Cloudflare bug data leak exposed
bbc.co.uk
bbc.co.uk
Huh?
https://webcache.googleusercontent.com/search?q=cache:VlVylT...
That request is scrubbed now, but it contained an Uber driver's lat-long coordinates. I used it to look up where they were driving.
CloudFlare really aren't helping themselves with these statements. The people who decide whether to use CloudFlare are programmers, are programmers generally can't be duped with statistics like "1 in 3.3M requests were leaking data" (translation: 100k requests per day were leaking data[1]) or "There's no evidence anyone used this data maliciously" (translation: we have no idea what is being exploited).
[1] https://news.ycombinator.com/item?id=13719518 and https://news.ycombinator.com/item?id=13722606
http://hghltd.yandex.net/yandbtm?fmode=inject&url=http%3A%2F...
Seconded. For example, here is CloudFlare's Chief Technology Officer regarding their response time:
"[Tavis, the Google engineer who discovered this bug, is] saying he’s frustrated but I’m a little bemused at why he’s frustrated with six days rather than 90" [1].
CloudFlare's CTO shouldn't be running around doing interviews with TechCrunch, let alone expressing bemusement about a fire from his camp.
[1] https://techcrunch.com/2017/02/23/major-cloudflare-bug-leake...
I am confused. The probability of someone seeing it is irrelevant, given that the leak happened already. Is security not supposed to be preemptive? For such an easy measure to take (password changing), saying you don't want to change it seems pretty silly. You can change all of your passwords in 30 minutes tops.
I believe the CTO is also mistaken about the probability anyway. As this is more publicized the likelihood of malicious people exploiting this will only increase. Therefore it's a race between them and the good actors fixing the problem. In the interim, changing your passwords at the very least should be done.
So I have to aim for the clearly impacted ones from this (if named/discoverable) and then have to decide how vulnerable I feel and whether I should go through the extra effort (or not) for every password I conceivably have.
Cloudflare's COO publicly dismissing the danger with a wan smile and a wave of his hand was motivation enough for me.
That, and this ridiculous statement: "Unfortunately, it was the ancient piece of software that contained a latent security problem and that problem only showed up as we were in the process of migrating away from it," he wrote.
My understanding is that they were not "in the process of migrating away from" an "ancient piece of software," but rather that this was something they implemented five months ago and that they had no idea anything was wrong until Google told them what they found.
That sort of behavior does not inspire trust and confidence.
That above is a pretty harsh thing to allege. So here's proof, from his own mouth.
First, he continually berates because "he called and Brian Krebs never responded".. Well, he invited him on stage of a BlackHat conference.
Secondly, the cloudflare CEO states that the booters (ddos pay-as-you-go sites protected by cloudflare) don't even pay, or pay with stolen credit cards. And admits is "just a disaster".
Thridly, a direct insult towards Krebs onstage "Well, who needs to actually ask questions as a journalist?" 48:08 ... No. Just no. Absolutely not.
And if I can find the post, Matthew Prince on here posted this video as a defence against a Tor dispute. Somehow, he thinks it's somehow enlightened and upright. My opinion, I don't believe so at all.
https://www.youtube.com/watch?v=wW5vJyI_HcU
Edit:
Further citation:
https://news.ycombinator.com/item?id=12575047
look for user:eastdakota
page text:"Yes, you can see Brian's critique of us here:"Whether or not he does I hope companies who use CloudFlare strongly consider alternatives. His comment certainly isn't out of ignorance, he has blogged at length on the necessity of password security and lambasted other companies for their behaviour in situations such as this.
Whats offensive here is if you take security seriously, then if there is a .01% chance of a disclosure - you tell people to change thier passwords,tokens,etc. That is taking security seriously.
It is possible for someone to take security seriously but not blindly value the tiniest bit of security over every other possible factor. Perhaps because they also take usability seriously.
If it is say a financial company and the leak of data from your account alone could have massive repercussions on your company and/or investigations by the SEC and others...then yeah...if there is a 0.000001% chance someone out there has your login info, you change that right away. Or be found to be negligent and not change them, see how fast you wind up without a job/in court/fined/jailed. Just. Change. Your. Password.
My company bills 1m a day through our online site, if my logins to our domain registrar were exposed then yes. .00001 is worth it, in the case someone would gain access and change our dns or do something else nefarious.
Like wise if my login to this site was disclosed, I can live with cleaning that up should it get out.
What shouldn't happen is the companies who were affected or the company who caused this (cloudflare) to say "no big deal"
At the very least they should say if you potentially used a serious service during this time and that service was using cloudflare then you might consider changing for reasons X,Y,Z.
Exactly. Evaluating risk levels and weighing tradeoffs accurately is taking security seriously. Overreacting to insanely unlikely scenarios is not.
If they misjudge that, it isn't an indication that they don't "take security seriously". It just means they made an error in judgment.
Really, I don't know the answers, but I'm not leaving because this seems like something that could happen anywhere at anytime. I honestly don't know though.
Yes. A t-shirt contest is a joke of a security bug bounty.
https://hackerone.com/cloudflare (t-shirt)
vs.
https://hackerone.com/coinbase ($500-$10k) or https://hackerone.com/uber ($500-$10k) or https://hackerone.com/facebook ($500-$10k) or dozens of others...
This leads to one of the two conclusions: 1) They are too cocky to think that they may have security problems (which is a big problem) 2) They know they may have security problems but don't care enough (which is a bigger issue).
There is no way you can cut this to make them look good.
It isn't a strawman to state economic incentives matter. Or do you genuinely believe people everyone experienced in security will take the $50 because of "ethics"?
The number of people who lost passwords is low, but it certainly happened to someone and none of us know if we're that someone.
The first guy knew how to take advantage of the information but the second guy could sit and wait for someone else to solve it and take the reward, it also meant the bot programmer wasnt in a competition with everyone to submit the solution first.
Given that there are many bitcoin sites listed with cloudflare there is some potential reward in locating and scanning that data.
It's good to change the passwords every so often anyway - it took me less time to just change my important passwords, than to check if the sites they are for, were using Cloudflare.
Out of context that omits the fact that it was a new feature. Ragel might be old, but they did leverage it, on purpose, for net new functionality. The fix didn't remove Ragel either.
So... just cross your fingers and hope nobody saw anything then? The way they're casually downplaying this incident is outrageous.
Heading :(some alarmist half truth) Content :( what we said in the headline probably isn't true )
"bigly" is a word now? Thanks Trump!