26 ms·
I would be pretty mad if a website that I was supposed to trust with my data made an untrue statement about how something was taken care of, when it was not, an
by slipmagic 10y ago
I would be pretty mad if a website that I was supposed to trust with my data made an untrue statement about how something was taken care of, when it was not, and then publish details of the bug while cache it still out in the wild, and now exploitable by any hacker who was living under a rock during the past few months.
- nodesocket 10y agoActually I proxy two of my profitable startup frontend sites with CloudFlare, so I am affected (not really), but giving them the benefit of the doubt as they run a great service and these things happen.
- phaed 10y agoThey are well past deserving the benefit of the doubt. I would also advise you notify your cloud-based services' customers how they might be affected (yes really), trust erosion tends to be contagious.
- josephb 10y agoAgreed. The condescending downplaying tones displayed just aren't acceptable.
- nodesocket 10y agoWe only host our static corporate sites (not apps) and furthermore never used CF email obfuscation, server-side excludes or automatic https rewrites thus not vulnerable.
- potatosareok 10y agoHi, I think you have misunderstood the issue. Just because YOU did not use those services does not mean your data was not leaked. It means that other peoples data was not leaked on YOUR site, but YOUR data could be leaked on other sites that were using these services.
- nodesocket 10y agoThanks for clarifying. You are absolutely right.
- sillysaurus3 10y agoWe only host our static corporate sites (not apps) If this part is true, they're not vulnerable. Only data that was sent to CloudFlare's nginx proxy could have leaked, so if they only proxy their static content, then that's the only content that would leak. The rest of their comment gives the wrong impression though, yeah.
- acqq 10y ago> Only data that was sent to CloudFlare's nginx proxy could have leaked, so if they only proxy their static content, then that's the only content that would leak. The way it worked, the bug also leaked data sent by the visitors of the these "static sites": IP addresses, cookies, visited pages etc.
- deleted 10y ago[deleted]
- tptacek 10y agoSo far as I know, nothing like this thing has ever happened at any CDN ever before.
- rdl 10y agoThere have definitely been incidents where CDNs mixed up content (of the same type) between customers. Not exactly like this, but close.