about." http://www.bbc.co.uk/news/technology-39077611

It's the modern version of the captain going down with the ship.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#180
post #96

Earlier quoted context omitted.

> Welp, time to stop using the same password for multiple services. > Welp, time to start using a password manager. FTFY

OP isn't saying they used the same password for transferwise as for their bank. Transferwise allows you to log into your internet banking and authorize a transaction through their site. You actually give them your internet banking password, regardless of how you log into their site. Which is pretty strange in itself, to trust a 3rd party with your internet banking password, but that's how it works.

Folks should review their banks' policies before doing this.

For example Bank of America won't hold customers liable for fraudulent transfers or bill pay transactions through their website, but sharing your online ID and password seems to void that protection.

https://www.bankofamerica.com/onlinebanking/online-banking-s...

Post reply on HN