31 comments

[ 0.23 ms ] story [ 45.4 ms ] thread
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.

> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.

What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?

Monkey see, monkey do: https://adele.pages.casa/md/blog/all-my-clients-wanted-a-car...

"It's not about utility. It's not even really about the chatbot. It's about visibility, the fear of looking behind. A website without a chatbot in 2026 risks feeling unfinished, like something's missing. Even if what's missing is a half-broken widget that most visitors dismiss in three seconds. The chatbot has become a social signal, not a tool. A way of saying: we're keeping up."

> “What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?”

This drives me nuts. But it is a continuum. From help-bots which are just natural language navigation to docs, to the best in class llm’s with access to both knowledge of the company and your data (my fav so far is Shopify). The most annoying are those who read the docs to you like lawyer-bots.

I’m guessing the speed at which companies go from the first type to the last type depend on many factors such as volume of support issues, the expertise of the users, and corporate culture of reliance on “accountability sinks” (someone to be mad at, but who has no authority to help or correct a problem—I’m thinking of the merchant platform Square and their dark pattern navigation that tricks you to suffer the instant fees of the fund-now link trying to find the transfer schedule).

Cloudflare is your favorite company and they are geniuses?

Dear Diary,

Today my fanboy bubble was burst.

Signed,

Author

In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.

Identity is hard y'all.

Just use LLMs. They can apparently doing everything and all the things
(comment deleted)
This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
Web security wasn't hard before we started trying to make the web a platform for full executable software.

I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).

JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.

Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.

What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.
1. Why is this website blocked when I try browsing it using Brave?

2. Why on earth would you want a financial product from a WAF?content delivery company?

this from a company whose main product is (was) security.

I feel there's a generalized decrease in quality in software in general.

Web Developers, please follow every best practice, I’m begging you

Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.

No one is asking Web Developers about their opinion man.

STOP making everything developers fault.

It looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.
Not too bad that they launched looking like a phishing scam because they eventually added a link?

Shit, the bar is low these days.

I saw the whole Cloudflare Pay thing and had the exact same thoughts - this has to be some sort of phishing...
Cloudflare seems to be trying to do EVERYTHING.
I tried to signup and got an "Internal Server Error" post the auth callback. Embarrassing for Cloudflare. Par for the vibe coded culture I guess.

  The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
That's just gold
Depending on how possible it is for a use case, reducing the attack surfaces and vectors can help, such as being mindful of how much client side javascript exposes anything.
I also immediately check to see if it's an actual Cloudflare product because cloudflare[.]pay seems too suspicious to me.

Luckily, Google didn't fail me this time. Found a blog about this product with a link to the same domain.