

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- I tried to signup and got an "Internal Server Error" post the auth callback. Embarrassing for Cloudflare. Par for the vibe coded culture I guess.by tchalla
- In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.
Identity is hard y'all.
by thadt - I don't understand what your point is. Do you disagree with any of the concrete suggestions in the blog post about what should have been done differently, or do you think they're hard to follow?by saghm
- It looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.by joemi
- Not too bad that they launched looking like a phishing scam because they eventually added a link?
Shit, the bar is low these days.
by EdwardDiego - I mean, what would stop someone from registering mycloudflare.pay and doing the same thing? Having the link in the other direction seems like what matters moreby saghm
- I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshotby dwedge
- I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.by dwedge
- So it's not just FedEx[1] who does that, but also one of the most important tech company…
[1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
by stymaar
That's just goldThe Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).by Insimwytim- What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.by andremendes
- I thought it wouldn't be as I assume :) CloudFlare scans for new tld and either gets in the sunrise period or at a minimum objects to anyone else registering a straight CloudFlare.tld. But CloudFlarepay.com or cl0udflar3.com have more scam risk.by hahahaa
- I only realized it wasnt after googling for the phrase “cloudflare.pay” and finding the announcement on Cloudflare’s own blog, which I trust because it is on cloudflare.com
All the bots including Google’s say it’s a phishing scam site probably, since they don’t know Cloudflare has a wallet product.
by EGreg - This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.by 1970-01-01
- Presumably the big scary sysadmins have access to the *.cloudflare.com DNS records, and marketing just needs to push this thing right now and can't wait, so it's easier for them to buy a new domain with a shiny new TLD than wait for pay.cloudflare.com to be authorised.
cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such a big company.
by marcta - >Why is pay.cloudflare.com so hard to establish?
An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc.
> `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is blocked. I don't care that it's a Zig application.
I remember just doing SOC2 for a startup and it made just spinning up an EC2 instance require several steps of rigamarole just to be "in-compliance". And if anything goes wrong? Well why didn't you follow the 2,000 step process?
I don't envy anyone who has to deal with issues like these.
by nemothekid - Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).by epochbtc
- I’d argue this is exactly why this happened and why the poster is correct but missing the point:
Your organizational management is the problem not the technology
If you can’t coordinate internally to roll out a proper domain then I question how well your teams are managed
- Why is this so, so common? They're subdomains. They're free. It's not hitting anybody's budget to publish a new DNS entry. If someone has permission to publish anything in your name, they probably should be able to go make themselves a subdomain.
- Web Developers, please follow every best practice, I’m begging you
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
by ozim - Who made the website?by inigyou
- Who do we call? CTOs I guess.by hahahaa
- My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.by 63stack
- The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
by madeofpalk - At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
by yellow_lead - What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.by mirashii
- Half the time, those bots don't even respondby frollogaston
- > “What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?”
This drives me nuts. But it is a continuum. From help-bots which are just natural language navigation to docs, to the best in class llm’s with access to both knowledge of the company and your data (my fav so far is Shopify). The most annoying are those who read the docs to you like lawyer-bots.
I’m guessing the speed at which companies go from the first type to the last type depend on many factors such as volume of support issues, the expertise of the users, and corporate culture of reliance on “accountability sinks” (someone to be mad at, but who has no authority to help or correct a problem—I’m thinking of the merchant platform Square and their dark pattern navigation that tricks you to suffer the instant fees of the fund-now link trying to find the transfer schedule).
by xtiansimon - The point is to show how AI you are.by inigyou
- The point is to signal to investors that they're all-in on the current fad, thus making the stock price go up.by bakugo