- Report: 8 years of Trump tax returns subpoenaed by prosecutors 3 Years Ago
- Netflix lands exclusive streaming rights to ‘Seinfeld’ 3 Years Ago
- Jenny Slate sets first comedy special at Netflix 3 Years Ago
- #EndSmearFear is aiming to save lives 3 Years Ago
- Netflix ‘Living With Yourself’ trailer offers a double dose of Paul Rudd Today 2:07 PM
- How to stream the 2019-20 UEFA Champions League Today 2:04 PM
- Caitlyn Jenner ridiculed with transphobic jokes during Alec Baldwin roast Today 1:27 PM
- Brad Pitt confronts his daddy issues in the sci-fi epic ‘Ad Astra’ Today 1:20 PM
- People are stanning Elizabeth Warren’s respect for a train’s quiet car Today 1:16 PM
- Far-right mobs attacked queer kids after first Pride in Ukraine city Today 1:13 PM
- Influencer who photoshopped clouds into photos is partnering with the editing app Today 12:34 PM
- Lupita Nyong’o and Danai Gurira team up for ‘Americanah’ Today 12:29 PM
- Video shows cop mocking Black ninth-grader who was detained at bus stop Today 12:27 PM
- Has Trump reversed course on fighting a war for the Saudis? Today 12:20 PM
- These iOS 13 features will have you racing to update your iPhone on Sept. 19 Today 12:05 PM
Your sensitive data may have been leaked from one of several big-name websites that were potentially affected by a typo in the code of hosting provider Cloudflare.
Private encryption keys, cookies, passwords, and HTTPS requests have all been spotted in public caches following a colossal error that let random bits of server memory slip into webpages during certain processes.
Tavis Ormandy, a security researcher at Google, first spotted the breach and immediately let Cloudflare know about it. The company fixed the problem just two days later, but the damage was done. Cloudflare learned the earliest leak dates all the way back to September 2016, which means personal information has been “randomly” appearing on websites for months.
Ormandy found hotel bookings, passwords, and messages from dating sites among the cached data. “I didn’t realize how much of the internet was sitting behind a Cloudflare CDN until this incident,” he wrote. “We’re talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything.”
That info was found stored in web browser cached pages. With help from Google, Yahoo, Bing, and others, 770 unique resource identifiers (URIs) were found that had been cached and contained leaked memory. Of those, 161 came from unique websites, according to a lengthy post Cloudflare wrote about the incident.
The root cause for the issue comes from the company’s use of a new HTML parser, which is basically a search bar for code that lets you easily find and edit sections of information. It underwent a buffer overflow, which Cloudflare says could have been avoided if it had simply been checked with “>=” instead of “==.”
Basically, a tiny error caused a massive problem.
The company says the greatest period of impact was from Feb. 13-18, with around one in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (around 0.00003% of requests). That may not seem like a lot, until you consider millions of businesses—including some of the world’s largest—use the service.
In a blog post, security expert Ryan Lackey offered some advice to everyone who uses the internet: Change your password and use two-factor verification.
“Cloudflare is behind many of the largest consumer web services (Uber, Fitbit, OKCupid, …), so rather than trying to identify which services are on Cloudflare, it’s probably most prudent to use this as an opportunity to rotate ALL passwords on all of your sites,” Lackey wrote. “Users should also log out and log in to their mobile applications after this update. While you’re at it, if it’s possible to use 2FA or 2SV with sites you consider important.”
Cloudflare claims to have not yet identified any malicious uses of the information.
This massive leak is just the latest in an endless string of incidents that make you want to hate the internet. The advice coming out of all of them is to continue to rotate your passwords, or simply use two-step or two-factor verification for all of your accounts.
A list of websites potentially affected by Cloudflare’s leak is being compiled on Github.
H/T the Verge
Phillip Tracy is a former technology staff writer at the Daily Dot. He's an expert on smartphones, social media trends, and gadgets. He previously reported on IoT and telecom for RCR Wireless News and contributed to NewBay Media magazine. He now writes for Laptop magazine.