TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Monzo’s Response to Cloudbleed

151 pointsby obeattieabout 8 years ago

9 comments

libeclipseabout 8 years ago
Even though they weren&#x27;t affected much and no one would have called them out if they didn&#x27;t do this, the fact that they did such a nice job of dissecting the situation and deploying the appropriate measures is really, really good.<p>Love monzo. &lt;3
评论 #13724200 未加载
deckiedanabout 8 years ago
Great that they respond so clearly and quickly.<p>One question - does anyone else feel that having NGINX as the only link in the summary kind of suggests that it&#x27;s an nginx problem? I could imagine my previous boss reading the article, and 3 months later saying, &quot;Wait what, we&#x27;re using nginx??? Isn&#x27;t that that shit that made cloudbleed happen?&quot;
评论 #13724175 未加载
评论 #13724279 未加载
评论 #13723954 未加载
评论 #13723989 未加载
mseebachabout 8 years ago
Honest question, this is far from my area of expertise: I get why you would put Cloudflare on a public website -- but what is the benefit of wrapping the authenticated, dynamic parts of a website&#x2F;service in Cloudflare? These are things you would want to never get cached, and, I suppose, you would want end-to-end TLS&#x27;d into your own network?
评论 #13723740 未加载
评论 #13723733 未加载
评论 #13724793 未加载
rodionosabout 8 years ago
The Monzo&#x27;s response is much more re-assuring compared to Cloudflare&#x27;s:<p><pre><code> &gt; &quot;We&#x27;ve seen absolutely no evidence that this has been exploited,&quot; he told Reuters by phone. &gt; &quot;It&#x27;s very unlikely that someone has got this information.&quot; </code></pre> <a href="http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-cyber-cloudflare-idUSKBN1630RT" rel="nofollow">http:&#x2F;&#x2F;www.reuters.com&#x2F;article&#x2F;us-cyber-cloudflare-idUSKBN16...</a>
评论 #13724873 未加载
_pmf_about 8 years ago
&gt; A bug in an NGINX module used by Cloudflare’s edge proxies<p>More precise: a bug in a proprietary closed source module for NGINX used in-house at Cloudflare.
评论 #13723918 未加载
overcastabout 8 years ago
What the heck is Monzo? I read the About, is this another Paypal 20 years later?
评论 #13724769 未加载
评论 #13724901 未加载
评论 #13724629 未加载
评论 #13724677 未加载
anc84about 8 years ago
If I understood the issue correctly, then &quot;Transaction information&quot; and &quot;Customers’ personally identifiable information&quot; via the Developer&#x27;s API <i>were</i> potentially affected.
brad0about 8 years ago
Great response from Monzo. I live in Scotland and it&#x27;s amazing the difference companies like monzo have compared to regular banks (see the tesco bank fiasco)
评论 #13723676 未加载
评论 #13723822 未加载
mdekkersabout 8 years ago
excellent response