At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
ozimtoday at 8:04 PM
Web Developers, please follow every best practice, I’m begging you
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
63stacktoday at 6:46 PM
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
1970-01-01today at 7:08 PM
This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
andremendestoday at 7:17 PM
What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.
joemitoday at 8:17 PM
It looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.
epochbtctoday at 7:14 PM
Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
thadttoday at 6:53 PM
In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.
Identity is hard y'all.
dwedgetoday at 6:47 PM
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
aprilnyatoday at 8:34 PM
I saw the whole Cloudflare Pay thing and had the exact same thoughts - this has to be some sort of phishing...
Joker_vDtoday at 6:47 PM
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
deletedtoday at 7:02 PM
LocalHtoday at 7:14 PM
Web security wasn't hard before we started trying to make the web a platform for full executable software.
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
TZubiritoday at 7:41 PM
this from a company whose main product is (was) security.
I feel there's a generalized decrease in quality in software in general.
iryndintoday at 7:39 PM
[dead]
thataccounttoday at 6:53 PM
Cloudflare is your favorite company and they are geniuses?
Dear Diary,
Today my fanboy bubble was burst.
Signed,
Author
sghiassytoday at 6:57 PM
Just use LLMs. They can apparently doing everything and all the things
wackgettoday at 7:40 PM
1. Why is this website blocked when I try browsing it using Brave?
2. Why on earth would you want a financial product from a WAF?content delivery company?