Private data leaked online by Cloudflare bug

February 24, 2017
A cry for people to change all of their online passwords because of a Cloudflare bug created a buzz on Twitter, where #CloudBleed became a trending topic

Internet users Friday were being urged to change all their passwords in the wake of a Cloudflare bug that could have leaked passwords, messages and more from website visits.

A Cloudflare service used by millions of websites to enhance security and performance said that it had fixed the flaw quickly after being alerted a week ago by Google researcher Tavis Ormandy.

"It turned out that in some unusual circumstances, our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data," Cloudflare chief technology officer John Graham-Cumming said in a blog post.

"And some of that data had been cached by search engines."

Essentially, intended to be temporarily stored overflowed "buffering" memory space and was then tucked into more exposed spots such as web pages that could then be captured by online search engines, according to descriptions of the bug.

"We fetched a few live samples and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major Cloudflare-hosted sites from other users," Ormandy said in an online post about the flaw.

"This situation was unusual, (personally identifiable information) was actively being downloaded by crawlers and users during normal usage, they just didn't understand what they were seeing."

Ormandy said in a Twitter message fired off from @taviso that Cloudflare has been leaking information for months, jeopardizing supposedly secure data at major websites including Uber, OKCupid, Fitbit and 1Password.

A cry for people to change all of their online because of the bug buzzed at Twitter, where "#CloudBleed" hashtag was a trending topic.

Explore further: CloudFlare tackles lost SSL key risk with Keyless SSL

Related Stories

CloudFlare tackles lost SSL key risk with Keyless SSL

September 19, 2014

Organizations looking for and concerned about optimal security protection are the targets of a new service announced by San Francisco-based CloudFlare. The offering is called Keyless SSL. CloudFlare explained that "An SSL ...

Many in US believe the were hit by Heartbleed

April 30, 2014

Many Americans scrambled to protect their personal information online after learning of the Heartbleed Internet flaw, and some believe their data was stolen, a survey showed Wednesday.

Answers to your questions about massive cyberattack

March 29, 2013

Here are some answers to questions about perhaps the biggest cyberattack ever, which recently targeted Spamhaus, an anti-spam group based in Geneva and London. It ended up slowing down or blocking access to numerous Internet ...

What you need to know about the Heartbleed bug

April 9, 2014

Millions of passwords, credit card numbers and other personal information may be at risk as a result of a major breakdown in Internet security revealed earlier this week.

Recommended for you

Archaeologists discover Incan tomb in Peru

February 16, 2019

Peruvian archaeologists discovered an Incan tomb in the north of the country where an elite member of the pre-Columbian empire was buried, one of the investigators announced Friday.

Where is the universe hiding its missing mass?

February 15, 2019

Astronomers have spent decades looking for something that sounds like it would be hard to miss: about a third of the "normal" matter in the Universe. New results from NASA's Chandra X-ray Observatory may have helped them ...

What rising seas mean for local economies

February 15, 2019

Impacts from climate change are not always easy to see. But for many local businesses in coastal communities across the United States, the evidence is right outside their doors—or in their parking lots.

The friendly extortioner takes it all

February 15, 2019

Cooperating with other people makes many things easier. However, competition is also a characteristic aspect of our society. In their struggle for contracts and positions, people have to be more successful than their competitors ...


Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.