>Between 2016-09-22 - 2017-02-18 encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests, and other sensitive data were leaked by Cloudflare to random requesters
>Cloudflare's network has the highest number of connections to Internet exchange points of any network worldwide
>ALL CloudFlare proxy customers have been vulnerable to having data leaked
>If you were behind Cloudflare and it was proxying sensitive data (the contents of HTTP POSTs, &c), they've potentially been spraying it into caches all across the Internet; it was so bad that Tavis found it by accident just looking through Google search results.
>This is approximately as bad as it ever gets. A significant number of companies probably need to compose customer notifications; it's, at this point, very difficult to rule out unauthorized disclosure of anything that traversed Cloudflare.
>In case you're wondering how this could be worse than Heartbleed: Yes, apparently the allocation patterns inside Cloudflare mean TLS keys aren't exposed to this vulnerability. But Heartbleed happened at the TLS layer. To get secrets from Heartbleed, you had to make a particular TLS request that nobody normally makes.
>Cloudbleed is a bug in Cloudflare's HTML parser, and the secrets it discloses are mixed in with, apparently, HTTP response data. The modern web is designed to cache HTTP responses aggressively, so whatever secrets Cloudflare revealed could be saved in random caches indefinitely.
- Y Combinator
Aaron Carter
So much data, how are they even gonna dig through it and sort shit from not shit
>multiple porn sites Someone needs to call the bank and block that credit card.
Aayyy
Jeremiah Rodriguez
I told you about cloudflare bro
Benjamin Bennett
What's worse having all your Sup Forums posts exposed our your entire porn history?
Benjamin Gutierrez
That's what you get for using a SSL botnet
Christian Long
Lel who cares.
It's so big the posts are like drops in an ocean.
Someone has to go through all the data and "expose" people but they won't it's just a credit card data mining operation
Most of these sites have transactions on them with names and data, that's what they are after.
Manneeyy. Nobody cares you called someone a faggot on february 19th 2017 at 17:46 pm
The same way nobody cares about your porn habits , you probably have bad taste
Be reasonable
Brandon Peterson
The CIA did this to destroy Sup Forums, they're scared of our power.
Zachary Rodriguez
So I'm not familiar with how Cloudflare works but I thought it was like a proxy server of sorts routing traffic from the clients to web server thus protecting the web server from DDoS attacks and large amounts of traffic.
If this is right how would encrypted passwords and information be in danger, the cloudflare servers don't decrypt the information right?
Jason Perez
I think it also saves caches of said websites, whether that is decrypted or not I don't know.
Kevin Adams
gg
Benjamin Harris
Wow
Austin Bennett
Old
Jace Phillips
uuuhh guys
Brandon Bennett
Yeah but how does the leaked data connect, say, a Sup Forums post to a particular person's name?
it's just an IP address right? There won't be searchable database that can single out shitposters as far as I can tell.
Luis Phillips
I was on freenode through SSL on my home server shell when this happened, am I fucked?
Isaiah Cruz
>every cloudflare-connected site leaking client data like IP
>link IP and other client data to every other kind of cloudflare-connected site
a possible doxing of every single Sup Forums user cannot be ruled out
Daniel Cruz
>ISP's dhcp keeps log of who had what ip when >??? >PROFIT
Dylan Phillips
In cases it is entire HTTP requests, which can include enough headers to reasonably uniquely identify you.
Luis Barnes
(you)ing myself
The blog at least has a mention about client SSL certificates not being leaked, wouldn't really trust them before we know more on this though.
Luis Adams
shit nigga gonna start using a password manager because this shit happens way too often lastpass or dashlane?
Joseph White
definitely not lastpass, use keepass
Asher Hughes
>when you try to centralize the internet but don't give a shit at all about the security >then refuse to tell anyone for 5 months you fucked up
top kek. Mega corps will never learn.
Asher Cruz
there was a thread here last weekend that showed the tweet from a google employee wanting to contact cloudflare and everyone was shitting bricks
That would absolutely destroy so many people it's not even funny. that would be relationship and job ending for many thousands if all that was easily accessible to normies.
Jace Thomas
good thing I'm a neet with literally 0 friends get rekt normies
Brody Ward
it would be very funny
Angel Morgan
Hmmm maybe hosting all your content on third party servers wasn't a good idea after all
Jeremiah Reyes
>Sup Forums.org oh shit, gotta change my tripcode :^)
Ryan Moore
Cloudflare to work need the SSL private keys of the sites sitting behind its proxy. So yes, cloudflare decrypt all the SSL traffic going through its servers.
Carter Powell
Cloudflare isn't a server service, it's a proxy
Cooper Ward
>Fakku affected Get fucked Jewcob
Jaxon Price
Does this effect the panda?
Robert Moore
If this can happen, the internet was made stupid.
Anthony Wilson
no, cloudflare was stupid, you stupid fuck
Aiden Robinson
trust no one, not even yourself
Jayden Bell
how does it check if a website uses cloudflare if it doesn't use cloudflare?
Christopher Cruz
why do people use Cloudflare as an entire loadbalancer solution and not as a CDN only?
Aiden James
Who is the asshole that keeps naming bugs?
Ian Hernandez
So the bug has only existed since the end of September 2016? Or is that a guess?
Jordan Taylor
>none of the other sites I go on uses cloudflare so is there anything to even be worried about then? i assume the issue would be if people could cross reference your Sup Forums shitposting with a social media account but it seems like none of them use cloudflare.
Josiah James
...
Jason Taylor
So I don't have to worry about my credit card if I bought my GoyPass™ before September?
Carson Nguyen
all cloudflare-connected sites have been compromised, so every cloudflare-connected site that has handled your cc has eventually leaked your details numerous times
so you should actually be very, very worried
this is probably going to be known as the biggest cybersecurity failure ever
Juan Diaz
Doesn't Patreon handle SSNs?
Anthony Nelson
>Cloudflare to work need the SSL private keys of the sites sitting behind its proxy Bullshit. They decrypt the content they are receiving from your server as any client would and then re-encrypt it using their own cert+key.
Easton Martinez
Who gives a fuck about patreon? Lol
It's funny because like 90 percent of the sites people are crying about being leaked have already been hacked (see: patreon)
btw if you have ever seen a doctor your ssn is likely for sale for under $10.
I assume cached information usually lasts for an hour up to a few days after the request?
What is the timeline of the age of cached information that was leaked along with new requests?
Luke Reed
People like this have fallen so far from reality they try to bring others down with them.
Owen Rodriguez
So, if I were logged into my gmail and was browsing a site that used Cloudflare, it's possible that my email account info was compromised?
Luke Richardson
I know its on the list retard, I just want to know how fucked those furry porn artists are
Jackson Sanchez
If nothing you use (or have used in the past 6 months) used Cloudflare, then you're probably ok.
Some of the sites I use that use Cloudflare are humblebundle, discord, gab.ai, pokemonshowdown, hackernews, and a few others
Christopher Wilson
They MITM all the traffic going through their servers, that's why they use their own SSL certificate for the sites they proxy.
Jordan Torres
Since they are fur fags they have more sex than anyone on this website, but yeah they are fucked.
Levi Stewart
Same reason web devs do other stupid shit - laziness. I only serve immutable images through CF, because their availability can be shit at times, their websocket proxy is unstable, they can cause clients to retain stale assets and they shit on my ETag scheme. It's configurable and depends on cache headers. Anywhere between a few minutes and forever. Yes, but they don't need your private SSL key (if you have SSL on your server), only the public one.
Chase Edwards
>aliexpress uses cloudflare
welp
I have ordered some questionable things.
James Richardson
Where can I find this checker?
Dominic Hernandez
...
Evan Martin
What's wrong with lastpass?
Ryder Morgan
I use a few of those. So what should I do? Change passwords?
Levi Green
Yes
Aaron Roberts
I've thought about using one for a long time now but my problem is that I want to be able to use my logins on other machines that aren't necessarily mine. How do you deal with this? Do you just store your password safe on USB or somewhere online?
The URL is the one in the picture
Jaxson Rivera
Doesn't seem to work for me
Alexander Carter
>1 in 3.3 million chance that a HTTP request would result in random uninitialised memory being leaked
it's literally nothing unless somebody is willing to sift through the internet for cached data and hoping that you will get some useful sensitive information
Jack Bennett
There's always some russian guy willing to do that.
Alexander Morales
I think maybe it checks to see if it resolves using Cloudflare DNS, although I'm not 100% sure.
Or you know, use a search engine that isn't removing cached information.
Blake Cooper
Why is such a large operation run so incompetently?
Andrew Stewart
/thread/
Joshua Green
for the 1/3.3 million chance to look at some random memory for the 1/whatever chance that it will be sensitive and then what? you get somebody's password? if you want that you can just look up one of those x million pw leaks LMAO
These kind of leaks are same type that push me closer to suicide, if I am unable to sort my information and end up compromising all that I own
Levi Diaz
>>aliexpress uses cloudflare AHHHHHH MY BOOTLEG FIDGET CUBE, JAMMER, RFID CLONER I'm not fussed
Wyatt Wilson
Originally cloudflare required the client to share both public and private SSL keys, Cloudflare keyless SSL or whatever they call it is a new option they offer. I don't use their services and I didn't know that keyless SSL was a thing. Still, even if they don't have the private key of the client they still decrypt and eventually re-encrypt all the the traffic going through their servers.
Hunter James
oh no patreon is affected. now people will know i commissioned porn a few times!
at least my anime figure websites weren't affected
Blake Walker
>tfw Sup Forums uses cloudflare >tfw i can't change my Sup Forums pass password
S H I E T
Colton Ross
I don't think it does actually
Daniel Adams
I hope whoever got them enjoys our anime lewds.
Hunter Lopez
Testing and code reviews "waste" money and time. Unpaid interns are cheap.
Mason Miller
So after changing passwords on affected sites, what else is there to worry about? I've never posted anything crazy on here.
Kayden Morris
Does this affect the rare Pepe market?
Ian Hall
Large operations are run by businessmen, not engineers.
Josiah Price
thanks for the cooldow free shitposting senpai :^)
the best lewds
Carson Cook
>He doesnt keep all his rare pepes buried in the backyard so nobody ever sees them