Author Topic: Cloudflare security leak?  (Read 3092 times)

0 Members and 1 Guest are viewing this topic.

Offline Spoon

  • 212
  • ヾ(´︶`♡)ノ
Cloudflare security leak?
Someone on a slack I visit linked this, and I was wondering if HLP could in any shape or form have been affected by this?
https://github.com/pirate/sites-using-cloudflare
Most of this is stuff I won't really pretend to understand, so I figured someone with a bit more knowhow about the subject could say something more meaningful
Urutorahappī!!

[02:42] <@Axem> spoon somethings wrong
[02:42] <@Axem> critically wrong
[02:42] <@Axem> im happy with these missions now
[02:44] <@Axem> well
[02:44] <@Axem> with 2 of them

 
Re: Cloudflare security leak?
What I'm hearing is "change every password you've ever used on a Cloudflare site", which in practice might as well be "change all your passwords on every website that hasn't explicitly been called safe". The severity of this leak is totally unprecedented in the history of network security in terms of the amount of potentially-compromised data. Literally any data that you sent through Cloudflare in the last several months may have ended up publicly displayed on someone's broken Chinese news website.
« Last Edit: February 24, 2017, 07:37:07 am by Phantom Hoover »
The good Christian should beware of mathematicians, and all those who make empty prophecies. The danger already exists that the mathematicians have made a covenant with the devil to darken the spirit and to confine man in the bonds of Hell.

 

Offline Spoon

  • 212
  • ヾ(´︶`♡)ノ
Re: Cloudflare security leak?
hard-light.net is on the list of known domains affected

Reminder that there are inactive admin accounts that could pose a serious security risk here.
Urutorahappī!!

[02:42] <@Axem> spoon somethings wrong
[02:42] <@Axem> critically wrong
[02:42] <@Axem> im happy with these missions now
[02:44] <@Axem> well
[02:44] <@Axem> with 2 of them

 

Offline mjn.mixael

  • Cutscene Master
  • 212
  • Chopped liver
    • Steam
    • Twitter
Re: Cloudflare security leak?


I'm so...tired... of having to change passwords across all sites every few weeks because of this crap. I take the given advice and use different passwords on just about every site.. but a leak like this? **** all that matters.
Cutscene Upgrade Project - Mainhall Remakes - Between the Ashes
Youtube Channel - P3D Model Box
Between the Ashes is looking for committed testers, PM me for details.
Freespace Upgrade Project See what's happening.

 

Offline Spoon

  • 212
  • ヾ(´︶`♡)ノ
Re: Cloudflare security leak?
^Agreed so much^
Urutorahappī!!

[02:42] <@Axem> spoon somethings wrong
[02:42] <@Axem> critically wrong
[02:42] <@Axem> im happy with these missions now
[02:44] <@Axem> well
[02:44] <@Axem> with 2 of them

 
Re: Cloudflare security leak?
^ Triple agreed ^

If that **** is as bad as it looks, it means I gotta change at least 3/4 of my passwords, awesome ...

 

Offline Zacam

  • Magnificent Bastard
  • Administrator
  • 211
  • I go Sledge-O-Matic on Spammers
    • Minecraft
    • Steam
    • Twitter
    • ModDB Feature
Re: Cloudflare security leak?
So, full stop here.

As of at least 3 hours ago, CloudFlare has certified/asserted that HLP as a domain has not been or had its traffic compromised in any way as a result of this vulnerability.

They are continuing with validating and monitoring for if that changes, and if it does, I'll be notified.
Report MediaVP issues, now on the MediaVP Mantis! Read all about it Here!
Talk with the community on Discord
"If you can keep a level head in all this confusion, you just don't understand the situation"

¤[D+¬>

[08/01 16:53:11] <sigtau> EveningTea: I have decided that I am a 32-bit registerkin.  Pronouns are eax, ebx, ecx, edx.
[08/01 16:53:31] <EveningTea> dhauidahh
[08/01 16:53:32] <EveningTea> sak
[08/01 16:53:40] * EveningTea froths at the mouth
[08/01 16:53:40] <sigtau> i broke him, boys

 

Offline chief1983

  • Still lacks a custom title
  • 212
  • ⬇️⬆️⬅️⬅️🅰➡️⬇️
    • Minecraft
    • Skype
    • Steam
    • Twitter
    • Fate of the Galaxy
Re: Cloudflare security leak?
But I hope you guys aren't using the same password here as anywhere else as we aren't using SSL for logins.  Your plaintext pass is already all over the tubes.
Fate of the Galaxy - Now Hiring!  Apply within | Diaspora | SCP Home | Collada Importer for PCS2
Karajorma's 'How to report bugs' | Mantis
#freespace | #scp-swc | #diaspora | #SCP | #hard-light on EsperNet

"You may not sell or otherwise commercially exploit the source or things you created based on the source." -- Excerpt from FSO license, for reference

Nuclear1:  Jesus Christ zack you're a little too hamyurger for HLP right now...
iamzack:  i dont have hamynerge i just want ptatoc hips D:
redsniper:  Platonic hips?!
iamzack:  lays

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Minecraft
    • Steam
    • Something
Re: Cloudflare security leak?
Is it bad that even with news like this I can't really summon the energy to go through and make my personal practices more secure?  Like, it's ridiculous enough even trying to keep track of passwords I've used in multiple places as-is, and my browser's list of saved passwords is long enough to substantially warp local space-time.  It's getting to the point where it doesn't seem humanly possible to keep everything straight, unless I go the dad route and put sticky notes around my monitor.
« Last Edit: February 24, 2017, 06:34:35 pm by Mongoose »

 

Offline jr2

  • The Mail Man
  • 212
  • It's prounounced jayartoo 0x6A7232
    • Steam
Re: Cloudflare security leak?
Is it bad that even with news like this I can't really summon the energy to go through and make my personal practices more secure?  Like, it's ridiculous enough even trying to keep track of passwords I've used in multiple places as-is, and my browser's list of saved passwords is long enough to substantially warp local space-time.  It's getting to the point where it doesn't seem humanly possible to keep everything straight, unless I go the dad route and put sticky notes around my monitor.

Same here.

 

Offline Spoon

  • 212
  • ヾ(´︶`♡)ノ
Re: Cloudflare security leak?
Maybe consider using a password manager in that case?
(I dont use them myself, I've got no recommendations)
Urutorahappī!!

[02:42] <@Axem> spoon somethings wrong
[02:42] <@Axem> critically wrong
[02:42] <@Axem> im happy with these missions now
[02:44] <@Axem> well
[02:44] <@Axem> with 2 of them

 

Offline jr2

  • The Mail Man
  • 212
  • It's prounounced jayartoo 0x6A7232
    • Steam
Re: Cloudflare security leak?
Maybe consider using a password manager in that case?
(I dont use them myself, I've got no recommendations)

I don't either, but: http://www.tomsguide.com/us/best-password-managers,review-3785.html

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Re: Cloudflare security leak?
I use last pass and I haven't ever wanted to go back since I started. It does cost a bit if you want multiple devices though. - Apparently they changed that. So now there's no real excuse not to use a password manager of some sort. 
« Last Edit: February 24, 2017, 10:13:44 pm by karajorma »
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: Cloudflare security leak?
I use last pass and I haven't ever wanted to go back since I started. It does cost a bit if you want multiple devices though.
Not any more.

https://lastpass.com

Quote
Free:
    Access on all devices Now Free
    Save & fill passwords
    Password generator
    Secure notes
    Share passwords & notes
    Security challenge
    Two-factor authentication (2FA)


Premium $1 /month, billed yearly

Premium includes
Everything in Free, plus:

    Shared family folder - up to 5 users
    YubiKey & Sesame 2FA options
    Priority tech support
    LastPass for applications
    Desktop fingerprint identification
    1GB of encrypted file storage
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Minecraft
    • Steam
    • Something
Re: Cloudflare security leak?
Hmm...I've been a bit wary of the concept of password managers in the past, but it might be worth giving it a shot.  Provided the extension plays nice on Pale Moon, anyway.

 

Offline rev_posix

  • Administrator
  • 213
  • I have the password to your shell account...
    • Trials and Tribulations
Re: Cloudflare security leak?
Hmm...I've been a bit wary of the concept of password managers in the past, but it might be worth giving it a shot.  Provided the extension plays nice on Pale Moon, anyway.
Unfortunately it doesn't.

The firefox plugin is an SDK/jetpack extension which isn't supported under the current palemoon build (27.1.1.1).

I've not looked to see if there is a way to get it working yet

EDIT:  From the palemoon forum:

Quote
The latest version of Lastpass (from lastpass.com, not the AMO) works fine if installed with Moon Tester Tool.

You need to download it with wget since hitting the "download" button doesn't actually download it, it tries to install it (which fails because it needs to be installed with Moon Tester Tool)

Code: Select all
 wget https://lastpass.com/lastpassffx/xpi.php -O lpffx.xpi

EDITEDIT:  And it does seem to work when doing it this way.  Moon Tester Tool is it's own add-on from the pale moon project page.
« Last Edit: February 24, 2017, 10:16:06 pm by rev_posix »
--
POSIX is fine, as is Rev or RP

"Although generally it is considered a no no to disagree with a mod since it's pretty much equivalent to kicking an unpaid janitor in the nuts while he's busy cleaning up somebody elses vomit and then telling them how bad they are at cleaning it up cause you can smell it down the hall." - Dennis, Home Improvement Moderator @ DSL Reports

"wow, some people are thick and clearly can't think for themselves - the solution is to remove warning labels from poisons."

 

Offline mjn.mixael

  • Cutscene Master
  • 212
  • Chopped liver
    • Steam
    • Twitter
Re: Cloudflare security leak?
I tried password managers.. none of them were particularly graceful on mobile devices...
Cutscene Upgrade Project - Mainhall Remakes - Between the Ashes
Youtube Channel - P3D Model Box
Between the Ashes is looking for committed testers, PM me for details.
Freespace Upgrade Project See what's happening.

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Re: Cloudflare security leak?
Well compared with the alternative of reusing the same password, Lastpass isn't bad. Hell, it will even automatically fill in the password for you. Plus the other advantage is that you can have ridiculously long passwords for things. I routinely use 50 character passwords for most websites now. Even ones I don't particularly care about.
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline The E

  • He's Ebeneezer Goode
  • 213
  • Nothing personal, just tech support.
    • Steam
    • Twitter
Re: Cloudflare security leak?
topical video

If I'm just aching this can't go on
I came from chasing dreams to feel alone
There must be changes, miss to feel strong
I really need lifе to touch me
--Evergrey, Where August Mourns