

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- So it's not just FedEx[1] who does that, but also one of the most important tech company…
[1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
by stymaar
That's just goldThe Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).by Insimwytim- What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.by andremendes
- This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.by 1970-01-01
- Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).by epochbtc
- Web Developers, please follow every best practice, I’m begging you
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
by ozim - My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.by 63stack
- At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
by yellow_lead