Live data from Hacker News

List of Sites Affected by Cloudflare's HTTPS Traffic Leak

github.com

221–228 of 228 posts

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#221
post #145

Earlier quoted context omitted.

I never received any notification from Watchtower to change password during linkedin hack, Dropbox hack and Yahoo hack. Apparently Watchtower was only supposed to notify you about Heartbleed vulnerability according to their website. > 1Password Watchtower is a service that identifies websites that are vulnerable to Heartbleed, and will suggest which sites need to have their passwords changed. https://watchtower.agile…

We update it all the time with new items as we see them announced. It won't contain all of them but whatever we stumble on or see in various places get added when there's an actionable thing a user can do. We've added a handful of sites today that have suggested changing passwords after this announcement. Kyle AgileBits

As a happy customer of 1Password, it would be great to see you connect with Have I been pwned?[1] for watchtower notifications.

[1] https://haveibeenpwned.com/

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#222
post #97

Just got this classy spam from dyn.com. Wonder if they're going through this list emailing every domain contact. > As you may be aware, Cloudflare incurred a security breach where user data from 3,400 websites was leaked and cached by search engines as a result of a bug. Sites affected included major ones like Uber, Fitbit, and OKCupid. > Cloudflare has admitted that the breach occurred, but Ormandy and other securit…

Here's the email I got from Cloudflare as a Dyn customer during the DDOS attacks: > "As I'm sure you're aware, DDoS attacks on Dyn's network have caused massive outages for millions of sites. This prompted me to reach out on the behalf of Cloudflare to see if we can be helpful. > Over the last 24 hours, we've been helping other Dyn customers migrate to Cloudflare to mitigate the risk. > Who on your team would be the…

I think it's a bit more forgivable if they did it in response to this message. A good blend of cheeky and poking with a stick.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#223
post #168

Earlier quoted context omitted.

I suppose it could be seen as a response in kind after: https://blog.cloudflare.com/dyn-issues-affecting-joint-custo... I would consider an email a bit of an escalation though, as opposed to a blog post.

The DYN attack affected Cloudflare customers, and we received a lot of support tickets that day. The blog post was more than warranted. The CEO and managers made sure the sales people weren't scummy in their tactics.

See the message I received as a Dyn customer... The sales people were scummy in their tactics.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#224

I wrote a simple website[1] to show if user have visited the websites included in the list automatically without browser plug-ins. It uses :visited CSS pseudo-class to highlight the site user have visited before. It is not 100% accurate, but it can be a fun way to quickly show people that they may visit sites on the list. [1] https://cloudbleed.github.io/

I want to share this with my more non-techy persons, but, on Chrome, turning of uOrigin, their are no names of companies listed. I can hover over every block for the name, but.. is this an error, or intentional to just have a large heart-block with no labels?

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#225
post #224

I wrote a simple website[1] to show if user have visited the websites included in the list automatically without browser plug-ins. It uses :visited CSS pseudo-class to highlight the site user have visited before. It is not 100% accurate, but it can be a fun way to quickly show people that they may visit sites on the list. [1] https://cloudbleed.github.io/

I want to share this with my more non-techy persons, but, on Chrome, turning of uOrigin, their are no names of companies listed. I can hover over every block for the name, but.. is this an error, or intentional to just have a large heart-block with no labels?

Could you suggest how the names of companies should be shown so we can improve the website? Appreciate your reply :)

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#226
post #81

Today I learned that uber does not have a change password option once you are logged in. You have to log out and pretend you forgot the password. Bad UX if you don't know.

The downside of mobile first or mobile only for that matter. Normal web flows are downplayed. Not that this is excusable for a company of this size.

There is no logged-in access to password reset in the (android) mobile app either.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#227
post #224

Earlier quoted context omitted.

I want to share this with my more non-techy persons, but, on Chrome, turning of uOrigin, their are no names of companies listed. I can hover over every block for the name, but.. is this an error, or intentional to just have a large heart-block with no labels?

Could you suggest how the names of companies should be shown so we can improve the website? Appreciate your reply :)

Just a right-side text that highlights once you mouse-over would be great. It may be too much to display all of names, but having it populate gives some idea of where you need to go.

Perhaps just every "red"/affected site could be populated on the right side :)

Appreciate the layout outside of naming labels however, nice work.

Re: List of Sites Affected by Cloudflare's HTTPS Traffic Leak

#228
post #168

Earlier quoted context omitted.

The DYN attack affected Cloudflare customers, and we received a lot of support tickets that day. The blog post was more than warranted. The CEO and managers made sure the sales people weren't scummy in their tactics.

See the message I received as a Dyn customer... The sales people were scummy in their tactics.

I don't think the Cloudflare message is nearly as scummy as the Dyn messaging.

Dyn makes it seem like the entire underlying tech at Cloudflare is vulnerable.

P.S. I no longer work at Cloudflare, so I don't really care, just my .02

Post reply on HN