Get 40% Off
🤯 Perficient is up a mind-blowing 53%. Our ProPicks AI saw the buying opportunity in March.Read full update

Bug causes personal data leak, but no sign of hackers exploiting: Cloudflare

Published 02/24/2017, 03:25 AM
Updated 02/24/2017, 03:30 AM
© Reuters. FILE PHOTO:  Matthew Prince, chief executive at internet start-up company called CloudFlare, poses in his office in San Francisco

By Jeremy Wagstaff

SINGAPORE (Reuters) - A bug in its software left hundreds of thousands of webpages hosted by Cloudflare Inc leaking encrypted personal data, but there was no sign yet the leak had been exploited by hackers, the Internet security firm said on Friday.

Cloudflare hosts six million websites, spreading them across the Internet to put them closer to customers while at the same time reducing their exposure to the so-called Distributed Denial of Service attacks that might knock them offline. 

The data leak was attributable to a bug in the firm's software that had been sending chunks of unrelated data to users' browsers when they visited a webpage hosted by Cloudflare, according to Google (NASDAQ:GOOGL) researchers.

Cloudflare Chief Technology Officer John Graham-Cumming said the problem had been fixed quickly and most of the exposed data removed from the caches of search engines like Alphabet's Google. 

"We've seen absolutely no evidence that this has been exploited," he told Reuters by phone. "It's very unlikely that someone has got this information." 

The leakage may have been active from Sept. 22, but the period most affected was from Feb. 13 until it was discovered on Feb. 18. At its height earlier this month, Graham-Cumming said, about 120,000 webpages were leaking information every day.

Some of this data included "private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings" as well as cookies, passwords and software keys, Google security researcher Tavis Ormandy, who discovered the bug, wrote in a forum on Feb. 19. 

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Ormandy also wrote on Twitter that data from ridesharing service Uber [UBER.UL] and cloud password company 1Password had been leaking. Uber declined to comment, while AgileBits, the maker of 1Password, denied in a blog post on Thursday that any personal data had been compromised. 

Graham-Cumming said it was difficult to say which of Cloudflare's six million websites had been affected. He said that Google and Cloudflare had been working together to remove any sensitive data from the store of webpages that search engines like Google collect when they index the web.

He said that process was not yet complete, which is why some researchers were still finding data if they knew where to look.

Some security researchers have said the problem is more serious than Cloudflare has described.

Jonathan Sublett of internet security company Shield Maiden said in a blog post that anyone who accessed sites that used Cloudflare "should consider their data public and work towards securing their accounts".

Graham-Cumming said it was difficult to say which of their customers were affected. "There will be a debate about how serious this is," he said. "We do not know of anybody who has had a security problem as a result of this."

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.