Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

181–190 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#181
post #167

Earlier quoted context omitted.

Do you have a concrete suggestion for the list maintainer to better vet the list? Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live?

> Can you prove that your site did not use the reverse proxy service at any point while the vulnerability was live? This is a scenario where it's impossible to prove innocence. Even if somebody provided you with the logs of their DNS server to show that the website never pointed to CloudFlare, I doubt these logs were stored in a way that their authenticity could be proved. In any case, the onus of proof should almost…

Thanks for answering!

Your last idea is a good idea but more work for the list editor. I'm not sure the motivations of the list editor, but if he or she is just an impartial volunteer (important assumption), it seems like it's really Cloudflare's responsibility to deliver a comprehensive report of affected sites, so that we don't have to guess?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#182

Earlier quoted context omitted.

Has anything similar to this happened before?

No

@jgrahamc how can you even answer that question when you didn't detect the issue yourselves?

The email we received was a joke, OK great our domains 'weren't affected' in the sense of memory dumps weren't being injected into our HTML, and luckily we only proxy static images/html through CF so at worst a visitor's google analytics cookie could have been leaked, but on a personal level any person who has used any CF-proxied website (e.g. Uber) in the past few months is potentially affected.

Whether or not you think it's likely anyone discovered this earlier, the fact remains that private data is still in various public and private caches around the world. It's a monumental cock-up that will require every CF proxy customer to rotate keys, invalidate tokens and force mass password resets to ensure complete peace of mind for millions of consumers who will probably never hear about this issue even though their credit card information, passwords and private messages could be floating around the internet as part of a cached version of a website they've never even visited.

Even the way you're looking for cached data to find affected customers - yeah ok, for page x.com/y you found data for customer z.com, but what about the other million times that affected x.com/y page was loaded, that could be data from a million different customers that someone else (human or otherwise) saw, whether they realised what it was or not. And trust me there are more than a few people on the planet who would know _exactly_ what they were seeing.

Forget about shareholder value for a minute, please, because it's an absolutely fatal mistake for your company to downplay an issue like this.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#183
This is ridiculous and somewhat irresponsible. This is just a list of domains using CloudFlare. The leak was only active under a set of very specific cases (email obfuscation, server-side excludes and automatic https rewrites).

I question Pirates (https://github.com/pirate) motives for even doing this? Karma? Reputation?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#184

This is ridiculous and somewhat irresponsible. This is just a list of domains using CloudFlare. The leak was only active under a set of very specific cases (email obfuscation, server-side excludes and automatic https rewrites). I question Pirates ( https://github.com/pirate ) motives for even doing this? Karma? Reputation?

Only a few hundred sites were leaking, sure, but the leaked info could have come from any domain that was being proxied by the same edge server. So we would do better to assume that any domain that uses Cloudflare could have had their passwords and other sensitive info exposed via leaky neighbors.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#185
post #184

This is ridiculous and somewhat irresponsible. This is just a list of domains using CloudFlare. The leak was only active under a set of very specific cases (email obfuscation, server-side excludes and automatic https rewrites). I question Pirates ( https://github.com/pirate ) motives for even doing this? Karma? Reputation?

Only a few hundred sites were leaking, sure, but the leaked info could have come from any domain that was being proxied by the same edge server. So we would do better to assume that any domain that uses Cloudflare could have had their passwords and other sensitive info exposed via leaky neighbors.

Thanks for clarifying. You are absolutely right.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#186
post #41

Earlier quoted context omitted.

Unless the web site was paranoid enough to encrypt your password client-side before sending it to the server, it's possible the password was leaked. With 2FA, your password and a one-time code were leaked and cached somewhere, but in order to log in as you today, an intruder would need to know a new code. And they wouldn't, unless you happened to set up your time-based one-time password (TOTP, e.g. Google Authenticat…

What is the timeframe where setting up TOTP is vulnerable? I haven't been able to find an indication of how long this bug has been in production.

Cloudflare shares a timeline on their blog post:

  The three features implicated were rolled out as follows.
  The earliest date memory could have leaked is 2016-09-22.

  2016-09-22 Automatic HTTP Rewrites enabled
  2017-01-30 Server-Side Excludes migrated to new parser 
  2017-02-13 Email Obfuscation partially migrated to new parser 
  2017-02-18 Google reports problem to Cloudflare and leak is stopped

  The greatest potential impact occurred for four days starting
  on February 13 because Automatic HTTP Rewrites wasn’t widely
  used and Server-Side Excludes only activate for malicious
  IP addresses.
https://blog.cloudflare.com/incident-report-on-memory-leak-c...

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#187
post #51

What if I sign in with facebook or other? Should I change muy password con facebook or what?

TL;DR? You should be ok... Long Version. That (most likely) would of used oauth. So instead of sending your FB password to the site to log you into FB with. You give your FB password (if your not signed in) to FB and then facebook give the site using "sign in with Facebook" a token they can use with facebook to get account info / do actions on your FB account. Now depending on which "sign in with" system you used the…

Its always interesting to me that such a good answer implies technical excellence of its own, but criticism follows: "would of" which you used twice (and therefore more likely intentionally) is not correct English! The correct phrase is "would have" and its easy to see why, online, people use "of" .. when speaking, the h is silent and the contracted written form is "would've" so it does sound similar, but because "of" and "have" have such different meanings, it always seems really dissonant to see that written.

pedantic regards, clort

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#188
post #182

Earlier quoted context omitted.

No

@jgrahamc how can you even answer that question when you didn't detect the issue yourselves? The email we received was a joke, OK great our domains 'weren't affected' in the sense of memory dumps weren't being injected into our HTML, and luckily we only proxy static images/html through CF so at worst a visitor's google analytics cookie could have been leaked, but on a personal level any person who has used any CF-pro…

I haven't for once thought about cost or shareholder value in the last week. Been working round the clock to clean up and evaluate impact.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#189

Earlier quoted context omitted.

We are in the process of contacting customer who we are able had information cached by a search engine.

That's not the biggest risk. The biggest risk is that a malicious actor stumbled upon this bug, realized they could trigger it with specially crafted HTML, then wrote a script to harvest the data, which would be private data from any website with an active session in memory on the shared proxy. In that case, the bigger websites are more likely to be affected, because high traffic means they're more likely to have dat…

I understand and we have been and are mining data we have to look for that having happened.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#190
I ginned up this little tool tonight to help people out instead of grepping.

https://bleed.cloud/index.html

Sorry for the index.html, trying to figure out how to get index file to work on cloudfront.

You can also run the python script on the website anonymously on your computer to dig sites out of your email, which is a good indicator that you have an account with them.

Post reply on HN