- How to live stream Pacquiao vs. Thurman 2 Years Ago
- Review: Hulu with Live TV ensures you always have something to watch 2 Years Ago
- How to live stream UFC on ESPN 4: Rafael dos Anjos vs. Leon Edwards Today 5:49 AM
- 2020 Democrats refuse to answer our questions about ‘Cats’ Friday 4:14 PM
- Belle Delphine’s Instagram account removed after mass reporting campaign Friday 4:08 PM
- Mariah Carey refuses old-age FaceApp challenge Friday 3:19 PM
- Journalists horrified by consolidation of Gatehouse, Gannett Friday 3:12 PM
- Facebook and Google could be tracking you on porn sites Friday 1:42 PM
- 7 best sites for psychic love readings Friday 1:20 PM
- Driver demonstrates why you always need to read road signs Friday 12:58 PM
- Area 51 remix video proves it’s the summer of Lil Nas X Friday 12:26 PM
- ‘ICE will come’: Convenience store clerk threatens customers speaking Spanish Friday 12:11 PM
- Rand Paul dodges questions about 9/11 Victims Fund, says ‘watch Fox News’ Friday 11:51 AM
- Report: ‘Stranger Things’ season 4 to begin shooting in October Friday 11:03 AM
- AT&T paid Michael Cohen to consult on net neutrality, FBI documents show Friday 9:10 AM
Cloudflare bug leaks personal data from some of the web’s biggest sites
Change your passwords right now.
Your sensitive data may have been leaked from one of several big-name websites that were potentially affected by a typo in the code of hosting provider Cloudflare.
Private encryption keys, cookies, passwords, and HTTPS requests have all been spotted in public caches following a colossal error that let random bits of server memory slip into webpages during certain processes.
Tavis Ormandy, a security researcher at Google, first spotted the breach and immediately let Cloudflare know about it. The company fixed the problem just two days later, but the damage was done. Cloudflare learned the earliest leak dates all the way back to September 2016, which means personal information has been “randomly” appearing on websites for months.
Ormandy found hotel bookings, passwords, and messages from dating sites among the cached data. “I didn’t realize how much of the internet was sitting behind a Cloudflare CDN until this incident,” he wrote. “We’re talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything.”
That info was found stored in web browser cached pages. With help from Google, Yahoo, Bing, and others, 770 unique resource identifiers (URIs) were found that had been cached and contained leaked memory. Of those, 161 came from unique websites, according to a lengthy post Cloudflare wrote about the incident.
The root cause for the issue comes from the company’s use of a new HTML parser, which is basically a search bar for code that lets you easily find and edit sections of information. It underwent a buffer overflow, which Cloudflare says could have been avoided if it had simply been checked with “>=” instead of “==.”
Basically, a tiny error caused a massive problem.
The company says the greatest period of impact was from Feb. 13-18, with around one in every 3,300,000 HTTP requests through Cloudflare potentially resulting in memory leakage (around 0.00003% of requests). That may not seem like a lot, until you consider millions of businesses—including some of the world’s largest—use the service.
In a blog post, security expert Ryan Lackey offered some advice to everyone who uses the internet: Change your password and use two-factor verification.
“Cloudflare is behind many of the largest consumer web services (Uber, Fitbit, OKCupid, …), so rather than trying to identify which services are on Cloudflare, it’s probably most prudent to use this as an opportunity to rotate ALL passwords on all of your sites,” Lackey wrote. “Users should also log out and log in to their mobile applications after this update. While you’re at it, if it’s possible to use 2FA or 2SV with sites you consider important.”
Cloudflare claims to have not yet identified any malicious uses of the information.
This massive leak is just the latest in an endless string of incidents that make you want to hate the internet. The advice coming out of all of them is to continue to rotate your passwords, or simply use two-step or two-factor verification for all of your accounts.
A list of websites potentially affected by Cloudflare’s leak is being compiled on Github.
H/T the Verge
Phillip Tracy is a former technology staff writer at the Daily Dot. He's an expert on smartphones, social media trends, and gadgets. He previously reported on IoT and telecom for RCR Wireless News and contributed to NewBay Media magazine. He now writes for Laptop magazine.