Bitcoin Forum
May 04, 2024, 04:45:50 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: [Warning][Cloudbleed bug] Change your passwords & 2FA & API keys  (Read 1515 times)
DomainMagnate
Hero Member
*****
Offline Offline

Activity: 602
Merit: 500



View Profile WWW
February 25, 2017, 11:09:21 AM
 #21

I have changed my password as soon as I got email regarding this bug.I haven't received any email from yobit, c-cex etc and I wonder if they use cloudflare or not.
1714841150
Hero Member
*
Offline Offline

Posts: 1714841150

View Profile Personal Message (Offline)

Ignore
1714841150
Reply with quote  #2

1714841150
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714841150
Hero Member
*
Offline Offline

Posts: 1714841150

View Profile Personal Message (Offline)

Ignore
1714841150
Reply with quote  #2

1714841150
Report to moderator
1714841150
Hero Member
*
Offline Offline

Posts: 1714841150

View Profile Personal Message (Offline)

Ignore
1714841150
Reply with quote  #2

1714841150
Report to moderator
neochiny
Hero Member
*****
Offline Offline

Activity: 756
Merit: 503


Crypto.games


View Profile WWW
February 25, 2017, 11:12:31 AM
 #22

--
1.How does that contribute to any discussions here ? Off-Topic Much ?
2.We're suppose to be talking about services using Cloudflare and not password managers..
3.Not every site.The sites which are prone to DDos do.Finally people can stop using that crap.
4.Not anytime soon.Neither is a feature request on the new forum.
1.What, I can't comment on a point in his post I find interesting? As for topic, SEE the hr line?
2. <sigh> Nitpick-much? Should I rearrange my post and place the middle part on top to stop your fussing?
3.Hence the word 'Almost'. And finally, the only part of your post that's got anything to do with the 'topic'.
4.Ahuh. Whatever you say.

As for topic ( Grin in case there's another fuss),
the bug's been there for months(September last year), Cloudflare was clueless, and for the bug to be found and reported by someone from Google?  Roll Eyes

Anyway, for anyone who hasn't done so yet, make sure to change your account's password and activate 2fa if possible.

Remember to make your passwords strong and never reuse on multiple sites.
(You could use password managers or make hard copies to keep track of your account details.  Tongue Tongue Grin Grin Grin)
 

████  ███████  ███
██████████
███      ███████
███      ███████████
██████████████████
████████
███   ████  ███████████
███ ███████████████
█████████
█████████████████
███  ███████
██████████████
███        ████████
███████████▀▀███▀▀███████████
██████▀▀     ███     ▀▀██████
████▀   ▄▄█████████▄▄   ▀████
████▄▄▄███▀  ▀█▀  ▀███▄▄▄████
██▀▀▀██▀      ▀      ▀██▀▀▀██
█▀  ▄██               ██▄  ▀█
█   ████▄▄         ▄▄████   █
█▄  ▀██▀             ▀██▀  ▄█
██▄▄▄██▄             ▄██▄▄▄██
████▀▀▀███▄ ▄█ █▄ ▄███▀▀▀████
████▄   ▀▀███▄█████▀▀   ▄████
███████▄     ███     ▄███████
███████████▄▄███▄▄███████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
..PLAY NOW..
███  ███████  ████
██████████
███████      ███
███████████      ███
██████████████████
████████
███████████  ████   ███
███████████████ ███
█████████
█████████████████
███████  ███
██████████████
████████        ███
Coding Enthusiast (OP)
Legendary
*
Offline Offline

Activity: 1039
Merit: 2783


Bitcoin and C♯ Enthusiast


View Profile WWW
February 25, 2017, 03:50:42 PM
 #23

Sound advice. It's worth adding that if you previously set up shared secret 2FA between 2016-09-22 and 2017-02-18 on one of the affected sites you should get a new secret in addition to changing your password. Usually disabling and reenabling 2FA is the way to do that.

Good idea, added "Change 2FA" and "API keys" to the subject and in the TL;DR with red font.

Projects List+Suggestion box
Donate: 1Q9s or bc1q
|
|
|
FinderOuter(0.19.1)Ann-git
Denovo(0.7.0)Ann-git
Bitcoin.Net(0.26.0)Ann-git
|
|
|
BitcoinTransactionTool(0.11.0)Ann-git
WatchOnlyBitcoinWallet(3.2.1)Ann-git
SharpPusher(0.12.0)Ann-git
Kprawn
Legendary
*
Offline Offline

Activity: 1904
Merit: 1073


View Profile
February 25, 2017, 04:12:40 PM
 #24

Holy Shit, a lot of big sites has been affected : 4,287,625 possibly affected domains. Some of these like Fiverr and Uber  are also on the list.

Damn, this is a major oversight on their side, and I think a bunch of these sites are going to cancel their membership after this. You think you are

relatively safe, and then something like this happens.  Roll Eyes

THE FIRST DECENTRALIZED & PLAYER-OWNED CASINO
.EARNBET..EARN BITCOIN: DIVIDENDS
FOR-LIFETIME & MUCH MORE.
. BET WITH: BTCETHEOSLTCBCHWAXXRPBNB
.JOIN US: GITLABTWITTERTELEGRAM
Yakamoto
Legendary
*
Offline Offline

Activity: 1218
Merit: 1007


View Profile
February 25, 2017, 04:18:22 PM
 #25

Shit, gonna have to go and change my blockchain API.

I'm glad this was caught relatively sooner rather than later, but it's a shame there is another issue of this kind.

Luckily I don't have anything of considerable value stored on anything there, maybe $10 across all the affected sites you mentioned. Either way, better to be safe rather than sorry.
~Bitcoin~
Legendary
*
Offline Offline

Activity: 994
Merit: 1000



View Profile
February 25, 2017, 04:29:30 PM
 #26

You can add cubits.com and nicehash.com on the list, i have got email from both of them about cloudbleed this week. I have changed password in most of the site that have cloudflare.

South Park
Hero Member
*****
Offline Offline

Activity: 2884
Merit: 794


I am terrible at Fantasy Football!!!


View Profile
February 25, 2017, 04:39:40 PM
 #27

--
I have to start using a password manager to deal everything now which i have been avoiding all this while.
Yeah well, I've tried using one before but decided against continuing its use after some time. It's just an additional worry.
Frankly, couldn't stop worrying that the password manager I use would be the weak point, and then ALL of my accounts woulda been compromised.
Decided to go old school instead and keep a hard copy.  Grin Nothing better than pen and paper.  Grin

Almost every site uses CloudFlare nowadays. AND that bug has been there for months.  Roll Eyes

I wonder when bitcointalk would use 2fa. It would be great if they decide to implement it soon..
Open source password managers are not so bad, you know you are the only one holding your passwords, the file where the passwords are contained is encrypted and you need a master password, if you like better to have a hard copy there is not a problem but password manager can save lots of time.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
e-coinomist
Legendary
*
Offline Offline

Activity: 2380
Merit: 1085


Money often costs too much.


View Profile
February 28, 2017, 12:58:31 PM
 #28

I wonder when bitcointalk would use 2fa. It would be great if they decide to implement it soon..

Nope. There allready is something far superior active. You can add a BTC address onto your profile (or post it somewhere (there's a thread for that where people quote those postings for tamper proofness)) and if THAT breaks, the whole Saga is over anyways.

2FA usually just adds an Android cellphone and everybody of us knows those aren't adding to your security but substracting from it.
tiggytomb
Legendary
*
Offline Offline

Activity: 1848
Merit: 1000


View Profile
February 28, 2017, 01:02:30 PM
 #29

Nice thread, I was looking for a list of all the sites that might be affected and I didn't see one until just now.  It's always a good idea to have 2FA enabled on all accounts.
bitcoinvest
Legendary
*
Offline Offline

Activity: 1124
Merit: 1000


13eJ4feC39JzbdY2K9W3ytQzWhunsxL83X


View Profile
February 28, 2017, 10:06:34 PM
 #30

I had account to exchange that is using cloudbleed Smiley very good for me i am around this forum all day long and had information from here 1st...

After 1-2 days email arrived from exchange to change password and OTP also Smiley

I really can't believe that up to now... some years before the OTP was announced to be something like unbreakable and here we are Smiley

Over the past 5 years from the experience we have in every day using computers ( no matter the level) i understood one thing...the only unbreakable is the BTCitcoin Smiley

But anyway, in the community we not hear anything bad from this bug to any exchange happening etc... so all is good !
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!