Hacker News new | ask | show | jobs
by nikisweeting 3398 days ago
As the author of the list these extensions are using (sites-using-cloudflare), I have doubts about the utility of public browser extensions to check for Cloudflare sites. An extension will alert if the user is on any of 4,000,000+ domains in the list. There will be too many false positives to make it a useful tool, and by forcing users to reset so many passwords, we're more likely to make them choose poor ones. That risk may outweight the safety gained by resetting passwords.

It was also mentioned in the Techcrunch article, many companies will probably choose not to reset user passwords, and will instead just pay for insurance to cover the tiny chance that one of their users had data leaked. https://techcrunch.com/2017/02/24/how-to-secure-your-data-af...