Live data from Hacker News

Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

bugs.chromium.org

991–1000 of 1001 posts

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#991
post #971

Earlier quoted context omitted.

You might not know the history here. Tavis works at Google and discovered the bug. He was extremely helpful and has gone out of his way to help Cloudflare do disaster mitigation, working long hours throughout last weekend and this week. He discovered one of the worst private information leaks in the history of the internet, and for that, he won the highest reward in their bug bounty: a Cloudflare t-shirt. They also t…

I think this is a one-sided view of what really happened. I can see a whole team at Cloudflare panicking, trying to solve the issue, trying to communicate with big crawlers trying to evict all of the bad cache they have while trying to craft a blogpost that would save them from a PR catastrophe. All the while Taviso is just becoming more and more aggressive to get the story out there. 6 freaking days. short timeline…

Google Project Zero has two standard disclosure deadlines: 90 days for normal 0days, and 7 days for vulnerabilities that are actively being exploited or otherwise already victimizing people.

There are very good reasons to enforce clear rules like this.

Cloudbleed obviously falls into the second category.

Legally, there's nothing stopping researchers from simply publishing a vulnerability as soon as they find it. The fact that they give the vendor a heads-up at all is a courtesy to the vendor and to their clients.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#992
post #879

Earlier quoted context omitted.

Matthew, with all due respect, you don't know what you're talking about. view-source: http://cc.bingj.com/cache.aspx?q=&d=4857656909960944&w=rj9cg... view-source: http://cc.bingj.com/cache.aspx?q=&d=4901023173710126&w=n3mEZ... view-source: http://cc.bingj.com/cache.aspx?q=&d=4558611265887320&w=urwoW... view-source: http://cc.bingj.com/cache.aspx?q=&d=4592983872701813&w=Ghwdd... view-source: http://cc.bingj.com/cache.…

How about clearing all the cache? (Or at least everything created the last few months.) I've never seen anyone suggest it, I suppose It cannot or should not be done for some reason?

The real problem is going to be where history matters and you can't delete - for example archive.org and httparchive.org. There is no way to reproduce the content in the archive obviously, so no one will be deleting it. The only way is to start a massive (and I mean MASSIVE) sanitization project...

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#993

Has anybody else actually received an email from Cloudflare about this? I'm a paying customer, but haven't heard anything from them yet. I hope they don't expect they can leave it at a random blog post that will go by unnoticed?

Has anybody received an email to say that their data WAS exposed?

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#994

Earlier quoted context omitted.

We're compiling a list of domains using several scrapers and updating it here: https://github.com/pirate/sites-using-cloudflare You can start by cross referencing your password manager with this list, and working your way out from there.

As an aside, I found this really interesting: ashleymadison.com ashleyrnadison.com I find it really interesting that they registered that particular misspelling and they both point to the same servers. I can see doing this for some obvious domains like gogle.com, but the distinction there is simply that r+n looks like m. Probably a really obvious answer here, but my guess is that they are trying to help people throw…

I think it's more likely that they bought the domain to prevent scammers from trying to bait users onto a fake site and enter login info, and since they have it why not redirect traffic.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#995
post #841
post #665

Earlier quoted context omitted.

How about... stop CLOUD THIS and CLOUD THAT. Cloud means extreme centralization. It means giving your data to a third party you don't control. Why? Why does our networked software have to assume a centralized topology? In the days when developed countries had dialup, protocols (IRC, Email, etc.) were all decentralized. Today, all the famous developers live with fancy broadband internet connections and forgot what it'…

lol, qbix.com connects to cloudflare.com

What are you talking about?

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#996
post #897

Earlier quoted context omitted.

> Nah. Bug bounties don't work for services like CDNs. Maybe they do elsewhere. But for enterprise services, the noise rate is too high, and the very good bug finders are either salaried, free, or working for the adversary. Yes, running a real bug bounty system requires professional security engineers and a professional security posture to sort through the noise. However, when the sole product you are selling is secu…

Here's a question: what's the trade-off in terms of return on investment between hiring salaried security engineers to administer a bug bounty and hiring salaried security engineers to find bugs directly? Parent's claim, as I read it, is that it's a better use of an enterprise CDN's money to hire security engineers to find bugs than to administer a bounty. Seems plausible to me. Where's that line?

> Parent's claim, as I read it, is that it's a better use of an enterprise CDN's money to hire security engineers to find bugs than to administer a bounty. Seems plausible to me. Where's that line?

Depends on the company, but tbpfh, most security engineers in a group tend to have a culture and that culture creates common blindspots. The fact they weren't testing for this sort of issue (i.e. parser memory leaks) is an example of something that seems obvious to some people that others ignore.

Maybe that is just my experience tho.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#997
post #714

Earlier quoted context omitted.

No. Only Cloudflare customers using a subset of features of the SSL proxy service are impacted. Cloudflare has a lot of customers who only use the free DNS service, for example.

Careful. It appears that any Cloudflare client who was sending HTTP/S traffic through their proxies is affected. A small subset of their customers had the specific problem that triggered the bug, but once triggered, the bug disclosed secrets from all their web customers. You're not exposed if you never sent traffic through their proxies; for instance, if you somehow only used them for DNS.

I suspect there are a large number of Cloudflare customers that only use their DNS. I have a couple of domains in this category.

The DNS service is essentially free. It's an upgrade from most registrars' built-in DNS. It's a pretty robust solution, really -- global footprint, DNSSEC, fully working IPv6, etc.

My point is, the actual number of impacted customers was much smaller than the entire set of Cloudflare customers. There are lists in this thread that still reference hundreds of thousands (millions?) of sites, and that's just wrong.

(I agree on your first point though; I was confused about the nature of the proxy bug at first).

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#998
post #711

Earlier quoted context omitted.

This list is misguided. It's just a dump of sites using Cloudflare's DNS, a hugely popular and (mostly) free service. The vulnerability only affected customers using Cloudflare's paid SSL proxy (CDN) service. The latter is a much smaller subset. Even then, only a subset of the SSL proxy users, those with certain options enabled that caused traffic to go through a vulnerable parser, were really impacted. I'm not sure…

This is not correct in my understanding: The sites with certain options enabled produced the erroneous behavior, but the data that would get leaked through this behavior could be from any site that uses Cloudflare SSL (as this requires Cloudflare to tunnel SSL traffic through their servers, decrypt it and re-encrypt it with their wildcard certificate). So if I understand correctly anyone using the (free) Cloudflare S…

I was wrong about the nature of the proxy issue, but right about DNS-only customers. Customers using only the free DNS service were not impacted by this at all, because traffic never flowed through the proxies.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#999

Earlier quoted context omitted.

But - I can't think of a single language in which using it "wrong" might not lead to info leaks? Any language with a runtime has to manage memory somehow at the runtime layer and so similar leaks can occur there depending upon design and implementation, and the wider OS context. At the whole program/application level, when you create your own data structures, you can find lots of ways to leak them to the world.

No one calls C#, JavaScript and Python memory unsafe because their runtimes are implemented in C. Nor do I expect CF to not use Linux or Nginx because they are written in C. We have to live with C but I expect everyone who does anything safety or security critical to do everything they can to minimize the amount code that is susceptible to this class of bug. Using a runtime with a safe language on top is a perfectly…

Regarding C#, the plan is to increasingly move C++ code to C#, now that they have Roslyn and .NET Native.

Re: Cloudflare Reverse Proxies Are Dumping Uninitialized Memory

#1000
Time for the C. A. R. Hoare's weekly quote, taking time to reflect on what happened since 1981 regarding computer security on system languages.

The first principle was security: The principle that every syntactically incorrect program should be rejected by the compiler and that every syntactically correct program should give a result or an error message that was predictable and comprehensible in terms of the source language program itself. Thus no core dumps should ever be necessary. It was logically impossible for any source language program to cause the computer to run wild, either at compile time or at run time. A consequence of this principle is that every occurrence of every subscript of every subscripted variable was on every occasion checked at run time against both the upper and the lower declared bounds of the array. Many years later we asked our customers whether they wished us to provide an option to switch off these checks in the interests of efficiency on production runs. Unanimously, they urged us not to - they already knew how frequently subscript errors occur on production runs where failure to detect them could be disastrous. I note with fear and horror that even in 1980, language designers and users have not learned this lesson. In any respectable branch of engineering, failure to observe such elementary precautions would have long been against the law.

-- Turing Award lecture 1981

Post reply on HN