Live data from Hacker News

Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

bugs.chromium.org

561–570 of 1001 posts

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#561

Earlier quoted context omitted.

I found: FitBit Hacker News Stack Overflow Zendesk Discord FastMail (not really see below)

We, FastMail, are not affected by this. We do not proxy TLS connections via any third party. We use CloudFlare for DNS distribution only, which is not part of this issue.

Thanks for posting here, I was explicitly looking to see if anyone mentioned Fastmail after I saw it on that Github list. You might want to post something on your site if you haven't already, kinda like 1password did.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#562
So.. when are we going to stop using unsafe languages which allows these kinds of memory corruption or leaks? If this is not reason enough, what else needs to happen before people realise that whatever language the cloudflare proxy is written in is a really bad one?

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#563

Has anybody else actually received an email from Cloudflare about this? I'm a paying customer, but haven't heard anything from them yet. I hope they don't expect they can leave it at a random blog post that will go by unnoticed?

Another paying customer here. No email communication from CloudFlare. Found out about this on HN.

You and OP should contact them, as customers.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#564
What is the optimal balance between centralization and decentralization? Most people in this thread are complaining about how using a big centralized service (cloudfare) causes so much damage when security issues come up, and yet I have seen many people advocate using a single password manager (like 1password) to which this exact type of huge security problem can happen (your password manager is the single point of security failure which can comprimise all of your accounts!!!).

What is the optimal solution???

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#565

>Cloudflare pointed out their bug bounty program, but I noticed it has a top-tier reward of a t-shirt. Considering the amount and sensitivity of the data they handle, I'm not sure a t-shirt is an appropriate top-tier reward.

Not only that, but the "reward" in the program is laughable and frankly insulting to any serious researcher considering the scope of CF. Bug bounty platforms are already becoming the fiverr of ITSEC (that's not a good thing), CF just made an extra effort do diminish the value for researchers. Management: "Why do we offer $5k for a small bug again? Look at CF, they don't offer any money!"

I don't disagree.

But, Taviso is probably contractually prohibited from accepting money from CF as a Google employee. Many large companies have 'outside activity' clauses and Google seems to be paying him already for that.

However, it will affect others whom are fully freelance.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#566
post #414

Earlier quoted context omitted.

How did you find that IP?

I used Censys to search for the IPv4 addresses of servers serving matching TLS certificates: https://censys.io/ipv4?q=443.https.tls.certificate.parsed.na...

Couldn't someone DDoS'ing a site use this to get around Cloudflare "protection?"

Uh, asking for a friend.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#567
post #178

Earlier quoted context omitted.

Because you'll make much more working for people who specifically hire you instead of doing a bunch of risky work on spec.

The point of bug bounties isn't to attract the interest of people who are working to find bugs . It's to make sure that if someone is finding bugs for fun or stumbles over bugs by accident , it's worth their time to report the bugs.

  >>  top-tier reward of a t-shirt.
A t-shirt still seems entirely too small; closer to insulting than motivating.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#568
post #11

Step 1) MITM the entire Internet, undermining its SSL infrastructure, build a business around it Step 2) leak cleartext from said MITM'd connections to the entire Internet I recently noted that in some ways Cloudflare are probably the only entity to have ever managed to cause more damage to popular cryptography since the 2008 Debian OpenSSL bug (thanks to their "flexible" ""SSL"" """feature"""), but now I'm certain o…

They also actively deter Tor use. I've cancelled subscriptions with Cloudflare-hosted sites because they make securely and anonymously browsing their sites a pain.

It makes sense that they treat Tor like a probable adversary, but the cost analysis seems really flawed.

Sure, the proportion of requests passing through Tor are more likely to be malicious, but given the bandwidth constraints the adversary seems limited.

The costs aren't only the lost business from people like you, but people who should use Tor giving in. There's some wisdom to people even researching something as mundane as what their dog ingested using anonymized services, much less other medical questions.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#570
Chrome marking Cloudflare HTTPS as "Secure" must be turned into something different, like "Not So Secure" or whatever. Secure = end to end.

Cloudflare is MitM by design. Chrome and others must not tolerate it. This vulnerability is just another reason to do it asap.

Post reply on HN