Another day, another C memory safety bug that completely breaks all security everywhere. We're definitely doomed to repeat the same mistakes over and over.
Probably only for 30-50 more years, honestly.
Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
621–630 of 1001 posts
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#622Can we start a list of affected right now? I found: OKCupid Uber people claiming 1Password, can't find Reddit Lyft Yelp Pingdom Digital Ocean Montecito Bank and Trust
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#623Earlier quoted context omitted.
We're compiling a list of domains using several scrapers and updating it here: https://github.com/pirate/sites-using-cloudflare You can start by cross referencing your password manager with this list, and working your way out from there.
You don't have to use scrapers, just use copies of the TLD zone files looking for cloudflare nameservers.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#624Earlier quoted context omitted.
> The infosec team worked to identify URIs in search engine caches that had leaked memory and get them purged. With the help of Google, Yahoo, Bing and others, we found 770 unique URIs that had been cached and which contained leaked memory. Those 770 unique URIs covered 161 unique domains. The leaked memory has been purged with the help of the search engines. So I tried it too, and there's still data cached there. Am…
jgrahamc: can you list which public caches you worked with to attempt to address this? It does not inspire confidence when even google is still showing obvious results
I agree it's troubling that Google is taking so long. We were working with them to coordinate disclosure after their caches were cleared. While I am thankful to the Project Zero team for their informing us of the issue quickly, I'm troubled that they went ahead with disclosure before Google crawl team could complete the refresh of their own cache. We have continued to escalate this within Google to get the crawl team to prioritize the clearing of their caches as that is the highest priority remaining remediation step.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#625Earlier quoted context omitted.
Lastpass knows how to change your passwords for many popular sites, and can automate it away for you.
LastPass uses local encryption to enable LastPass to have Zero knowledge of users passwords. This means that user's passwords aren't passed in the clear even inside a TSL session. So LastPass isn't the password manager mentioned in the post.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#626Earlier quoted context omitted.
As for the SHA-1 collision mentioned by jgrahamc[1] earlier today: How am I going to explain this to my wife? Actually a serious question. How do we communicate something like this to the general public? [1] https://news.ycombinator.com/item?id=13713826
"It's like some extremely popular remailer company accidentally put badly or barely shredded copies of handled letters into other people's envelopes. Strangers' sensitive info is potentially sitting inside unsuspecting mailboxes worldwide."
Or used as confetti for a parade: http://www.npr.org/2012/11/27/166023474/social-security-numb...
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#627This comes around to me as something that just shouldn't have happened. CloudFlare are pretty big on Go, as far as I can tell (and I guess Lua for scripting nginx). Why was this parsing package written in a non memory-safe language? Parsing is one of those "obvious" things easy to mess up; the likelihood of a custom, hand written parser being buggy is pretty high. If it's somehow understood that your library is likel…
[1] https://www.nginx.com/resources/wiki/extending/api/main/
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#628Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#629Earlier quoted context omitted.
They also actively deter Tor use. I've cancelled subscriptions with Cloudflare-hosted sites because they make securely and anonymously browsing their sites a pain.
I'm running a side-project on Cloudflare and it's accessible through Tor without problems. I suspect this comes down to the settings a site owner sets up in their Cloudflare interface. It would stand to reason if for example you applied the highest security setting across the board, Tor and VPN users would get presented with a captcha.
Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
#630Also, mono-cultures have always been a very bad idea, not just in agriculture.