Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Your blog post doesn't seem to discuss their response very much.

What leads you to believe that CloudFlare was impressively fast and transparent in this case? Especially since statements from Project Zero seem to imply that they were anything but.



CF disabled the problematic feature within hours, on a Friday evening. After that, figuring out what private data was stuck in search engine caches was obviously going to take some time. It seems clear enough that they were working as fast as they could. Tavis is awesome but I think he was being unfairly hard on them in the project zero thread.

(Note: All of the above is based on my external observations, as I was not yet an employee nor did I have any internal access at the time.)


"statements from Project Zero" -- nope, statement from one person. Also you're assuming those are facts.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: