Cloudbleed bug compromises personal information

February 26, 2017 •

A new security bug has compromised personal information all across the internet. Thousands of popular websites that use the Content Delivery Network (CDN) Cloudflare were compromised. Random chunks of secure data were passed to the wrong users, including passwords, images, private messages, frames from private video -- everything.[2,3,4,5]

Some of the information was being passed to search engine spiders, and made publicly available as cached webpages through search engines such as Google. This started happening back in September 2016. It is only anyone's guess how long this took to be noticed and for certain individuals to start harvesting as much of the private data as possible.

Some bitcoin sites such as and were among the compromised websites. Users are urged to update passwords, and their old passwords may have been revealed.

What is known is that starting on February 13, 2017 a lot more of the information started being compromised. Apparently that is when knowledge of the bug was first distributed in various security communities and unidentified users began collecting information. It took 5 days for this to be stopped.

Tavis Ormandy, a British bug hunter, discovered the problem by chance a week ago, when he noticed that large chunks of private data were sitting inside of cached pages that been crawled by the Google search engine spider.

A lot of the compromised data has already been scrubbed from the cache, and Google already already found and removed most of the data, but not all of it has been, and Google is far from the only web caching service. Resourceful individuals would still, presently, be able to harvest private information.

