Skip to content
This repository has been archived by the owner on Jan 18, 2018. It is now read-only.

What specific features were affected? #127

Closed
turtledude01 opened this issue Feb 24, 2017 · 8 comments
Closed

What specific features were affected? #127

turtledude01 opened this issue Feb 24, 2017 · 8 comments

Comments

@turtledude01
Copy link

If I use FULL ssl encryption from end to end is it possible that my websites 'were' affected? I have read in many places that it is only the Flexible SSL that was affected, is this true?

@coderobe
Copy link
Contributor

Anything that routes through Cloudflare could have possibly leaked data via third partys that caused the leak to occur.

@turtledude01
Copy link
Author

Id love to see proof of this because nothing I have found officially states this.

@coderobe
Copy link
Contributor

coderobe commented Feb 24, 2017

Because Cloudflare operates a large, shared infrastructure an HTTP request to a Cloudflare web site that was vulnerable to this problem could reveal information about an unrelated other Cloudflare site.

Here's the official blog post, the quote can be found near the end of the post.
Search for External impact and cache clearing

@turtledude01
Copy link
Author

Ive already read that one, doesn't prove anything

@coderobe
Copy link
Contributor

coderobe commented Feb 24, 2017

The whole blog post goes into detail explaining why, and what exactly happened. It's been published by Cloudflare themselves. Personally i'd say this is proof enough, especially if potentially confidential data was leaked.

@turtledude01
Copy link
Author

Now show me proof that every site listed in this repo was affected.

@coderobe
Copy link
Contributor

coderobe commented Feb 24, 2017

The key words are could have and possibly.

Every website routed through Cloudflare's CDN solutions had a slim chance of leaking data via other, unrelated websites where the bug occured - as long as it happened on the same proxy node.

@pirate pirate closed this as completed Feb 24, 2017
@pirate
Copy link
Owner

pirate commented Feb 24, 2017

Even sites cloudflare has manually emailed saying they're not affected are not "proven" to be unaffected: #87 (comment)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants
@pirate @turtledude01 @coderobe and others