Is this why old images were wiped from Sup Forums recently?
Angel Anderson
It's good I don't login here
Eli Ramirez
Ironically, your data is safe if the only sites you use are Google, Facebook, Amazon, etc which have their own CDNs.
Realistically, what percentage of the human population uses at least one service "protected" by CloudFlare? I'd think it'd be safe to say at least 50%.
Leo Nelson
ha
Nolan Green
...
Angel Sullivan
...
Angel Cooper
Uber uses Cloudflare servers behind the scenes, even if you access it through the app. Lots of companies do this.
1Password also uses Cloudflare.
Bentley Wood
Based tavis
William Kelly
OK? Neither of those are companies I mentioned, nor anywhere near their size.
Adrian Butler
From what I understand, if the post submissions go through a cloudflare server it could have been leaking the associated IP addresses.
Easton Clark
they're doing MITM on every site they host. WHAT COULD GO WRONG!?!?
PS: Even Sup Forums is using that fucking garbage and they're endangering everyone who purchases passes. HIRO, ditch that shit please!
Brandon Thomas
Cloudflare was hacked once solely to vandalize Sup Forums.
Zachary Torres
this.
If people are going to use this shit, they should at least send encrypted blobs since TLS isn't going to save you here.
Jason Foster
Those niggers also block Tor
Jayden Jenkins
This is why I don't use Cloudflare.
Joshua Anderson
So you knew the bug existed? Could have reported it then.
Joseph Sanchez
Good. Fuck Cloudflare.
Have you ever tried to work with them to identify and stop a spammer or a scam site? They are fucking assholes. I hope something big happens with this security breach, big enough to ruin their entire fucking company and close their doors.
Landon James
No, thanks. I don't want to deal with that circus. Protip: Don't use AES.
Tyler Wilson
So what popular sites use cloudflare? Outside of uber and fitbit.
Joshua Russell
>1Password Feels good for not falling for the cloud password storage meme.
Jace James
so you're mad at them for not handing over customers private info to any retard that asks?
i use cloudflare, it saves a lot of money on bandwidth and makes your ss much faster by hosting them on cdns all over the world for free
>b but it had a bug so did every other piece of software ever made..
Adrian Diaz
>a Cloudflare-hosted site like what
Julian Martinez
They're more common than you might realize. I almost always browse via Tor, and I run into their bullshit all the time. I don't remember on what specific sites though.
Dylan Turner
cloudfag please go
Ryan Bell
> Good you realize that all your Sup Forums posts are potentially sitting around the internet now with your IP address attached right
Gabriel Garcia
I posted this a few days ago. Had a feeling it would be bad, didn't think it would be this bad ><
Based fucking Tavis
Henry Nguyen
>NOTE: Sup Forums USES CLOUDFLARE. Sup Forums is the least relevant site that uses NSACloud, literally almost all of the rest of the internet uses it Time to change all my passwords, again >purchasing passes TOPFUCKINGKEK Anyways, jewt implemented the CDN in his retardation They will never close their doors, they're a NSA asset Literally everything that isn't Facebook, Google and Amazon, with a few exceptions of people who use other CDN's Yeah I remember this Unfortunately Cloudflare is an NSA asset so he won't get the publicity he deserves
Joseph Lopez
you now realise the ddos attacks and the new tech to end it all.
problem reaction solution
nsa way
Caleb Walker
fuck you cloud!
Noah Butler
>so you're mad at them for not handing over customers private info to any retard that asks? They don't and over PUBLIC CONTACT INFORMATION when provided with HARD EVIDENCE.
Fuck them.
>i use cloudflare, it saves a lot of money on bandwidth and makes your ss much faster by hosting them on cdns all over the world for free Hope your customer data is retrieved from caches and you get fucked over for using a shit service.
Connor Garcia
official logo!
Dylan Gonzalez
Passwords should be hashed though if your website is not shit.
Luis Peterson
Are you fucking retarded? This leaked data comes from the web server, before any kind of hashing can be applied.
William Perez
this is leaking POST requests dude
Anthony Price
I thought data gets encrypted with HTTPS before it travels over the internet. So Cloudflare being a man in the middle should just be transporting garbage to their client who decrypts it with their private key.
Leo Carter
I don't know nothing about this crap, but I would have assumed that common practice would be to hash passwords locally before even sending them over the internet.
Hudson Lewis
cloudflare MITM all their clients, that's literally how their service works
Nicholas Sullivan
more like everything
"I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything."
Luke Turner
Cloudflare decrypts stuff, check any site that uses cloudflare and you will find that the certificate is issued to them They (((need))) your SSL certificate to work, they're a massive NSA op It is what should be done but there's a shitton of sites run by literal retards who will send plaintext passwords Even a lot of banking sites are like this
Jason Diaz
That would defeat the point of hashing at all, you would instead leak the hash and use that as a password (pass the hash)
Anthony Carter
WHAT THE FUCK
Samuel Cruz
Is there a list of websites that use Cloudflare that isn't hidden behind some sort of registration screen?
Christopher Jackson
No you're dumb. The cert is issued to cloudflare, they decrypt your data. If you don't know how to check certs, stop posting.
Anthony Parker
Who cares, senpai. We have archives
Julian Parker
Shouldn't passwords be hashed client-side before they're transported over the internet so "password" becomes "UxFMf1Nz9H5ggjTyiQB1"? Then if the website gets hacked they only found your username associated with "UxFMf1Nz9H5ggjTyiQB1" and don't know the password you use for every other login on the internet.
Liam Jackson
It would at least protect you across websites.
Landon Howard
What should be done is sending everything through HTTPS, but in this case it doesn't prevent the password from leaking due to the way Cloudflare works.
Jason Taylor
Some call me the meme master.
Christopher Smith
No, I think that was because Hiro was being dumb as per usual.
Lucas Allen
No, because then an attacker can grab that "UxFMf1Nz9H5ggjTyiQB1" and send that to the server instead, that hash becomes your new password. Passwords need to be sent as plaintext over HTTPS and hashed (using a proper algorithm) after being received by the server.
Jaxson Richardson
Can I bypass Cuckflare and access Sup Forums directly?
Jordan Walker
Time to stop using the internet and burn all my technology.
>The greatest period of impact was from February 13 and February 18 with around 1 in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (that’s about 0.00003% of requests).
I can't even match 1 number on a Powerball ticket. I like my odds.
Zachary Watson
>Any passwords you have EVER sent to a Cloudflare-hosted site might show up in some other random page somewhere on the internet. >NOTE: Sup Forums USES CLOUDFLARE. I dont normally use a password on Sup Forums. I usually use the name Anonymous.
Carson Wright
they don't tell you what their rate of http requests a day is because it would indicate a much larger leak of data
Brody Rodriguez
I can't find one. I'm checking my sites by doing traceroute.
Brayden Peterson
If there is a data dump they could be post you made linking your IP to post about lolis.
Adam Cook
I dont like loli's Idgaf.
Blake Gonzalez
So is there a complete list of sites affected?
Brandon Gutierrez
>full messages from a well-known chat service Discord fags btfo.
Hudson Cox
We are not yet at 50 percent for human internet access.
Camden Watson
> Some of this data was cached publicly in search engines such as Google If big brother is not watching you fap at least you can trust he is recording everything for a later private viewing.
Lucas Adams
So have they fixed this issue as of now? Is it time to change all our passwords and shit?
Joseph Long
>I don't know nothing about this crap Basically Sup Forums summed up in one statement minus the double negative.
It's fixed, but the damage is fucking done, and its big time.
Daniel Reyes
>Cloudflare has over 2 million websites on its network, and data from any of these is potentially exposed. Yeah just assume everything is compromised and change all passwords.
Michael Jackson
How do I tell if a site uses cloudflare?
Lucas Sanders
>The underlying bug occurs because of a C pointer error. No shit. Seriously C should be banned. There is not a single human being that can write safe code with it.
Jacob Gutierrez
technically this was a thing that was compiling some other language to C, not a human being
Ryder Diaz
Well fuck me. Guess all I can do is change my passwords and emails and hope for the best.
Jose Wright
>batoto >myanimelist >exhentai Do any of these us it?
Asher Kelly
The point stands. No human being nor AI nor compiler can write safe C code. If it is in C assume there are multiple exploitable bugs.
James Young
>Sup Forums uses Cloudflare Passfags btfo, I hope they stored CC data too.
It was a service called swipe or something that pops up.
Chase Robinson
Interesting. Besides the ip details is there a way to extract more information out of this? I'd like to see how exposed it is. Captcha: pepe impacto
Anthony Brooks
it's already been fixed & my site doesn't have any sensitive information. it's just a porn site
Ryder Rogers
Fuck cloudflare. NSA operation.
DDoS sites until they join you, then spy on all their HTTPS traffic because they hand their cert over to you.
Gavin Torres
How many bitcoin sites were just drained because you can google cache search and grab passwords. Search for "CF-Host-Origin-IP" and "authorization" in jewggle, receive a shitload of passwords.
Jewggle is going to have nuke their entire cache
Fucking NSAflare. For years they were called out by cryptographers and 'security industry' for how they handled 0day by making a marketing site about it and just dumping the information after warning only their biggest customers.
Colton Powell
Forgive my ignorance, but where would that data appear? Like, in the html source of the page? Where would one look to find those leaks?
Isaiah Sanchez
Access, or reliable/consistent access? I thought even third-worlders had access via cafes. Isn't WhatsApp super popular in Africa?
Camden Perry
>The accident corrurs because of a car. No shit. Seriously cars should be banned. There is not a single human being that can drive safely.
Mason Rivera
Search engine caches (which they explicitly mention are already mostly purged), Archive.org, maybe proxies that aggressively cache?
Xavier Miller
No, I meant, assuming someone gave me one of those pages that received the leaks, where would the leaked data be in that page?
Austin Bailey
It's transmitted in the body of the response to the client, so, yes, in the HTML source
Parker Cox
They've barely purged it, there's cross cache contamination going on everywhere with leaked OAuth tokens galore for the taking still.
The #1 problem is of course Baidu with their Chinese government overseers likely fully raping the cache, plus the NSA runs it's own http cache as per Snowden leaks since years ago. Almost everything on the internet caches http so this leak is huge.
This bug was caused by parsing. Parsing html in C or using regex is the stupidest thing you can ever do in Cloudflare's official writeup is also missing plenty of details, they are blaming all of this on some ancient parser generating a pointer error but fail to mention they used fucking malloc and didn't zero unit memory, so that memory was full of data still and leaked, actually sprayed all over the internet in every single cache.
People who run major caches: - all universities - all Fortune 500 companies - NSA/GCHQ ect - Jewggle, FB, MS, Baidu, duckduckgo, about a thousand other search engines
This will be fully cleaned up in about 2 years from now probably. On the project0 blog they found entire chats, adult video frames and even financial transactions.
Also, Discord was the biggest leak for some reason Discord logins and chats have been sprayed everywhere in cache history.
Apparently even if they zero'd after free like GrSecurity/Pax-Sanitize works this bug would still happen sincein addition to bad C programming practices, a pointer error was barfing out random arrays.
Ryan Young
that list is not yet complete, still stuff being added.
most of the internet used cloudflare because they are NSA partners and helpfully offered a free tier DDoS protection (likely after ddosing you)
John Ortiz
The list is full of garbage sites
Jose King
I only get one page of results, and most of those don't have cached copies available. I think Google is disabling their cached copies for any page that seems to have this vulnerability. I tried Bing and got the same result.
Juan Lee
>online password manager data Does this mean the pasword manager used cloudflare?