Cloudflare's Sign in with Apple generates JWTs that can be reused, bypasses 2FA

👋 Just noticed the new Sign in with Apple button on the dash. It seems this will let you sign in to an existing Cloudflare account simply if the email address on the Apple account matches the email address on a Cloudflare account. This seems like a major security issue, … | Continue reading


@community.cloudflare.com | 1 year ago

Archive.today returning bogus IP to Cloudflare Resolvers

I can’t resolve archive.is using 1.1.1.1 or 1.0.0.1. Works fine with other name severs. I’m receiving error 1001 using Cloudflare’s DNS. nslookup archive.is 8.8.8.8 Server: google-public-dns-a.google.com Address: 8.8.8.8 Non-authoritative answer: Name: archive.is Address … | Continue reading


@community.cloudflare.com | 2 years ago

Testing Cloudflare Argo Performance

I added Argo to a high volume client site today. It’s supposed to save 318 minutes of latency per month, as per the emailed message. The site is pretty fast already though so I’m skeptical. 19,080,000 milliseconds saved across 52,561 page loads (creating 2,163,163 requests) per … | Continue reading


@community.cloudflare.com | 2 years ago

Cloudflare Someone else can create an account / token on your email address

This morning I saw someone created a Cloudfare account on my business address, logged in and created API tokens. I used forgot my password to gain access, setup MFA, trash those API tokens and made sure my mailbox wasn’t compromised. It did give me a scare. It’s exactly like … | Continue reading


@community.cloudflare.com | 2 years ago

Spam on Cloudflare

Any chance Cloudflare deletes the account behind these spam sites? I didn’t have luck with the report abuse form. The hacker seems to be making these sites automatically, protected behind CloudFlare. | Continue reading


@community.cloudflare.com | 2 years ago

iOS private relay in Mail does not work with 1.1.1.1 DNS

While I am connected with 1.1.1.1 app (DNS only mode) I am not able to load email content with the new private relay feature. In the Mail app I get: Unable to load remote content privately. Disabling 1.1.1.1 in DNS queries mode fixes the problem. Am I the only one with this is … | Continue reading


@community.cloudflare.com | 2 years ago

Cloudflare cookie folding change causing disruption for Chromium based browsers

In Chrome 93.0.4577.82, I’m seeing some weirdness when setting cookies since Cloudflare folds all set-cookie headers into one. Here’s an example of the set cookie header when folded: set-cookie: test=1; Path=/; Expires=Tue, 13 Sep 2022 22:21:21 GMT; Secure; SameSite=None, test2 … | Continue reading


@community.cloudflare.com | 2 years ago

Cloudflare has started throttling download speeds

Horrible speeds when CloudFlare proxy enabled. If I or any one else clicks to download a file from the site with Cloudflare enabled, the downloads speeds per download are about 2MB/s. If I disable cloudflare proxy or bypass it by editing my hosts file, I can get 60-90MB/s. But as … | Continue reading


@community.cloudflare.com | 2 years ago

Stop Using HCAPTCHA

I just find that the challenge with captcha page for cloudflare service changed its provider from google’s recaptcha to hcaptcha. IT SUCKED! I never met that many requests for me to solve the CAPTCHA at Google era. Since most people use Chrome, for users’ experience, I strongly … | Continue reading


@community.cloudflare.com | 3 years ago

Cloudflare's proxy violates HTTP/1.1, and they don't care

Hello, It looks like there is a bug in how the cloudflare edge caching works regarding the HTTP Vary header. When a server serves a cacheable resource with a Vary: User-Agent header, cloudflare caches the resource when the first request comes, and then serves the same content ag … | Continue reading


@community.cloudflare.com | 4 years ago

Stop Using HCAPTCHA

I just find that the challenge with captcha page for cloudflare service changed its provider from google’s recaptcha to hcaptcha. IT SUCKED! I never met that many requests for me to solve the CAPTCHA at Google era. Since most people use Chrome, for users’ experience, I strongly … | Continue reading


@community.cloudflare.com | 4 years ago

Some Cloudflare IPs not reachable

The same issue with IP 104.18.46.41 My website and service is not available in Russia. | Continue reading


@community.cloudflare.com | 4 years ago

Cloudflare Workers KV Vulnerability

The KV namespace id is just a unique identifier. One of the properties of this unique identifier is that it’s difficult to guess, since it’s a UUIDv4. That means that if an attacker found out about this they couldn’t just guess all the namespace ids. Our long hex ids (like zone i … | Continue reading


@community.cloudflare.com | 4 years ago

Moving site connected to Cloudflare to new hosting

Hey all! I was couple times forced to change hosting for my websites and I will be facing similar issue soon. However in my case i had huge downtime probably I did something wrong. Assuming I have a website on CF and its working nicely, but I have to move it to next hosting, w … | Continue reading


@community.cloudflare.com | 4 years ago

Facebook now adds fbclid query string to URLs, busting CloudFlare’s cache

Hi, So since a few days, Facebook started adding an fbclid query string to all URLs posted on its platform. The URLs look like this: https://www.website.com/perma-link/?fbclid=IwAR2FEKP2N1EZQ0QU7ioC1MHvrqnrjtETeDNCpG9dkd3cLZIu_OF-IjTD2-c This query string is unique for each use … | Continue reading


@community.cloudflare.com | 5 years ago

Cloudflare Workers Webpack Boilerplate

Thank you, @zack - very nice to have the approval of a Cloudflare overlord team member! I should add that I just do this for fun, so if you and your Cloudflarian colleagues ever want to take the wheel on this, just let me know! 👍 | Continue reading


@community.cloudflare.com | 5 years ago

Archive.is not publishing IP addresses to Cloudflare's 1.1.1.1 resolver

Archive.is has chosen not to publish their IP addresses to Cloudflare DNS resolvers. You’ll need to take up the issue with them. | Continue reading


@community.cloudflare.com | 5 years ago