3 ms·
Another Cloudflare customer also said basically this is much ado about nothing, but prefaced their comment by saying "We take security seriously". Whats offens
by robalfonso 10y ago
Another Cloudflare customer also said basically this is much ado about nothing, but prefaced their comment by saying "We take security seriously".
Whats offensive here is if you take security seriously, then if there is a .01% chance of a disclosure - you tell people to change thier passwords,tokens,etc. That is taking security seriously.
- 794CD01 10y agoWould you say the same at .001%? How about .0001%? It is possible for someone to take security seriously but not blindly value the tiniest bit of security over every other possible factor. Perhaps because they also take usability seriously.
- Cshelton 10y agoIf your password for Cupcakely (made up) was leaked..and it was 0.01% chance....well who cares. Someone might order some cupcakes on my account. If it is say a financial company and the leak of data from your account alone could have massive repercussions on your company and/or investigations by the SEC and others...then yeah...if there is a 0.000001% chance someone out there has your login info, you change that right away. Or be found to be negligent and not change them, see how fast you wind up without a job/in court/fined/jailed. Just. Change. Your. Password.
- robalfonso 10y agoYou have to evaluate the type of account disclosure that was possible against your own use cases. My company bills 1m a day through our online site, if my logins to our domain registrar were exposed then yes. .00001 is worth it, in the case someone would gain access and change our dns or do something else nefarious. Like wise if my login to this site was disclosed, I can live with cleaning that up should it get out. What shouldn't happen is the companies who were affected or the company who caused this (cloudflare) to say "no big deal" At the very least they should say if you potentially used a serious service during this time and that service was using cloudflare then you might consider changing for reasons X,Y,Z.
- 794CD01 10y ago>You have to evaluate the type of account disclosure that was possible against your own use cases. Exactly. Evaluating risk levels and weighing tradeoffs accurately is taking security seriously. Overreacting to insanely unlikely scenarios is not.
- robalfonso 10y agoYes, but you might not understand me. I meant they are assuming they are doing the evaluating on behalf of their customers. I'm the customer and I've got to do the evaluating , but I might not understand the potential but telling me there is almost no issue doesn't help me do that.
- 794CD01 10y agoIf they understand security better than their customers, it's correct for them to say so when an issue doesn't require customers to individually review whether they are affected. If they misjudge that, it isn't an indication that they don't "take security seriously". It just means they made an error in judgment.