{"id":12455,"date":"2017-02-26T08:38:17","date_gmt":"2017-02-26T13:38:17","guid":{"rendered":"http:\/\/www.thundercloud.net\/infoave\/new\/?p=12455"},"modified":"2017-02-26T14:46:05","modified_gmt":"2017-02-26T19:46:05","slug":"what-is-cloudbleed-and-why-should-you-care","status":"publish","type":"post","link":"https:\/\/www.thundercloud.net\/infoave\/new\/what-is-cloudbleed-and-why-should-you-care\/","title":{"rendered":"What is Cloudbleed and Why Should You Care?"},"content":{"rendered":"<h1>What is Cloudbleed and Why Should You Care?<\/h1>\n<p>A company called Cloudflare provides web security and performance boosts to millions of websites including Fitbit, OkCupid, Uber, and Yelp and millions of others. Recently, it was\u00a0discovered that Cloudflare has been leaking user data on to the Web from\u00a0September 22 2016 until February 18, 2017. The leak was discovered by Google researchers and reported to Cloudflare on February 18. Cloudflare \u00a0detailed the problem in a public<a href=\"https:\/\/blog.cloudflare.com\/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug\/\" target=\"_blank\">\u00a0announcement <\/a>on Thursday, February 21, 2017.<\/p>\n<p>Between\u00a0September 22, 2016 to February 18, 2017, sites using Cloudflare services, leaked session tokens, passwords, private messages, API keys, and other sensitive data randomly. That data was also cached (stored) by search engines, and may have been intercepted by hackers and other miscreants. Whatever information was intercepted by criminals would likely be sold or posted online.<\/p>\n<p>This entire episode is referred to as Cloudbleed.<\/p>\n<p>Many sites you probably use often were <strong>NOT<\/strong> affected.<\/p>\n<p><strong>Sites NOT affected are:<\/strong><\/p>\n<ul>\n<li>Facebook<\/li>\n<li>Google<\/li>\n<li>Outlook.com<\/li>\n<li>Microsoft.com<\/li>\n<li>Twitter<\/li>\n<li>Amazon.com<\/li>\n<li>Instagram<\/li>\n<li>Pintarest<\/li>\n<\/ul>\n<p>Some of the larger sites that WERE affected by Cloudbleed are:<\/p>\n<ul>\n<li>authy.com<\/li>\n<li>fitbit.com<\/li>\n<li>coinbase.com<\/li>\n<li>betterment.com<\/li>\n<li>transferwise.com<\/li>\n<li>prosper.com<\/li>\n<li>digitalocean.com<\/li>\n<li>patreon.com<\/li>\n<li>bitpay.com<\/li>\n<li>bitdefender.com<\/li>\n<li>news.ycombinator.com<\/li>\n<li>producthunt.com<\/li>\n<li>medium.com<\/li>\n<li>4chan.org<\/li>\n<li>yelp.com<\/li>\n<li>okcupid.com<\/li>\n<li>zendesk.com<\/li>\n<li>uber.com<\/li>\n<\/ul>\n<p>You can get a complete list of sites that were affected by Cloudbleed from\u00a0<a href=\"https:\/\/github.com\/pirate\/sites-using-cloudflare\/blob\/master\/README.md\" target=\"_blank\">this page<\/a>.<\/p>\n<p>If you a log-in account on any of the affected sites, it would be a good idea to change your password for those sites. According to Cloudflare, about 1 out of every 3.3 million requests\u00a0exposed user data. While 1 out of 3.3 million does not sound like a lot, in web traffic terms it is quite significant.<\/p>\n<p>And, just so you know, Cloudeight is NOT affected by Cloudbleed.<\/p>\n<p>We are posting this information to keep you informed and not to alarm you. Keep in mind that as a general rule, it&#8217;s a good idea to change your passwords every 3 to 6 months anyway. So if you do have accounts with any of the affected sites, now would be a great time to change your passwords.<\/p>\n<hr \/>\n<hr \/>\n<h3>Cloudie&#8217;s Birthday &#8220;Pay What You Like&#8221; Sale is going on now!<\/h3>\n<p>You pick the price; you get a great deal &#8211; and help Cloudeight too!<\/p>\n<p><a href=\"http:\/\/thundercloud.net\/direct\/2017\/pay-what-you-like\/index.htm\" target=\"blank\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" src=\"http:\/\/thundercloud.net\/infoave\/images\/2017\/birthday-banner.png\" alt=\"Cloudie's 16th Birthday Sale - Pay What You Licke\" width=\"580\" height=\"167\" \/><\/a><\/p>\n<p><strong><u><a href=\"http:\/\/thundercloud.net\/direct\/2017\/pay-what-you-like\/index.htm\" target=\"blank\">Get more information by clicking here &#8212; or on the image above!<\/a><\/u><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is Cloudbleed and Why Should You Care? A company called Cloudflare provides web security and performance boosts to millions of websites including Fitbit, OkCupid, Uber, and Yelp and millions of others. Recently, it was\u00a0discovered that Cloudflare has been leaking user data on to the Web from\u00a0September 22 2016 until February 18, 2017. The leak was discovered by\u2026 <span class=\"read-more\"><a href=\"https:\/\/www.thundercloud.net\/infoave\/new\/what-is-cloudbleed-and-why-should-you-care\/\">Read More &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1433,1678,1426,1656,1674],"tags":[],"_links":{"self":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/12455"}],"collection":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/comments?post=12455"}],"version-history":[{"count":4,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/12455\/revisions"}],"predecessor-version":[{"id":12462,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/posts\/12455\/revisions\/12462"}],"wp:attachment":[{"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/media?parent=12455"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/categories?post=12455"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thundercloud.net\/infoave\/new\/wp-json\/wp\/v2\/tags?post=12455"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}