Show HN: Does it use Cloudflare?
doesitusecloudflare.com
doesitusecloudflare.com
For ex. It says uber.com is not vulnerable - because the homepage isn't, while the app is consitantly one of the most impacted in the caches I've seen
I don't think anyone has really nailed the methodology here - and I think that is important (as is erring towards false positives rather than false negatives) for security mitigation advice
These lists are bad, because they list any Cloudflare clients that can be found, not just the ones that might have had exposed data.
dig website.com +short | head -n1 | xargs -- whois | grep -q cloudflare
dig website.com +short | grep -q cloudflareOf course, mine isn't exactly performant, was the result of about 15 minutes of work, and just uses that Github repo with the list of affected domains (so, not exactly the most comprehensive). But hey, it was fun to build.
But the parent comment is untrue. Cloudflare will have unencrypted data in memory at some point, even if it's encrypted coming and going. This is how they eliminate the scary browser message about self-signed certificates, ironically.
[1]https://thenextweb.com/insider/2014/09/08/reddit-launches-fu...
https://www.reddit.com/r/programming/comments/5vtv16/cloudfl...