Cloudfare service used by 5.5 million sites may have leaked passwords and auth.tokens

Status
Not open for further replies.
The only website I'm finding so far that I use with Cloudfire is reddit, so I went ahead and changed it. Had no personal info there and a unique password so I think I lucked out
 
Probably explains why someone in Munich used my password this morning. Google denied them and I had to reset everything. Turned on 2FA. Going to start systematically changing passwords every so often. Way too many breaches happening to feel secure.
 
Probably explains why someone in Munich used my password this morning. Google denied them and I had to reset everything. Turned on 2FA. Going to start systematically changing passwords every so often. Way too many breaches happening to feel secure.

It's already been said that Google doesn't use this I believe
 
Question for clarity, in the link provided with the sites, I found only 3 that I have visited in the timeframe of the Cloudflare leak issue. However I don't have accounts on those specific sites at all, as I just browse them.

Am I assume that I need to still change passwords for any regular site I browse with an account not listed in any of the cloudflare site lists provided within this thread, on the off chance that the affected Cloudflare used site, may have sent an information data request to a non-affected site where I do have a login account?
 
That is a huge fuck-up. I hope I'm in the clear. I don't think I have non-dummy accounts on any major Cloudflare site.
 
The only way to mitigate stuff like this happening is to simply not sign up to stuff that isn't absolutely essential. It's a mess.
 
Question for clarity, in the link provided with the sites, I found only 3 that I have visited in the timeframe of the Cloudflare leak issue. However I don't have accounts on those specific sites at all, as I just browse them.

Am I assume that I need to still change passwords for any regular site I browse with an account not listed in any of the cloudflare site lists provided within this thread, on the off chance that the affected Cloudflare used site, may have sent an information data request to a non-affected site where I do have a login account?
That's one thing I'm not sure about. I use Google to log into Medium, so I'm not sure if my Google account may have been compromised by Google exchanging information with Medium to log me in.

I'm going to assume if you just browsed a site and did not exchange any secure information, then you should be fine?
 
The only way to mitigate stuff like this happening is to simply not sign up to stuff that isn't absolutely essential. It's a mess.

Yes, tried to quickly delete my accounts on a few sites. Seems to be impossible. Didn't find how to delete them.
 
Namecheap, codepen, udemy, greenmangaming, glass door, uber, etc.

Basically I need to just change my password for everything. To say this is annoying is an understatement.
 
Fuck me authy is affected as well. This is so fucked.

I have a lot of work to do, not just on a personal level either. Thank you GAF for bringing this to my attention.

Today was supposed to be the first day of my weekend...
 
I found this warning on a discord channel I follow:

Sites vulnerable include:
Uber
Reddit
Yelp
Digital Ocean
OKCupid
RapGenius
Coinbase
Product Hunt
Udemy
Crunchyroll
FitBit
Hacker News
Zendesk
Discord
Github pages
Chocolatey


Damn, that's worse than I thought. lol

Damn I use 3 of those and I don't even wanna know what the full list of sites are...Ugh I don't want to have to go through changing everything :(

edit: Actually is there a full list of sites that have been compromised?
 
Fuck me authy is affected as well. This is so fucked.

I have a lot of work to do, not just on a personal level either. Thank you GAF for bringing this to my attention.

Today was supposed to be the first day of my weekend...

This really should not be ruining your weekend. It is a configuration induced security vulnerability, not a hack. There is no evidence anyone exploited it, and while the scope has the potential to be quite large, we know very little about whose information has been exposed, and what of that information is available. This is not like a site-wide hack where the best thing to do is immediately move to reset your password. That Github list strikes me as totally irresponsible, just listing any site that used Cloudflare, with no details about whether it used the affected features, what kind of session data was being sent on the site, etc. If it makes you feel more comfortable, update a password, but I think the vast majority of people could stand to wait for a few days, find out the scope and recommendations that come as a result, and then acting in due time.
 
Other notable sites that gaffers might frequent:

Nexusmods.com
Moddb.com

For London GAF:

Tfl.gov.uk

This really should not be ruining your weekend. It is a configuration induced security vulnerability, not a hack. There is no evidence anyone exploited it, and while the scope has the potential to be quite large, we know very little about whose information has been exposed, and what of that information is available. This is not like a site-wide hack where the best thing to do is immediately move to reset your password. That Github list strikes me as totally irresponsible, just listing any site that used Cloudflare, with no details about whether it used the affected features, what kind of session data was being sent on the site, etc. If it makes you feel more comfortable, update a password, but I think the vast majority of people could stand to wait for a few days, find out the scope and recommendations that come as a result, and then acting in due time.

Ok thanks, seeing this upon recently waking up is quite unsettling. I will stop panicking.

for now
 
This really should not be ruining your weekend. It is a configuration induced security vulnerability, not a hack. There is no evidence anyone exploited it, and while the scope has the potential to be quite large, we know very little about whose information has been exposed, and what of that information is available. This is not like a site-wide hack where the best thing to do is immediately move to reset your password. That Github list strikes me as totally irresponsible, just listing any site that used Cloudflare, with no details about whether it used the affected features, what kind of session data was being sent on the site, etc. If it makes you feel more comfortable, update a password, but I think the vast majority of people could stand to wait for a few days, find out the scope and recommendations that come as a result, and then acting in due time.
I tend to panic at this sort of stuff but this post reassured me.
 
So, I'm guessing the best we can do is sit back and hope that the situation doesn't blow all the way up?

While we're taking password managers. I've been using Dashlane for the last year and a bit. They're reputable, right?
 
Well, i´ve been changing passwords for the last half hour at work.

Crunchyrool
patreon
Greenmangaming + Steam since i linked it with it
Humblebundle
paypal because i payed with paypal on those sites
reddit

Fuck me, and give that man more than a t-shirt lmao
 
This really should not be ruining your weekend. It is a configuration induced security vulnerability, not a hack. There is no evidence anyone exploited it, and while the scope has the potential to be quite large, we know very little about whose information has been exposed, and what of that information is available. This is not like a site-wide hack where the best thing to do is immediately move to reset your password. That Github list strikes me as totally irresponsible, just listing any site that used Cloudflare, with no details about whether it used the affected features, what kind of session data was being sent on the site, etc. If it makes you feel more comfortable, update a password, but I think the vast majority of people could stand to wait for a few days, find out the scope and recommendations that come as a result, and then acting in due time.

Good advice to go by.

I try to keep my online presence as simple as possible. No linking between accounts, different passwords for each site, and a bare minimum presence.
 
Probably just a coincidence but Reddit is making me reset my password... and of course the password emailer thing seems to be borked.
 
Sorry for a dumb question... What if the password managers get hacked one day? Aren't they the holy grail and more likely to be attempted?

I suooose it's still better to have to change passwords once if that ever happens, rather than multiple random times as one site gets hacked?
 
I went through the full list. The only one I've ever logged into as a member was humblebundle.com.
But I also bought something from teespring.com once.
 
So, for those of us who have been signed out on devices which use our google accounts, if they're not affected by this, why have we been signed out? Or have I missed something when reading this thread?
 
Jesus that an insane number of sites...

This might be optimistic but is there a chance no one found this to do something malicious with the data?
 
So, for those of us who have been signed out on devices which use our google accounts, if they're not affected by this, why have we been signed out? Or have I missed something when reading this thread?

that apparently could do with Google changing something with 2FA on their end yesterday. Not sure though.
 
Is this why I got randomly kicked off my YouTube account on iOS last night?

So basically this is "reset all passwords" time right?
 
So, for those of us who have been signed out on devices which use our google accounts, if they're not affected by this, why have we been signed out? Or have I missed something when reading this thread?

The Google-signout seems to be unrelated to the Cloudflare issue (so far).
 
Status
Not open for further replies.
Top Bottom