Cloudflare Data Leak, Time to change all your website password

Status
Not open for further replies.

kaizer01

Active Member
1,131
2011
172
720
"Tavis Ormandy (Tavis Ormandy) of Google’s Project Zero uncovered a major vulnerability in the Cloudflare Internet infrastructure service. Essentially, web requests to Cloudflare-backed sites received answers which included random information from other Cloudflare-backed sites! This information could potentially include confidential information (private messages on dating sites, emails), user identity information (Personally Identifying Information (PII), and potentially in a healthcare context, Protected Health Information (PHI), or user, application, or device credentials (passwords, API keys, authentication tokens, etc.)"

more info here: https://medium.com/@octal/cloudbleed-how-to-deal-with-it-150e907fd165#.2u2x75fc7

Better to be safe than sorry.
 
Last edited:
4 comments
Status
Not open for further replies.
Back
Top