Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
In TFA there is no single issue of actual things that web developers could be blamed for.
CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.
All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...
Ffs, just put this on apps.proton.me or something so I actually know it's real!
An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc.
> `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is blocked. I don't care that it's a Zig application.
I remember just doing SOC2 for a startup and it made just spinning up an EC2 instance require several steps of rigamarole just to be "in-compliance". And if anything goes wrong? Well why didn't you follow the 2,000 step process?
I don't envy anyone who has to deal with issues like these.
cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such a big company.
https://aws.amazon.com/blogs/security/threat-tactic-spotligh...
(AWS have since fixed this problem, but it exists on other services.)
Your organizational management is the problem not the technology
If you can’t coordinate internally to roll out a proper domain then I question how well your teams are managed
The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
That's just gold[1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
All the bots including Google’s say it’s a phishing scam site probably, since they don’t know Cloudflare has a wallet product.
Identity is hard y'all.
The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.
The domain's whois is also devoid of identifying details:
https://rdap.nominet.uk/pay/domain/cloudflare.pay
Registered through 101domain, with nothing except a registrar abuse contact.
I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.
edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.
Luckily, Google didn't fail me this time. Found a blog about this product with a link to the same domain.
It's why Valve moved into OSes and hardware. If they didn't, Microsoft were holding a nuclear bomb over their heads. It's why Google has a phone platform, because Apple has been replacing the Google apps one-by-one. It's also why Samsung has a parallel suite of apps to the Google ones. It's why the pizzeria makes fries, because they're threatened by the fry shop across the street starting to serve pizza. It's why Uber tried to make self driving taxis. It would be good if the fry shop made only the best fries and the pizza shop made only the best pizza and Valve made only the best game store and Microsoft made only the best OS, but it's a very unstable equilibrium. Does your ISP still give you an email address?
2. Why on earth would you want a financial product from a WAF?content delivery company?
I feel there's a generalized decrease in quality in software in general.
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.
I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.
I bet the world would crumble. Good.
Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.
Email has similarly been destroyed by HTML email, at least partially.
It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.
> Your viewpoint enables billions of dollars of fraud every year, worldwide.
Yep. Having knives in every kitchen enables people to be stabbed, too. As a society we choose to allow useful things to exist rather than locking everyone in a straitjacket, even though the latter would be more safe and prevent all kinds of crime and tragedy. It's funny that you complain about centralizing control at the same time as making this argument that nobody should have tools because tools can be misused.
Dear Diary,
Today my fanboy bubble was burst.
Signed,
Author
https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-...
Cisco looks to have made money from repression and torture.
Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.
And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house.
Are Cloudflare supposed to be the police?
Does the UN provide a registry list of criminal domains that should not be livened?
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.
In fact, they would have likely already heard about the new product at lunch or something.
Of course not. The extremely vast majority of support staff aren't connected to "internal people" and certainly don't have any access to the main company's Slack.
Most of all, those people are paid very little on very tight length-per-interaction targets. They can't spend any time at all looking for stuff outside the docs package or chatting with peeps outside the immediate costaff.
With the latter type, there’s still almost always a line of communication to corporate. And the support staff still try to help. They are decent human beings, even if the end result kind of sucks.
Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experience anyway, right?