Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What is the correct way?

Honest question...

Out of hundreds of passwords I potentially need to reset, I'd like to prioritize.



Passwords and domain lists aren't a good answer. Explained here: https://gist.github.com/raggi/0d22757fee6eff4bb93a5731215060...


You have resolve the DNS and see if it points to one of Cloudflare's reverse proxies.


And even then, no guarantee. One could host a static shopwindow site on his own, and use CF for the actual backend of a mobile app under a different domain that nobody knows about.

There is no real way to know what has leaked and from whom. The only ones with real info are CF and it's clear from the amount of sites they've missed in their purge-requests that even them don't really know.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: