APC Australia

Protect yourself from Cloudbleed

A security bug that went unnoticed for months has now been patched, but who has been affected and how can you protect yourself from potential exploitati­on?

-

Despite the fact that ‘Cloudbleed’ sounds like the name of an emo band from the mid 2000s, it’s actually a serious security bug that affected content distributi­on network (CDN) Cloudflare. In September 2016, the company, which also provides internet security and distribute­d domain name server services to many websites, fell victim to a bug in the HTML parsing software it uses to read data from client websites, leaking sensitive informatio­n, including passwords and cookies, over one million times. A member of Google’s Project Zero — a team of security analysts hired to uncover zero-day software vulnerabil­ities — discovered the bug in February 2017 and alerted Cloudflare of the issue. Now, while there have not yet been any reports of that leaked data having being exploited — and the vulnerabil­ity itself has thankfully been patched — what can you do to protect yourself and your data from this and similar bugs?

 ??  ??

Newspapers in English

Newspapers from Australia