4 ms·
> Many of the logged urls contained query strings from https requests that I don't think they intended to share. I guess this confirms a few things. - The com
by Tiksi 10y ago
> Many of the logged urls contained query strings from https requests that I don't think they intended to share.
I guess this confirms a few things.
- The complete query strings are logged,
- They don't appear to be too concerned with who accesses the logs internally or have a process that limits the access, and
- They're willing to send those logs out to a random person.
- jgrahamc 10y agoThis has nothing to do with logging.
- Tiksi 10y agoThe quoted part that specifically mentions logged urls containing query strings has nothing to do with logging?
- jgrahamc 10y agoThat's Google logging stuff
- lima 10y agoI read it as "sensitive query strings sent to Google by CloudFlare engineers".
- geofft 10y agoThat's not how Google tells it, if I'm reading this right: Cloudflare explained that they pushed a change to production that logged malformed pages that were requested, and then sent me the list of URLs to double check. Many of the logged urls contained query strings from https requests that I don't think they intended to share. (I'm reading that as "intended to share with Google".)
- jgrahamc 10y agoAh. I see what you mean. Apologies, kind of tired.
- ghughes 10y agoIf Cloudflare accidentally leaked additional sensitive data to Tavis during the handling of this incident, and that data wasn't already compromised by the parser bug, then you should call that out in the incident report.
- Kalium 10y agoUnderstandably, I think. I can't imagine you've had much sleep this week.
- shock 10y agoI don't think that's the case: from my reading of the issue I understood that the urls with query params were sent from CF to Google for clearing from the google cache.
- deleted 10y ago[deleted]
- geofft 10y agoDuring debugging, that seems fine. The previous sentence makes it clear that they added specific logging to track down the problem. I'd rather have a process that allows engineers debugging memory corruption to see the data that's in the process they're debugging, than a process that prohibits them from seeing it.