2nd Cloudflare hack reveals the dangers of them seeing ALL passwords - eviltoast

Cloudflare just revealed on their blog that back in November a sophisticated hacker, likely a nation state, got access to some of their servers. This comes after a security firm identified a different vulnerability months earlier. This shows the true dangers of them overseeing all traffic and all cryptocurrency on all centralized exchanges. It’s critically important you understand this:

https://simplifiedprivacy.com/cloudflarehack/

Tor Browser Onion: http://privacypkybrxebcjicfhgwsb3coatqechwnc5xow4udxwa6jemylmyd.onion/cloudflarehack/

I question that GetMonero.org is on Cloudflare. We should strongly reconsider this as we’re downloading XMR wallet binaries from an organization not friendly to privacy. And the PGP public key to verify it is on the same Cloudflare website.

I do not have much say in this community as I’m new, but I ask you to bring it to the attention of those who do.

  • Blake@monero.town
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    9 months ago

    Yeah tbh fuck cloudflare, fully compromised

    cloudflare to host top level US government web services .gov https://cloudflare.net/news/news-details/2023/Cloudflare-Wins-CISA-Contract-for-Registry-and-Authoritative-Domain-Name-System-DNS-Services/default.aspx

    however I understand why many people use it. it’s the biggest of the ddos protection services, and with ddos mitigation, the beefier the better. i’ve seen plenty of smaller, ethical, cypherpunk ddos services but when the big ddos comes they can’t help too much.

    with something like monero - it’s an obvious target for censorship, even temporarily - imagine a financial crash, or nation state revolution where people want to get their money out. perfect time for monero adoption, but getmonero.org is down to ddos. therefore being with cloudflare is the best protection. however if sed flight to monero goes against the interests of the USA and they threaten to pull their $8million contract from cloudflare, things might change very quickly (one of many ways in which corporations are controlled)

    i guess it’s still up for debate - obviously monero is a force of decentralisation so cloudflare is antithetical. but what is the alternative?

  • clever_banana@lemmy.today
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    9 months ago

    I strongly agree, but if you tell the admin they will ask for a replacement.

    Do we have a suggested alternative to cloud flare to protect from DDoS attacks? Its a legitimate issue for many sites.

    For form spam protection I usually recommend hcaptcha, but that won’t work for DoS

    Edit: I have noticed that hetzner protects themselves with a pow-powered DOS protection service that actually works (unlike cloudflare) on hardened web browsers. But I’ve never seen them advertise it for resale, which is a shame.