8 ms·
jgrahamc: can you list which public caches you worked with to attempt to address this? It does not inspire confidence when even google is still showing obvious
by sikhnerd 10y ago
jgrahamc: can you list which public caches you worked with to attempt to address this? It does not inspire confidence when even google is still showing obvious results
- eastdakota 10y agoGoogle, Microsoft Bing, Yahoo, DDG, Baidu, Yandex, and more. The caches other than Google were quick to clear and we've not been able to find active data on them any longer. We have a team that is continuing to search these and other potential caches online and our support team has been briefed to forward any reports immediately to this team. I agree it's troubling that Google is taking so long. We were working with them to coordinate disclosure after their caches were cleared. While I am thankful to the Project Zero team for their informing us of the issue quickly, I'm troubled that they went ahead with disclosure before Google crawl team could complete the refresh of their own cache. We have continued to escalate this within Google to get the crawl team to prioritize the clearing of their caches as that is the highest priority remaining remediation step.
- deleted 10y ago[deleted]
- obituary_latte 10y ago>I'm troubled that they went ahead with disclosure before Google crawl team could complete the refresh of their own cache. It sounded like they (cf) were under a lot of pressure to disclose ASAP from project zero and their 7 day requirement...
- taviso 10y agoMatthew, with all due respect, you don't know what you're talking about. view-source:http://cc.bingj.com/cache.aspx?q=&d=4857656909960944&w=rj9cgKJZJYOhAbxPoQ4RPcxV_spLZkc2 http://cc.bingj.com/cache.aspx?q=&d=4857656909960944&w=rj9cg... view-source:http://cc.bingj.com/cache.aspx?q=&d=4901023173710126&w=n3mEZSOo0Ye0unl8ctnPq60S3jw6FUOL http://cc.bingj.com/cache.aspx?q=&d=4901023173710126&w=n3mEZ... view-source:http://cc.bingj.com/cache.aspx?q=&d=4558611265887320&w=urwoWdnZYEgZBEywdX8DopbtRj22Loty http://cc.bingj.com/cache.aspx?q=&d=4558611265887320&w=urwoW... view-source:http://cc.bingj.com/cache.aspx?q=&d=4592983872701813&w=GhwddjoJYL0opajOudQpo4_EcD1Bb1tS http://cc.bingj.com/cache.aspx?q=&d=4592983872701813&w=Ghwdd... view-source:http://cc.bingj.com/cache.aspx?q=&d=4997243316273666&w=wdpFHreZbW_ge4UnFi51WMykOFS0jzqW http://cc.bingj.com/cache.aspx?q=&d=4997243316273666&w=wdpFH... Not as simple as you thought?
- acqq 10y agoExactly, it looks that the cleaning people up to now only looked for the most obvious matches (just searching for the Cloudflare unique strings). There's surely more where "only" the user data are leaked and are still in the caches.
- sidcool 10y agoCan anyone provide some context please ?
- Gigablah 10y agoFor anyone being linked directly to the post: the link back to the parent page is right on top: https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752 You can also click on "parent", and repeat as necessary.
- asdfaoeu 10y agoThe bottom of the file has contents from another connection. Notably HTTP/1.1 Host gateway.discord.gg
- myth_buster 10y agoGreat(x3) parent https://news.ycombinator.com/item?id=13718752 https://news.ycombinator.com/item?id=13718752
- __jal 10y agoI find it troubling that the CEO of Cloudflare would attempt to deflect their culpability for a bug this serious onto Google for not cleaning up Cloudflare's mess fast enough. Don't use CF, and after seeing behavior like this, don't think I will.
- Gigablah 10y agoWell, the CEO does have beef with Google: https://blog.cloudflare.com/post-mortem-todays-attack-apparent-google-app/ https://blog.cloudflare.com/post-mortem-todays-attack-appare... This led to Cloudflare refusing to implement support for Google Authenticator for 4 years.
- artursapek 10y agolol, really? Google authenticator is just TOTP - it's an open standard. That seems childish. Also, the notion that the CEO of an internet company would have a "beef with Google" is pretty funny.
- fishywang 10y agoOn a personal note, I agree with you. Before Let's Encrypt is available to public use (beta), CF provided "MITM" https for everyone: just use CF and they can issue you a certificate and server https for you. So I tried that with my personal website. But then I found out that they replace a lot of my HTML, resulting mixed content on the https version they served. This is the support ticket I filed with them: On wang.yuxuan.org, the css file is served as: <link rel="stylesheet" title="Default" href="inc/style.css" type="text/css" /> Via cloudflare, it becomes: <link rel="stylesheet" title="Default" href="http://wang.yuxuan.org/inc/A.style.css.pagespeed.cf.5Dzr782jVo.css" type="text/css"/> This won't work with your free https, as it's mixed content. Please change it from http:// to //. Thanks. There should be more similar cases. But CF just refuse to fix that. Their official answer was I should hardcode https. That's bad because I only have https with them, it will break as soon as I leave them (I guess that makes sense to them). Luckily I have Let's Encrypt now and no longer need them.
- paulcole 10y agoAt least tell me they got their t-shirts lol.
- yarou 10y agoThey're fresh out of those, especially if you're female.
- glass_of_water 10y ago> I agree it's troubling that Google is taking so long. Google has absolutely no obligation to clean up after your mess. You should be grateful for any help they and other search engines give you.
- swsieber 10y agoYou're right, I guess. (Disclaimer: Not affiliated with any company affected / involved) But I still find it troubling. Is it their mess? No. Does it affect a lot of people negatively - yes. I expect Google to clean this up because they're decent human beings. It's troubling because it's not just CloudFare's mess at this point. It reminds me of the humorous response to "Am I my brother's keeper?", which is "You're your brother's brother"
- cortesoft 10y agoGoogle cleaning this up is going to take a ton of man-hours, which will cost a LOT of money. How much money is Google obligated to spend to help a competitor who fucked up? Are they supposed to just drop everything else and make this the top priority?
- swsieber 10y agoI don't see this as them as helping a competitor. The damage has been done (in terms of customer relations). I view leaving up the cached copy of leaked data as being a jerk move - not towards CloudFare, but to anyone whose data was leaked. This is an opportunity for Google to show what they do with rather sensitive data leaks - do they leave them up or scrub them? Had damage from the leak been aleady done (to those whose data it was)? Probably. Even taking that into account, I think the Google search comes off as a jerk in this situation.
- cortesoft 10y agoI feel like you are operating under the assumption that deleting this leaked data is trivial, that they just have to hit a delete button and the data is gone. This is not the case; it is not obvious, trivial, or easy to delete the leaked data. It is not simple to find it all. This is not like they are being given a URL and being asked to clear the cached version of it; they are being asked to search through millions of pages for possibly leaked content.
- deleted 10y ago[deleted]
- winteriscoming 10y ago>> We have continued to escalate this within Google to get the crawl team to prioritize the clearing of their caches as that is the highest priority remaining remediation step. If you are using the same attitude as you use in this comment, with their team, i'm pretty sure they will be thrilled to keep aside all their regular work and help you out cleaning up a enormous mess created by a bug in your service.
- hbbio 10y agoNext time, beware of parsers. Or formally verify them :) https://arxiv.org/pdf/1105.2576.pdf https://arxiv.org/pdf/1105.2576.pdf (disclaimer: co-author)
- Lazare 10y agoThis comment greatly lowers my respect for Cloudflare. Bugs happen to us all; how you deal with this is what counts, and wilful, blatant lying in a transparent attempt to deflect blame from where it belongs (Cloudflare) onto the team that saved your bacon? I've recommended Cloudflare in the past, and I was planning, with some reservations, to continue to do so even after disclosure of this issue. But seeing this comment? I don't see how I can continue. (For the sake of maximum clarity: I take issue: 1) with the attempt at suggesting the main issue is in clearing caches, not on the leak itself. It doesn't matter how fast you close the barn door after the horse is gone and the barn has burned down. 2) With the blatantly false claim that non-Google caches have been cleared, or were faster to clear than Google's. Cloudflare should know, better than anyone, the massive scope of this leak, and the fact that NO search engine's cache has or could be cleared of this leak. If you find yourself in a situation so bad you feel like you need to misdirect attention to someone else, and it turns out no one else is actually doing anything so you have to like about that...maybe you should just shut up and stop digging?)
- jessaustin 10y agoHey! Don't keep the horse locked in if the barn is burning!
- kentt 10y agoFor this who haven't been following along, this is the CEO of CloudFlare lying in a way that misrepresents a major problem CloudFlare created. Additionally, they are trying to blame parts of this problem on those that told them about the problem they created.
- kentt 10y agoI despise the way you've dealt with this issue with as much dishonesty as you thought you could get away with. I will be migrating away from your service first thing Monday. I will not use you services again and will ensure that my clients and colleagues are informed of you horrific business practices now and in the future.
- easuter 10y agoOh wow, taking a shit on Google after they helped you by reporting a critical flaw in your infrastructure. I'm no longer using CF for my own projects, but you've just cemented my decision that none of my clients will either.