HKGalden科技臺
發表文章發起投票
好像很大煲!CloudFlare有bug令網站漏出用戶密碼
https://www.engadget.com/2017/02/24/server-bug-leaks-user-data-for-thousands-of-popular-websites/

https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

A number of high-profile websites have been leaking their users personal data into the ether, thanks to an error at their hosting provider. Cloudflare, which provides services to companies like Patreon, Fitbit and OKCupid among others, had an error in its code that caused pieces of memory to dump into web pages. The Register described the issue as sitting down to a fresh table in a restaurant and being handed the previous diner's wallet.

Tavis Ormandy, a security researcher at Google, spotted the breach and found encryption keys, cookies, passwords and HTTPS requests in public caches. He contacted Clouldflare, which then began to work to identify and stop the issue, which came down to a typo in the code that caused a buffer overrun. In its public statement, Cloudflare added that it held off on disclosing the issue until it had ensured that search engine caches had been cleared of any personal data.

If you're worried about how this affects you — and it probably does — then it's time to change your passwords for everything. There's a full list of directly affected sites available here, although it's probably wise to change all of your security keys, since you never know what data has leaked to where. Additionally, 1Password, which uses Cloudflare for hosting, has come out publicly to reassure customers that their data remains secure.

係時候改膠登密碼?
Good0Bad2
2017/02/24, 7:18:01 晚上
本貼文共有 0 個回覆
此貼文已鎖,將不接受回覆
發表文章發起投票