Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Why the ‘Cloudbleed’ Data Leak Flaw Posed a Major Threat to Websites

    By
    Don Reisinger
    -
    March 2, 2017
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      PrevNext

      1Why the ‘Cloudbleed’ Data Leak Flaw Posed a Major Threat to Websites

      Why the 'Cloudbleed' Data Leak Flaw Posed a Major Threat to Websites

      Cloudflare has patched critical security flaws that could have allowed leaks of data from thousands of websites over a six-month period. Cloudflare and security researchers are still watching to see if any leaked data has been exploited.

      2What Is Cloudflare, Anyway?

      What Is Cloudflare, Anyway?

      Cloudlflare is a prominent internet infrastructure company that provides a host of services to websites, including load-balance optimization and security. It also provides website performance data. Cloudflare works behind the scenes in a lot of prominent websites.

      3This Affects Thousands of Sites

      This Affects Thousands of Sites

      Cloudflare said in a Feb. 23 statement that user information to thousands of websites, including passwords, leaked over a six-month period. Its edge servers, it said, malfunctioned and returned memory that contained private user information, some of which could have been crawled and cached by search engines.

      4Here Are Some Affected Sites

      Here Are Some Affected Sites

      The full list of affected sites hasn’t been publicly disclosed, but some companies have said they might have been affected. As of this writing, Uber has confirmed it was a Cloudbleed victim. Fitbit also was affected. Other impacted sites could emerge.

      5How Many Users Are Affected?

      How Many Users Are Affected?

      Knowing how many users were affected by Cloudbleed is difficult. Cloudflare provides its solutions to sites that work with millions of internet users. Most security experts believe a chunk of those folks were subject to it.

      6Three Cloudflare Features Were Turned Off

      Three Cloudflare Features Were Turned Off

      According to Cloudflare, after it learned of the problem, it discovered three features might have been at the center of the leak and shut them down: email obfuscation, server-side excludes and automatic HTTPS rewrites.

      7How Quickly Cloudbleed Was Fixed

      How Quickly Cloudbleed Was Fixed

      Cloudflare moved quickly to address Cloudbleed. The company said it turned off the affected services within 47 minutes of discovering the flaw and fixed the leak fully in less than seven hours.

      8An Eye on Malicious Activity

      An Eye on Malicious Activity

      In addition to addressing Cloudbleed, Cloudflare analyzed the scope of the leak. It found that although search engines including Google had cached its data, there had been no malicious activity surrounding it. The cached data was purged wherever it was found.

      9Users Should Change Passwords

      Users Should Change Passwords

      Although malicious hackers hadn’t taken advantage of the leak, it’s still a good idea to change your website passwords immediately. It’s the first line of defense against any malicious hacker who might somehow cull data from Cloudbleed.

      10Not Much Else Can Be Done

      Not Much Else Can Be Done

      Unfortunately, beyond changing passwords, there isn’t much users can do about Cloudbleed. The damage has already been done—the information was leaked and there is no way to change that. Users should remain vigilant and be on the lookout for any odd account behavior.

      11Looking Ahead Post-Cloudbleed

      Looking Ahead Post-Cloudbleed

      Looking ahead, things could get worse before they become better. The investigation into Cloudbleed and its reach has just begun. The leak appears to have been plugged, but more companies are expected to join the list of affected Cloudflare customers.

      PrevNext

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×