Private data leaked online by Cloudflare bug

Image
AFP San Francisco
Last Updated : Feb 25 2017 | 1:13 AM IST
Internet users today were being urged to change all their passwords in the wake of a Cloudflare bug that could have leaked passwords, messages and more from website visits.
A Cloudflare service used by millions of websites to enhance security and performance said that it had fixed the flaw quickly after being alerted a week ago by Google researcher Tavis Ormandy.
"It turned out that in some unusual circumstances, our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data," Cloudflare chief technology officer John Graham-Cumming said in a blog post.
"And some of that data had been cached by search engines."
Essentially, sensitive data intended to be temporarily stored overflowed "buffering" memory space and was then tucked into more exposed spots such as web pages that could then be captured by online search engines, according to descriptions of the bug.
"We fetched a few live samples and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major Cloudflare-hosted sites from other users," Ormandy said in an online post about the flaw.
"This situation was unusual, (personally identifiable information) was actively being downloaded by crawlers and users during normal usage, they just didn't understand what they were seeing."
Ormandy said in a Twitter message fired off from @taviso that Cloudflare has been leaking information for months, jeopardising supposedly secure data at major websites including Uber, OKCupid, Fitbit and 1Password.
A cry for people to change all of their online passwords because of the bug buzzed at Twitter, where "#CloudBleed" hashtag was a trending topic.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Feb 25 2017 | 1:13 AM IST

Next Story