• Member Since 11th Jan, 2012
  • offline last seen 11 minutes ago

Wild Zontars


More Blog Posts10

Feb
24th
2017

Change (almost) ALL of your passwords, not just FiMfic! · 10:02pm Feb 24th, 2017

PSA: You probably need to change a lot of your passwords NOW.

Check here to see if any site you're worried about uses Cloudflare. If it does, your password and other personal information may have been leaked.

This is very, very bad:

Oh, my god.

Read the whole event log.

If you were behind Cloudflare and it was proxying sensitive data (the contents of HTTP POSTs, &c), they've potentially been spraying it into caches all across the Internet; it was so bad that Tavis found it by accident just looking through Google search results.

The crazy thing here is that the Project Zero people were joking last night about a disclosure that was going to keep everyone at work late today. And, this morning, Google announced the SHA-1 collision, which everyone (including the insiders who leaked that the SHA-1 collision was coming) thought was the big announcement.

Nope. A SHA-1 collision, it turns out, is the minor security news of the day.

This is approximately as bad as it ever gets. A significant number of companies probably need to compose customer notifications; it's, at this point, very difficult to rule out unauthorized disclosure of anything that traversed Cloudflare.

Report Wild Zontars · 368 views ·
Comments ( 0 )
Login or register to comment