TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Email from Cloudflare's CEO about 'Cloudbleed'

7 点作者 JOfferijns超过 8 年前

1 comment

koolba超过 8 年前
&gt; To date, we have yet to find any instance of the bug being exploited, but we recommend if you are concerned that you invalidate and reissue any persistent secrets, such as long lived session identifiers, tokens or keys. Due to the nature of the bug, customer SSL keys were not exposed and do not need to be rotated.<p>This should be rewritten: <i>Any data sent to or from users of your website during the time the bug was live is potentially cached permanently. This includes all session identifiers, passwords, email addresses, and PII that was sent or received by your website. We recommend immediately rotating session secrets to prevent session hijacks using this data, notifying all you customers and forcing password resets.</i>
评论 #13723303 未加载