Skip to content

Cloudflare releases HAR santizer in response to the Okta breach

blog.cloudflare.com
16 pointsgregdoesit2 comments
On HN

Comments

Feels like this tool should have been created by Okta in the first place, instead of asking their customers to submit them HAR files and then directly exposing the secrets in these files to the attackers.

It's kind of irresponsible to publish this, given the way it's developed and deployed. It's not even a very good implementation of what it's supposed to do. (Using regular expression search-and-replace as a substitute for parsing? <http://langsec.org/>)

This tool is not good.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.