Bitcoin Forum
May 05, 2024, 06:31:59 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: 1 2 [All]
  Print  
Author Topic: Cloudflare hacked? So now we need to change passwords on Bitcointalk again?  (Read 1576 times)
adaseb (OP)
Legendary
*
Offline Offline

Activity: 3752
Merit: 1710



View Profile
February 24, 2017, 03:05:17 AM
 #1

Found this on Reddit:
https://www.reddit.com/r/Bitcoin/comments/5vuih9/internet_psa_cloudbleed_cloudflare_leaked/

Since Bitcointalk uses Cloudfare this means we need to change our passwords again? Also Bitfinex, Poloniex, Coinbase, etc ?


.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
1714890719
Hero Member
*
Offline Offline

Posts: 1714890719

View Profile Personal Message (Offline)

Ignore
1714890719
Reply with quote  #2

1714890719
Report to moderator
1714890719
Hero Member
*
Offline Offline

Posts: 1714890719

View Profile Personal Message (Offline)

Ignore
1714890719
Reply with quote  #2

1714890719
Report to moderator
1714890719
Hero Member
*
Offline Offline

Posts: 1714890719

View Profile Personal Message (Offline)

Ignore
1714890719
Reply with quote  #2

1714890719
Report to moderator
TalkImg was created especially for hosting images on bitcointalk.org: try it next time you want to post an image
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
RoommateAgreement
Hero Member
*****
Offline Offline

Activity: 770
Merit: 500


Bazinga!


View Profile
February 24, 2017, 04:04:26 AM
 #2

Since Bitcointalk uses Cloudfare

bitcointalk has never been using cloudflare and is not using cloudflare now either.

funny thing is that people have always been suggesting to Theymos to go to cloudflare and they always denied because of security reasons. now we can see one of them.

Buying the dip...
Spoetnik
Legendary
*
Offline Offline

Activity: 1540
Merit: 1011


FUD Philanthropist™


View Profile
February 24, 2017, 05:51:23 AM
 #3

Since Bitcointalk uses Cloudfare

bitcointalk has never been using cloudflare and is not using cloudflare now either.

funny thing is that people have always been suggesting to Theymos to go to cloudflare and they always denied because of security reasons. now we can see one of them.

Agreed.

And another reason maybe privacy too.. There has been TOR issues with Cloudflare i think.
But mostly i think theymos wanted full control.. and he rightly so should considering the target this place is.

FUD first & ask questions later™
Kakmakr
Legendary
*
Offline Offline

Activity: 3444
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
February 24, 2017, 06:09:09 AM
 #4

Since Bitcointalk uses Cloudfare

bitcointalk has never been using cloudflare and is not using cloudflare now either.

funny thing is that people have always been suggesting to Theymos to go to cloudflare and they always denied because of security reasons. now we can see one of them.

Yes, we had a site running behind Cloudflare and we got hacked 3 times in 2 years. You get a false sense of security, when you use them and you think you are bullet proof. I am glad this forum decided not to use them, because it will keep the admins on their toes.

Most "hacks" are done through social engineering and fooling the employees working for Cloudflare.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
davis196
Hero Member
*****
Offline Offline

Activity: 2968
Merit: 913



View Profile
February 24, 2017, 12:40:50 PM
 #5

Found this on Reddit:
https://www.reddit.com/r/Bitcoin/comments/5vuih9/internet_psa_cloudbleed_cloudflare_leaked/

Since Bitcointalk uses Cloudfare this means we need to change our passwords again? Also Bitfinex, Poloniex, Coinbase, etc ?



Localbitcoins uses Cloudflare and there might be some risk for people`s accounts but i`m not that concerned.
I don`t have bitcoins in my LBC wallet right now. Grin
I don`t know what is the relation between Cloudflare being hacked and Bitcointalk accounts security?

Hydrogen
Legendary
*
Offline Offline

Activity: 2562
Merit: 1441



View Profile
February 24, 2017, 12:52:07 PM
 #6

Does cloudflare store one-way-hashed passwords or plain text?

I don't know if there are collision or other vulnerabilities for one way hashes, which is what should be stored if standard security is followed.

The breach could be nothing to worry about.

Thanks for the info btw. I changed my password just in case.
asdalani
Hero Member
*****
Offline Offline

Activity: 882
Merit: 500


CryptoTalk.Org - Get Paid for every Post!


View Profile
February 24, 2017, 12:52:32 PM
 #7

People should've known better to have a 3rd party do the security of their websites.

 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
Kray
Hero Member
*****
Offline Offline

Activity: 658
Merit: 500



View Profile
February 24, 2017, 12:54:06 PM
 #8

Why we need change our password, i guess they hash our password so it still save right?
asdalani
Hero Member
*****
Offline Offline

Activity: 882
Merit: 500


CryptoTalk.Org - Get Paid for every Post!


View Profile
February 24, 2017, 12:56:02 PM
 #9

I think that ChronoBank was using CloudFlare as well:

From their Altcoin ANN:
Dear TIME token holders,

A critical vulnerability was detected in Cloudflare service. Our ICO website used Cloudflare for anti-DDOS protection.

Change your password at ICO Dashboard immediately!

https://chronobank.io

More info on this vulnerability:

https://medium.com/@octal/cloudbleed-how-to-deal-with-it-150e907fd165

Best regards,
Chronobank team


 
                                . ██████████.
                              .████████████████.
                           .██████████████████████.
                        -█████████████████████████████
                     .██████████████████████████████████.
                  -█████████████████████████████████████████
               -███████████████████████████████████████████████
           .-█████████████████████████████████████████████████████.
        .████████████████████████████████████████████████████████████
       .██████████████████████████████████████████████████████████████.
       .██████████████████████████████████████████████████████████████.
       ..████████████████████████████████████████████████████████████..
       .   .██████████████████████████████████████████████████████.
       .      .████████████████████████████████████████████████.

       .       .██████████████████████████████████████████████
       .    ██████████████████████████████████████████████████████
       .█████████████████████████████████████████████████████████████.
        .███████████████████████████████████████████████████████████
           .█████████████████████████████████████████████████████
              .████████████████████████████████████████████████
                   ████████████████████████████████████████
                      ██████████████████████████████████
                          ██████████████████████████
                             ████████████████████
                               ████████████████
                                   █████████
.CryptoTalk.org.|.MAKE POSTS AND EARN BTC!.🏆
jtipt
Hero Member
*****
Offline Offline

Activity: 1064
Merit: 529



View Profile
February 24, 2017, 12:57:51 PM
 #10

People should've known better to have a 3rd party do the security of their websites.
Yeah, but unfortunately a lot of websites use CloudFlare Sad Now I need to go and change a lot of passwords and i might have, i hope that cloudflare uses some encryption to store to data.
bL4nkcode
Copper Member
Legendary
*
Offline Offline

Activity: 2142
Merit: 1305


Limited in number. Limitless in potential.


View Profile
February 24, 2017, 01:04:15 PM
 #11

There are so many sites that are affected by this issue from CloudFlare and even on crypto-games.net also using this service just received their email about this, and  I changed my password also for security reasons.  And I don't think if this forum is currently using CloudFlare, can some confirmed it if this is true? I didn't see in News above the forum or even on meta about this.  
devans
Sr. Member
****
Offline Offline

Activity: 528
Merit: 368


View Profile
February 24, 2017, 04:00:39 PM
 #12

And I don't think if this forum is currently using CloudFlare, can some confirmed it if this is true? I didn't see in News above the forum or even on meta about this.  

bitcointalk.org does not use Cloudflare and is not affected. theymos says the same in this thread on the Meta board.
bathrobehero
Legendary
*
Offline Offline

Activity: 2002
Merit: 1051


ICO? Not even once.


View Profile
February 24, 2017, 05:35:52 PM
 #13

Why we need change our password, i guess they hash our password so it still save right?

Cloudflare revealed a serious bug in its software today that caused sensitive data like passwords, cookies, authentication tokens to spill in plaintext from its customers’ websites.

Not your keys, not your coins!
nillohit
Full Member
***
Offline Offline

Activity: 154
Merit: 100

***crypto trader***


View Profile
February 24, 2017, 08:22:34 PM
 #14

I've just changed passwords of coinbase, btc-e, bitpay, cubits & localbitcoins

П    |⧛ ☛  Join the signature campaign and earn free PI daily!  ✅ |⧛    П
|⧛         ☛  PiCoin - get in now  ✅     ☛ No ICO!  ✅          |⧛
arcanaaerobics
Sr. Member
****
Offline Offline

Activity: 364
Merit: 250


View Profile
February 24, 2017, 08:58:55 PM
 #15

I've just changed passwords of coinbase, btc-e, bitpay, cubits & localbitcoins
You think that is safe?
Keylogger they injected keylogger from those emails that Cloudbet, coinbase and all those other sites that sent you out emails to "Change your passwords NOW!" they didn't even tell you why because they were caught with their pants down and got ass fucked royally all because of their so called "SECUR-ITY TEAM A-ONE!" are not competent at their own FUCKING JOBS! Roll Eyes
FIre this fuckheads and replace them with fucking monkeys!
They would do a better job then these fucking freaks of nature.
Good god DAMN MAN! Are everybody fools now?! Roll Eyes
Spoetnik excluded of course because he is a fellow AK-47 owner! Grin Wink
And fellow country man I was referring to this fucking retardo:
https://bitcointalk.org/index.php?topic=1798844.0

Have fun with this freak as much as I have for the past week of knowing he existed!
And I still wish he was never born. Undecided
Winner
Legendary
*
Offline Offline

Activity: 1190
Merit: 1000


Look ARROUND!


View Profile
February 24, 2017, 11:20:40 PM
 #16

I've just changed passwords of coinbase, btc-e, bitpay, cubits & localbitcoins

I think that YoBit, c-cex and 98% of the HYIP websites use CloudFlare.

Is CloudFlare the only website security company that features DNS protection or something? I guess that people that build websites are too much in a hurry to do it themselves and that's why things like this happen.

Bringing in a third-party to do dirty work isn't the right thing to do unless the person building the website doesn't really care for learning on how to have their websites updated with the latest security.

It makes me wonder why people like the hard route, it only brings shame.


Watch when Bitcoin starts breaking your systems.

Oh, too soon?


.........................................
             █████████████████
         ███ ██     █     ██ ███
       ██ █████     █     █████ ██
     ███   █   █  █████  █   █   ███
   ███     █    ███ █ ███    █     ███
  ██  ███ ██ ███    █    ███ ██ ███  ██
  ██     ████       █      █████     ██
 ███   ██ █  ███    █    ███  █ ██   ███
 █ █ ██   █     ██  █  ██     █   ██ █ █
█████     █       █████       █     █████
 █ █ ██   █   ████  █  ████   █   ██ █ █
 ███   ████ ██      █      ██ ████   ███
  ██  █  █████      █      █████  █  ██
  ██ ██   ██ ████   █  ████  ██   ██ ██
   ██      █     ██████      █     ███
     ████  █   ██████████    █  ████
       ██ █████     █    ██████ ██
         ███  ██    █   ███  ███
            █████████████████
ARROUND









.









.
Telegram
ANN Thread
Bounty Thread
Whitepaper
shinratensei_
Legendary
*
Offline Offline

Activity: 3094
Merit: 1024


Leading Crypto Sports Betting & Casino Platform


View Profile
February 24, 2017, 11:44:48 PM
 #17

I've just changed passwords of coinbase, btc-e, bitpay, cubits & localbitcoins
I think that YoBit, c-cex and 98% of the HYIP websites use CloudFlare.
Kraken, Polo, and all of the exchange site are using cloudflare.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Quickseller
Copper Member
Legendary
*
Offline Offline

Activity: 2870
Merit: 2298


View Profile
February 24, 2017, 11:59:20 PM
 #18

Quote from: theymos
No, only sites which used Cloudflare could've been affected.
enquirer
Sr. Member
****
Offline Offline

Activity: 306
Merit: 257


View Profile
February 26, 2017, 01:43:27 PM
 #19

Wait, Cloudflare has access to all decrypted data on the server end of https sessions? So Cloudflare employees or employees at data centers that cloudflare uses have access to all Bitfinex, poloniex etc passwords? Completely irresponsible if so, regardless of cloudbleed bug. They are basically selling user security for 30 shekels worth of traffic reduction.
clickerz
Hero Member
*****
Offline Offline

Activity: 1414
Merit: 505


Backed.Finance


View Profile
February 26, 2017, 01:50:07 PM
 #20

Wait, Cloudflare has access to all decrypted data on the server end of https sessions? So Cloudflare employees or employees at data centers that cloudflare uses have access to all Bitfinex, poloniex etc passwords? Completely irresponsible if so, regardless of cloudbleed bug. They are basically selling user security for 30 shekels worth of traffic reduction.

We don't know yet their level of security. This is maybe possible or not. Hope this issues would be clarified soon. There are also many  sites under cloudfare and this is devastation if true. But for those 2FA is activated, I thick it is more secure and not the way we think as of now.

Open for Campaigns
devans
Sr. Member
****
Offline Offline

Activity: 528
Merit: 368


View Profile
February 26, 2017, 02:17:48 PM
 #21

Wait, Cloudflare has access to all decrypted data on the server end of https sessions? So Cloudflare employees or employees at data centers that cloudflare uses have access to all Bitfinex, poloniex etc passwords? Completely irresponsible if so, regardless of cloudbleed bug. They are basically selling user security for 30 shekels worth of traffic reduction.

Cloudflare acts as a reverse proxy and has access to all data that passes between the server and the client. Keep in mind that that is also the case for sites' hosting providers, including those that don't use Cloudflare. Aside perhaps from running the servers in your basement, which is neither practical nor cost-efficient, it's not possible to completely avoid trusting a third party.
Pages: 1 2 [All]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!