'CloudBleed' leak compromises passwords for services including Uber, FitBit, and OKCupid


A security breech dubbed "CloudBleed" because of its link to cybersecurity company Cloudflare compromised some 3,400 websites, including popular services like Uber, FitBit, and OKCupid. News of the bug broke Thursday and Friday after it was discovered by a Google researcher named Tavis Ormandy, and users are encouraged to change their passwords on affected sites even though the problem has now been fixed.
Ormandy's report indicated he was able to find "private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings," though Cloudflare says it has "not discovered any evidence of malicious exploits of the bug or other reports of its existence."
For now, most potentially affected "users are probably fine," explained Adam Clark Estes at Gizmodo Saturday. "Then again," he adds, "Cloudbleed illustrates a larger problem with internet security. If one major player gets pwned, the consequences can be catastrophic."
The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.

Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Bonnie Kristian was a deputy editor and acting editor-in-chief of TheWeek.com. She is a columnist at Christianity Today and author of Untrustworthy: The Knowledge Crisis Breaking Our Brains, Polluting Our Politics, and Corrupting Christian Community (forthcoming 2022) and A Flexible Faith: Rethinking What It Means to Follow Jesus Today (2018). Her writing has also appeared at Time Magazine, CNN, USA Today, Newsweek, the Los Angeles Times, and The American Conservative, among other outlets.
-
Burkina Faso's misinformation war
Under The Radar The president of the West African country has quickly become the face of a viral, AI-powered propaganda campaign
-
Jeffrey Epstein's secrets
Feature Six years after his death, conspiracy theories still swirl around the sex trafficker. Why?
-
Voting: Trump's ominous war on mail ballots
Feature Donald Trump wants to sign an executive order banning mail-in ballots for the 2026 midterms
-
New York court tosses Trump's $500M fraud fine
Speed Read A divided appeals court threw out a hefty penalty against President Trump for fraudulently inflating his wealth
-
Trump said to seek government stake in Intel
Speed Read The president and Intel CEO Lip-Bu Tan reportedly discussed the proposal at a recent meeting
-
US to take 15% cut of AI chip sales to China
Speed Read Nvidia and AMD will pay the Trump administration 15% of their revenue from selling artificial intelligence chips to China
-
NFL gets ESPN stake in deal with Disney
Speed Read The deal gives the NFL a 10% stake in Disney's ESPN sports empire and gives ESPN ownership of NFL Network
-
Samsung to make Tesla chips in $16.5B deal
Speed Read Tesla has signed a deal to get its next-generation chips from Samsung
-
FCC greenlights $8B Paramount-Skydance merger
Speed Read The Federal Communications Commission will allow Paramount to merge with the Hollywood studio Skydance
-
Tesla reports plummeting profits
Speed Read The company may soon face more problems with the expiration of federal electric vehicle tax credits
-
Dollar faces historic slump as stocks hit new high
Speed Read While stocks have recovered post-Trump tariffs, the dollar has weakened more than 10% this year