Hard Light Productions Forums

Site Management => Site Support / Feedback => Topic started by: Spoon on February 24, 2017, 07:23:45 am

Title: Cloudflare security leak?
Post by: Spoon on February 24, 2017, 07:23:45 am
Someone on a slack I visit linked this, and I was wondering if HLP could in any shape or form have been affected by this?
https://github.com/pirate/sites-using-cloudflare
Most of this is stuff I won't really pretend to understand, so I figured someone with a bit more knowhow about the subject could say something more meaningful
Title: Re: Cloudflare security leak?
Post by: Phantom Hoover on February 24, 2017, 07:32:24 am
What I'm hearing is "change every password you've ever used on a Cloudflare site", which in practice might as well be "change all your passwords on every website that hasn't explicitly been called safe". The severity of this leak is totally unprecedented in the history of network security in terms of the amount of potentially-compromised data. Literally any data that you sent through Cloudflare in the last several months may have ended up publicly displayed on someone's broken Chinese news website.
Title: Re: Cloudflare security leak?
Post by: Spoon on February 24, 2017, 07:43:37 am
hard-light.net is on the list of known domains affected

Reminder that there are inactive admin accounts that could pose a serious security risk here.
Title: Re: Cloudflare security leak?
Post by: mjn.mixael on February 24, 2017, 08:21:04 am
(http://www.relatably.com/m/img/angry-memes/Angry-Meme-04.jpg)

I'm so...tired... of having to change passwords across all sites every few weeks because of this crap. I take the given advice and use different passwords on just about every site.. but a leak like this? **** all that matters.
Title: Re: Cloudflare security leak?
Post by: Spoon on February 24, 2017, 08:34:07 am
^Agreed so much^
Title: Re: Cloudflare security leak?
Post by: X3N0-Life-Form on February 24, 2017, 11:18:20 am
^ Triple agreed ^

If that **** is as bad as it looks, it means I gotta change at least 3/4 of my passwords, awesome ...
Title: Re: Cloudflare security leak?
Post by: Zacam on February 24, 2017, 11:50:44 am
So, full stop here.

As of at least 3 hours ago, CloudFlare has certified/asserted that HLP as a domain has not been or had its traffic compromised in any way as a result of this vulnerability.

They are continuing with validating and monitoring for if that changes, and if it does, I'll be notified.
Title: Re: Cloudflare security leak?
Post by: chief1983 on February 24, 2017, 11:53:50 am
But I hope you guys aren't using the same password here as anywhere else as we aren't using SSL for logins.  Your plaintext pass is already all over the tubes.
Title: Re: Cloudflare security leak?
Post by: Mongoose on February 24, 2017, 06:21:02 pm
Is it bad that even with news like this I can't really summon the energy to go through and make my personal practices more secure?  Like, it's ridiculous enough even trying to keep track of passwords I've used in multiple places as-is, and my browser's list of saved passwords is long enough to substantially warp local space-time.  It's getting to the point where it doesn't seem humanly possible to keep everything straight, unless I go the dad route and put sticky notes around my monitor.
Title: Re: Cloudflare security leak?
Post by: jr2 on February 24, 2017, 07:17:04 pm
Is it bad that even with news like this I can't really summon the energy to go through and make my personal practices more secure?  Like, it's ridiculous enough even trying to keep track of passwords I've used in multiple places as-is, and my browser's list of saved passwords is long enough to substantially warp local space-time.  It's getting to the point where it doesn't seem humanly possible to keep everything straight, unless I go the dad route and put sticky notes around my monitor.

Same here.
Title: Re: Cloudflare security leak?
Post by: Spoon on February 24, 2017, 08:11:54 pm
Maybe consider using a password manager in that case?
(I dont use them myself, I've got no recommendations)
Title: Re: Cloudflare security leak?
Post by: jr2 on February 24, 2017, 08:17:56 pm
Maybe consider using a password manager in that case?
(I dont use them myself, I've got no recommendations)

I don't either, but: http://www.tomsguide.com/us/best-password-managers,review-3785.html
Title: Re: Cloudflare security leak?
Post by: karajorma on February 24, 2017, 09:20:49 pm
I use last pass and I haven't ever wanted to go back since I started. It does cost a bit if you want multiple devices though. - Apparently they changed that. So now there's no real excuse not to use a password manager of some sort. 
Title: Re: Cloudflare security leak?
Post by: rev_posix on February 24, 2017, 10:00:33 pm
I use last pass and I haven't ever wanted to go back since I started. It does cost a bit if you want multiple devices though.
Not any more.

https://lastpass.com

Quote
Free:
    Access on all devices Now Free
    Save & fill passwords
    Password generator
    Secure notes
    Share passwords & notes
    Security challenge
    Two-factor authentication (2FA)


Premium $1 /month, billed yearly

Premium includes
Everything in Free, plus:

    Shared family folder - up to 5 users
    YubiKey & Sesame 2FA options
    Priority tech support
    LastPass for applications
    Desktop fingerprint identification
    1GB of encrypted file storage
Title: Re: Cloudflare security leak?
Post by: Mongoose on February 24, 2017, 10:04:15 pm
Hmm...I've been a bit wary of the concept of password managers in the past, but it might be worth giving it a shot.  Provided the extension plays nice on Pale Moon, anyway.
Title: Re: Cloudflare security leak?
Post by: rev_posix on February 24, 2017, 10:07:45 pm
Hmm...I've been a bit wary of the concept of password managers in the past, but it might be worth giving it a shot.  Provided the extension plays nice on Pale Moon, anyway.
Unfortunately it doesn't.

The firefox plugin is an SDK/jetpack extension which isn't supported under the current palemoon build (27.1.1.1).

I've not looked to see if there is a way to get it working yet

EDIT:  From the palemoon forum:

Quote
The latest version of Lastpass (from lastpass.com, not the AMO) works fine if installed with Moon Tester Tool.

You need to download it with wget since hitting the "download" button doesn't actually download it, it tries to install it (which fails because it needs to be installed with Moon Tester Tool)

Code: Select all
 wget https://lastpass.com/lastpassffx/xpi.php -O lpffx.xpi

EDITEDIT:  And it does seem to work when doing it this way.  Moon Tester Tool is it's own add-on from the pale moon project page.
Title: Re: Cloudflare security leak?
Post by: mjn.mixael on February 24, 2017, 10:14:39 pm
I tried password managers.. none of them were particularly graceful on mobile devices...
Title: Re: Cloudflare security leak?
Post by: karajorma on February 25, 2017, 01:24:10 am
Well compared with the alternative of reusing the same password, Lastpass isn't bad. Hell, it will even automatically fill in the password for you. Plus the other advantage is that you can have ridiculously long passwords for things. I routinely use 50 character passwords for most websites now. Even ones I don't particularly care about.
Title: Re: Cloudflare security leak?
Post by: The E on February 25, 2017, 03:19:00 am
topical video