Cloudflare Patches Bug That Leaked User Data, Says No Sign of Hackers Exploiting

Advertisement
By Gadgets 360 Staff | Updated: 24 February 2017 17:47 IST
Highlights
  • Cloudflare customers like Uber, 1Password, Fitbit were likely affected
  • The data leak was attributable to a bug in the firm's software
  • Cloudflare CTO in a blog post said the problem had been fixed quickly
Cloudflare Patches Bug That Leaked User Data, Says No Sign of Hackers Exploiting

A bug in its software left hundreds of thousands of webpages hosted by Cloudflare leaking encrypted personal data, but there was no sign yet the leak had been exploited by hackers, the Internet security firm said on Friday. Google Project Zero security researcher Tavis Ormandy, who discovered the bug, wrote on Twitter that Cloudflare customers like Uber, 1Password, Fitbit, and OKCupid were likely affected. The bug is being unofficially termed Cloudbleed, for its similarity to the Heartbleed bug.

Cloudflare, a content delivery network and Internet security services provider, hosts six million websites, spreading them across the Internet to put them closer to customers while at the same time reducing their exposure to the so-called Distributed Denial of Service (DDoS) attacks that might knock them offline. While millions of websites are thought to have been affected by the bug, some reports put that number closer to 3,400.

The data leak was attributable to a bug in the firm's software that had been sending chunks of unrelated data to users' browsers when they visited a webpage hosted by Cloudflare, according to Google researchers.

Cloudflare Chief Technology Officer John Graham-Cumming in a blog post said the problem had been fixed quickly - within six hours - and most of the exposed data removed from the caches of search engines like Alphabet's Google.

Advertisement

"We've seen absolutely no evidence that this has been exploited," he told Reuters by phone. "It's very unlikely that someone has got this information."

The leakage may have been active from September 22, but the period most affected was from February 13 until it was discovered on February 18. At its height earlier this month, Graham-Cumming said, about 120,000 webpages were leaking information every day. Graham-Cumming in his blog post added, during that time, "end-user passwords, authentication cookies, OAuth tokens used to log into multiple website accounts, and encryption keys Cloudflare used to protect server-to-server traffic were all at risk of being exposed."

Advertisement

Some of this data included "private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings" as well as cookies, passwords and software keys, Ormandy wrote on February 19.

As mentioned, Ormandy also wrote on Twitter that data from ridesharing service Uber and cloud password company 1Password had been leaking. Uber declined to comment, while AgileBits, the maker of 1Password, denied in a blog post on Thursday that any personal data had been compromised.

Advertisement

Graham-Cumming said it was difficult to say which of Cloudflare's six million websites had been affected. He said that Google and Cloudflare had been working together to remove any sensitive data from the store of webpages that search engines like Google collect when they index the web.

He said that process was not yet complete, which is why some researchers were still finding data if they knew where to look.

Some security researchers have said the problem is more serious than Cloudflare has described.

Jonathan Sublett of internet security company Shield Maiden said in a blog post that anyone who accessed sites that used Cloudflare "should consider their data public and work towards securing their accounts".

Graham-Cumming said it was difficult to say which of their customers were affected. "There will be a debate about how serious this is," he said. "We do not know of anybody who has had a security problem as a result of this."

As this bug has been around for a long time posing a serious threat of personal information breach, users are strongly advised to change their passwords at the least. Cloudflare has fixed the bug, but if you're extra paranoid about your personal information online, do read Security researcher Ryan Lackey's additional security measures here.

Written with inputs from Reuters

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google I/O 2025: Here Are All the Major AI Announcements
  2. Oppo Reno 14 Series to Arrive With Integrated Google Gemini Features
  3. Infinix GT 30 Pro 5G With MediaTek Dimensity 8350 Ultimate SoC Launched
  4. HP Launches OmniStudio X All-in-One PC With Intel Core Ultra 7 CPU
  5. Android 16 Release: All You Can Expect from Google's Upcoming OS Update
  6. Google Unveils SynthID Detector Verification Portal to Combat Deepfakes
  7. Alcatel V3 Pro 5G, V3 Classic 5G Teased Ahead of May 27 India Launch
  8. Honor 400 Series Confirmed to Get Six Years of Android Updates
  9. Samsung Galaxy Watch 8 Classic Renders Tease Squircle Design, New Button
  1. Honor 400 Series to Get Six Years of Android Updates, AI Features Powered by Google’s Veo 2
  2. Samsung Galaxy Watch 8 Classic CAD Renders Tease New Squircle Design, Extra Button: Report
  3. Cyberpunk 2077 Sequel Will Feature a Second City in Addition to Night City, Says Series Creator
  4. Trump Memecoin Holders Set to Dine With US President, Tron Founder Justin Sun Confirms Attendance 
  5. Amazon Working on Large Foldable Device Similar to Huawei MateBook Fold Ultimate: Ming-Chi Kuo
  6. Infinix GT 30 Pro 5G With MediaTek Dimensity 8350 Ultimate SoC, 5,500mAh Battery Launched: Price, Features
  7. Google Announces SynthID Detector That Can Identify Gemini-Generated Content at Google I/O 2025
  8. Realme Buds Air 7 Pro Global Launch Set for May 27; Colours, Key Features Revealed
  9. iQOO Watch 5 With 1.43-Inch AMOLED Display and TWS Air 3 With Up to 45 Hours of Total Battery Life Launched
  10. Google Outlines Vision for Universal AI Assistant, Expands Project Astra and Project Mariner
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.