4 ms·
How CloudFlare got patched last week and AWS not?
by _mikz 13y ago
How CloudFlare got patched last week and AWS not?
- tszming 13y agoI am also interested to know why CloudFlare is ahead of those major Linux distributions on this.
- hrrsn 13y agoSimple. Someone alerted them ahead of time since they terminate a lot of SSL connections. Testing with distros is a lot harder.
- deleted 13y ago[deleted]
- jgrahamc 13y agoAre you asking why CloudFlare published their (our) blog post when we did? We did because the OpenSSL project had issued their advisory on the vulnerability already. I personally observed the OpenSSL disclosure on this on the New page of Hacker News prior to our blog post being made live (and prior to submitting it to HN). You can also verify this yourself by following the New page backwards.
- Igalze 13y agoI think that the question was, how come CF knew about this while other providers did not? I would assume that AWS would be on the short list...
- deleted 13y ago[deleted]
- acdha 13y agoGiven that the OpenSSL team has slacked massively on setting up an advanced notification list, would you consider notifying distributions privately the next time you received word of something of this magnitude?
- justincormack 13y agoNot if they agreed not to disclose it, there is a lot of trust involved here.
- acdha 13y agoTrue, although if nothing a discrete “You want full staffing ready for something bad next week” would have been polite. The bigger question, though, is how much trust you can have with the kind of people who would zero-day most of the internet for a marketing exercise. Discrete notifications would have closed the vulnerability window for a lot of people (think e.g. stealthy AWS, Rackspace, etc. upgrades) and it's not clear to me that Codenomicon is likely to produce future tips of such value as to outweigh that.
- Igalze 13y agoThis comment is better than 99% of the media coverage I've seen so far. Who announces a crucial SSL vulnerability that affects Twitter, AWS, Steam, Yahoo and Dropbox without notifying them first? They are making a name for themselves by exposing private information of millions of internet users. Also, I find it interesting that the vulnerability was discovered by Google's researcher and some of their main competitors weren't notified about it.
- tszming 13y agoCloudFlare will not terminate SSL for free users - only for the paid plans. I will be also surprised if they really terminate more SSL connections than AWS ELB & CloudFront. I am not saying CloudFlare did anything wrong - they are doing great this time. I am wondering if other parties like AWS received the disclosure at the same time, what they are waiting? CloudFlare fixed the issue last week, not yesterday.