• Scott Wilson@infosec.exchange
    link
    fedilink
    arrow-up
    2
    ·
    2 months ago

    @Jerry@hear-me.social How would Cloudflare know this, unless they are intercepting and LOOKING AT credentials and otherwise HTTPS-encrypted traffic?

    • Cheradenine@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      2 months ago

      I’m no fan of Cloudflare, but did you read the article?

      As part of our Application Security offering, we offer a free feature that checks if a password has been leaked in a known data breach of another service or application on the Internet. When we perform these checks, Cloudflare does not access or store plaintext end user passwords.

      They then go on to say they hash them and compare the hash to a db.

      It’s an interesting read