There are 4,287,625 domains, including Uber, FitBit, and Patreon, that may have been affected by a large security bug that leaked people’s personal information into others’ browsers. From as far back as September 22 to February of this year, user data has been slowly being leaked into Google and Bing caches as well as other bots that trawl the internet. This error affects almost all websites that utilize Cloudflare for security and content delivery, by causing pieces of user data to be dumped into web pages. The Orange County Register described this issue as sitting down at a clean table in a restaurant and being handed the previous diner’s wallet.
Tavis Ormandy, a vulnerability researcher on Google’s Project Zero team, reported to Cloudflare on February 17, that large chunks of data including sensitive user data was being cached in pages being crawled by Google’s search engine. In his attempts to reproduce the issue, he found that if an HTML page hosted by Cloudflare had a specific combination of unbalanced tags, it would intersperse pages of uninitialized memory into the output, meaning that if you were to access one such website, there could be chunks of your private information picked up by another website.
Cloudflare reacted within an hour of hearing of the issue from Ormandy, killing its Email Obfuscation service, and its Automatic HTTPS Rewrites a bit over three hours later. Logs on Cloudflare showed that the greatest amount of leakage occurred between February 13 and 18 with about 1 in every 3,300,000 HTTP requests resulting in memory leakage. Major news outlets have advised consumers of websites using Cloudflare to change their passwords, even for accounts protected by 2-factor authentication.
Cybersecurity today is a growing phenomenon as more and more people are entering the cyber world. Cyber attacks are growing with greater frequency and intensity yet they go unreported, or even under-reported, leaving users with a false sense of security. At WEST 2017, a conference held by the United States Navy, there was a discussion of the steps that the military is taking to expand the reaches of cyber in operations.
<
Sean Chiang Troy HS 11th Grade>
댓글 안에 당신의 성숙함도 담아 주세요.
'오늘의 한마디'는 기사에 대하여 자신의 생각을 말하고 남의 생각을 들으며 서로 다양한 의견을 나누는 공간입니다. 그러나 간혹 불건전한 내용을 올리시는 분들이 계셔서 건전한 인터넷문화 정착을 위해 아래와 같은 운영원칙을 적용합니다.
자체 모니터링을 통해 아래에 해당하는 내용이 포함된 댓글이 발견되면 예고없이 삭제 조치를 하겠습니다.
불건전한 댓글을 올리거나, 이름에 비속어 및 상대방의 불쾌감을 주는 단어를 사용, 유명인 또는 특정 일반인을 사칭하는 경우 이용에 대한 차단 제재를 받을 수 있습니다. 차단될 경우, 일주일간 댓글을 달수 없게 됩니다.
명예훼손, 개인정보 유출, 욕설 등 법률에 위반되는 댓글은 관계 법령에 의거 민형사상 처벌을 받을 수 있으니 이용에 주의를 부탁드립니다.
Close
x