1,098 karma · joined May 6, 2008
jake (at) jarv.is
[ my public key: https://keybase.io/jakejarvis; my proof: https://keybase.io/jakejarvis/sigs/VssoQRISbhOAElwEbfmqpseJJlReccc3cjwhhBS1k_s ]
openpgp4fpr:3BC6E5776BF379D36F6714802B0C9CF251E69A39
https://9to5mac.com/2021/08/25/analysts-google-to-pay-apple-...
> As a reminder from the Support Team, cycling your secrets is something that all users should do on a regular basis per your company’s security process. If you are unsure how to do this please contact Support and we would be happy to help you.
...and that's it. That's the full "bulletin."
Highly recommend trying it. I'm seeing the vast majority of visits now are not hitting the origin server at all — for assets or the page itself. At least it's a good stopgap until we can convince everyone to move 100% static...one can dream, right?
[0] https://blog.cloudflare.com/automatic-platform-optimizations...
This part never made any sense to me. Such an easy fix to make.
Also, the post states this is done completely on-device and links to a page with significant details on this: https://support.google.com/phoneapp/answer/10104618
> We are down in Florida. It’s a hot mess in the ER today. EMS diversion on cardiac patients because the cath lab is down.
> I work at an inpatient psych site in Philly PA. The nurses told me they asked the patients what they take for morning meds and then didn’t even distribute evening meds bc they have no record of their medications.
> We have no access to anything computer based including old labs, ekg's, or radiology studies. We have no access to our PACS radiology system. No patients died tonight in our ED but I can surely see how this could happen in large centers due to delay in patient care.
https://www.reddit.com/r/hacking/comments/j17aj1/cyberattack...
1. Check for <link rel="icon" ...> tag(s)
2. Check for /favicon.ico
3. ...give up?
Someone correct me if I'm wrong!
> 1. Once traffic is ensured to flow though Cloudflare, we initiate decommission of Route53.
> We would disable the transfer lock and generate an auth code.
> immediately after, we move the domain over to the Cloudflare registry
I love the overall plan but this part would worry me... The most obvious contingency plan when you're putting so many eggs into one basket is to keep a kill-switch somewhere like your domain registrar, where you can abandon ship entirely by switching nameservers in the worst of scenarios, right?
Correct me if I'm wrong but when the Cloudflare dashboard went down a few weeks (months?) ago, no sort of DNS-level changes would have been possible. (Either way, I don't think you can even set external nameservers for domains on Cloudflare Registrar yet?)
Just curious about the thinking behind this particular move and why the pros outweigh the cons of leaving the domain where it is.
So, if I want convenient nightly backups (without plugging my phone in and using the "new" Catalina apps, which I'm still convinced are just new iTunes skins), Apple — and adversaries — will still have unfettered access to all my iMessages, Maps history, photos, health records, almost everything listed here and more [0][1].
Tim Cook has claimed a fix is coming for a while now [2], but meanwhile using iCloud for its intended purpose is a huge, and largely unadvertised, gaping hole in Apple's otherwise impressive privacy promises. :(
[0] https://www.theverge.com/2016/3/2/11144588/walt-mossberg-app...
[1] https://www.cellebrite.com/en/productupdates/move-your-inves...
[2] https://www.macrumors.com/2019/02/28/eff-user-encrypted-iclo...
0 = never send the header
1 = send the header only when clicking on links and similar elements
2 = (default) send on all requests (e.g. images, links, etc.)
If you want more granular control (like sending referrers but only the root of the domain) all of the various network.http.referer flags for Firefox are listed here:https://wiki.mozilla.org/Security/Referrer
Doesn't have a few of the features that your extension has, but it's done the trick for me!
If anyone's interested, I wrote a guide a while ago on adding these headers via Cloudflare Workers, which can be helpful if you're hosting a static site on S3, GitHub Pages, etc. where you can't add these headers directly:
The mechanics behind the v2 API (using k-anonymity with hashes [1]) are pretty interesting too. Troy has clearly put a lot of thought and time into what started as a pet project a few years ago and should be infinitely commended!
[0] https://blog.1password.com/finding-pwned-passwords-with-1pas...
[1] https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
A personal spy cam in a rental home is bad enough, but the fact that there are so many open to the world (and therefore indexed on Shodan) makes it infinitely worse.
My main fright during this outage wasn't really the outage itself, but the fact that I couldn't log into the dashboard and simply click the orange cloud to bypass Cloudflare in the meantime. I'm assuming that this is now covered by this mitigation:
>> 6. Putting in place an emergency ability to take the Cloudflare Dashboard and API off Cloudflare's edge.
If so, and if this would have prevented the dashboard outage even during the WAF fiasco, this is a huge comfort to me. Just curious, though: how far can you really go in separating Cloudflare "the interface" from Cloudflare "the network?"
And in general, what does everyone on HN think about mission-critical companies using their own infrastructure and being their own customer? Especially when the alternative is using a competitor?
I'm certainly not defending this trend and I think it's incredibly unhealthy — especially for the average teenager who's already naturally self-conscious about their appearances. But a minor eye correction will be peanuts in the eyes of this crowd (no pun intended) compared to the amount of processing that most of their Instagram and Snapchat photos go through before being uploaded.
[0] https://www.theguardian.com/media/2018/mar/09/facetune-photo...
[1] https://abcnews.go.com/GMA/Living/photo-retouching-apps-affe...
Out of ~20,000 students and ~10,000 staff, they only needed to get lucky once, unfortunately.