FacebookInstagramTwitterContact

 

Tom Brady Reveals Jude Bellingham Chat After Real Madrid Move           >>           Spain WWC Winners, Jude Bellingham Take Home Laureus Awards           >>           A-League's Central Coast Mariners Eye $2.3m AFC Cup Payday           >>           Gambling Activity Foiled           >>           Temporary Slip Road Closure           >>           Water Disruption           >>           National Speech Contest           >>           Religious Programme           >>           Workshop Closing Ceremony           >>           MoU Signing for Internationalisation of Higher Education           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Cloudbleed Bug: Everything You Need To Know


Internet security suffered a major blow by a bug nicknamed Cloudbleed. Patrick Holland/CNET

 


 February 27th, 2017  |  12:03 PM  |   1413 views

CNET.COM

 

The internet has a new security bug called Cloudbleed and it's pretty bad. We explain what it is, how it affects you and what you can do.

 

Cloudbleed is the latest internet bug that puts users private information in jeopardy. News of the bug broke late on Thursday, but there is already a lot of confusion about it and the actual impact it has on people's information.

 

We compiled this as a guide to Cloudbleed and how you should respond. News of Cloudbleed is ongoing, and we'll update this article as new issues arise. Check back for new information.

 

What is Cloudbleed?

 

Cloudbleed is the name of a major security breach from the internet company Cloudflare that leaked user passwords, and other potentially sensitive information to thousands of websites over six months. The Register describes it as "sitting down at a restaurant, supposedly at a clean table, and in addition to being handed a menu, you're also handed the contents of the previous diner's wallet or purse."

 

The name comes from Tavis Ormandy of Google's Project Zero, who reported the bug to Cloudflare and joked about calling it Cloudbleed after the 2014 security bug Heartbleed.

 

Is Cloudbleed worse than Heartbleed?

 

At this point, no. As scary as any internet security breach seems, these were pretty different. Heartbleed affected half a million websites, whereas at this time only 3,400 websites are believed to have had the Cloudbleed bug.

 

But here's the potentially scary part. Those 3,400 websites leaked private data that came from other Cloudflare clients. So the actual number of websites actually affected could be much higher.

 

Is Cloudbleed still actively dangerous?

 

No. Think of Cloudbleed like a person surviving a heart attack. It's scary and it will require changes to prevent it from happening again. But the worst of it is over, for now.

 

If there is an upside to this story, it's that Cloudflare stopped the bug within 44 minutes of finding out about it and fixed the problem completely within 7 hours.

 

However, the bug is believed to have affected websites going as far back as September with the height of the breach occurring between Feb. 13 to 18. So there will be ripples of consequential fallout as companies learn about the bug and whether their customers' information was involved.

 

Who is Cloudflare?

 

Cloudflare provides essential internet infrastructure and security to millions of websites. On its website, Cloudflare lists Nadaq, Bain Capital, OKCupid, ZenDesk and Cisco among others under its "Trusted by" section.

 

Even though you might not be familiar with the name Cloudflare, chances are a website you've visited uses the company for security or information delivery.

 

What websites were affected?

 

At this point, we know that Uber, Fitbit and OKCupid were three directly affected, but there's thousands more.

 

In response to news of the leak, companies have taken to Twitter to acknowledge the bug and reassure their customers.

 

How many people are at risk because of Cloudbleed?

 

It's tough to say, but it's low. As I mentioned above, the peak of the Cloudbleed bug was between Feb. 13 to 18. In a post on the its website, Cloudflare states that during this time about "1 in every 3,300,000 HTTP requests through Cloudflare" potentially resulted in memory leakage. That statistic was further clarified to be about 0.00003 percent of requests.

 

What kinds of information was leaked?

 

When you look at the web address for a website you're on, sometimes you see "http" at the beginning. But when you're on a secure website, for example a bank or a password login screen, you'll see "https" at the beginning indicating that the page is secure.

 

Services like Cloudflare help move information entered on those "https" websites between users and servers securely. What happened here is some of that secure information was unexpectedly saved when it should not have been. And to make matters worse, some of the saved secure information was cached by search engines like Google, Bing and Yahoo.

 

So it could have been a username or a password, a photo or frames of a video as well as behind-the-scenes things like server information and security protocols. At this time, there is no indication that any of this information was accessed by hackers.

 

What should I do?

To be honest, nothing you do now will undo what has happened. But there are things you can do to protect yourself from such things happening again before the next Cloudbleed-like incident happens.

 

The first thing to do is change the passwords for any of your accounts that use Cloudflare. Fitbit, OKCupid and Medium are a few, but you can find out if websites you use rely on Cloudfare with this tool.

 

And, if any of those websites or services offer two-step verification (sometimes called two-factor verification), use it. It ensures that even if someone were to get a hold of your password, they would not be able to access your account.

 

We also recommend contacting the companies of the sites and services you use and let them know your feelings about protecting your security and privacy. As worried about Cloudbleed as some people might be, companies will be pretty worried too and hearing from their customers can go a long way toward improving things for everyone.

 

What happens next?

 

Again, information about Cloudbleed became public as of February 23, and as we get new information about the bug we'll update this article.

 


 

Source:
courtesy of CNET

by Internet security suffered a major blow by a bug nicknamed Cloudbleed. Patrick Holland/CNET

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

Ten Dead As Navy Helicopters Collide Mid-Air In Malaysia

 2024-04-24 07:44:54

Mortgage Costs Rise As Banks Confirm Higher Rates

 2024-04-24 08:19:11