Cloudflare Software Bug Causes Data Leak

Robinson+Cole Data Privacy + Security Insider
Contact

Cloudflare, Inc., a provider of performance and security solutions for websites, recently disclosed that a software bug caused it to leak customer data that was then cached by search engines. Uber, Fitbit, and OkCupid sites may have been affected. While the leaked data is believed to contain private information, the extent of that information is unclear. End-user passwords, cookies, and authentication tokens used to log in to multiple website accounts may have been exposed. In an incident report published on its website, Cloudflare emphasized that customer SSL private keys were not leaked.

Tavis Ormandy, a security engineer with Google’s Project Zero, discovered the bug and contacted Cloudflare to report the issue. The bug affected Cloudflare’s systems since September, 2016 however the greatest impact occurred between February 13 and February 18, 2017. According to Cloudflare’s incident report, its initial mitigation occurred in 47 minutes and it had resolved the problem in less than seven hours. Cloudflare is working with search engines, including Google, Yahoo, and Bing, to scrub the data from their caches.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Robinson+Cole Data Privacy + Security Insider | Attorney Advertising

Written by:

Robinson+Cole Data Privacy + Security Insider
Contact
more
less

Robinson+Cole Data Privacy + Security Insider on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide