Skip to Content.
Sympa Menu

inc-ops-notifications - [InCommon NOTICE] Cloudbleed incident (IMPORTANT)

Subject: InCommon Operations Notifications

List archive

[InCommon NOTICE] Cloudbleed incident (IMPORTANT)


Chronological Thread 
  • From: Thomas Scavo <>
  • To: "" <>
  • Cc: InCommon Administration <>
  • Subject: [InCommon NOTICE] Cloudbleed incident (IMPORTANT)
  • Date: Mon, 27 Feb 2017 19:51:48 +0000
  • Accept-language: en-US
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:lEnJoB/IA1yJD/9uRHKM819IXTAuvvDOBiVQ1KB+0usfIJqq85mqBkHD//Il1AaPBtSGragawLON6+jJYi8p2d65qncMcZhBBVcuqP49uEgeOvODElDxN/XwbiY3T4xoXV5h+GynYwAOQJ6tL1LdrWev4jEMBx7xKRR6JvjvGo7Vks+7y/2+94fdbghMhDexe61+IRS5oQnMuMQanZZpJ7osxBfOvnZGYfldy3lyJVKUkRb858Ow84Bm/i9Npf8v9NNOXLvjcaggQrNWEDopM2Yu5M32rhbDVheA5mEdUmoNjBVFBRXO4QzgUZfwtiv6sfd92DWfMMbrQ704RSiu4qF2QxLzliwJKyA2/33WisxojaJUvhShpwBkw4XJZI2ZLedycr/Bcd8fQ2dKQ8RfWDFbAo6kb4UBEfcPPfpWoYf+plsBsRSwCga3CePz0z9EmmP60bEm3+g8FwzNwQwuH8gJsHTRtNj7KqcSUeewzKbS1jXIcu5Y1ivn54jWdRAqvPaBXa5qccrK1UYgDR3FjlKLpIzkOTOVyvoCs3Kd7+V+SeKjlXQrpB9srTiy38ohjJTCiIwSylDB7yp5wYA1KMW5SE59fd6rDoFQtyeEOItqXM8uWX9ntzsnyrEepZG7eC8KyIk6yB7Rb/yIaZKI7Qz5WOmNJjd4gXRoc6+8iRaq6UWs1/HwW8au3FtFrCdJiNbBum0X2xDO5MWKSeNx8lqh1DuNzQze6uBJLVoqmafUNZIt2KM8moYOvUnFAyT4gl/5jLWMeUUh4uWo6/roYrHhppKEL4F5lgbwPrggl8CmD+o2NQYDU3Gc+eunyrLv50r5QKhWjvItlanZrZbaKtkBqq6hGQ9V1Zoj5AijADe60dQYmn8HIEhCeBKak4jpP1bOIPf7Dfuln1uslzJry+jHPr3nHJrNMmDOnKr9cbty8UJRxwg+wcpQ6p5JEL0NPfz+V0zpuNzdFBA5Mgi0w+j9CNV604MTQX6PArWCMKzOq1CI+OUvLvKNZI8TpDbyNeIl5/jwgn8lh1MRZ7em0oYKaHygBPRpP12ZYWbwgtcGCWoKvww+Q/DtiF2HVD5TYHCyU7g75jEhB4KqFIbDSZy3j7Oc2Se7H5tWa3tCClCNCnfoa56EV+kWZCKTJM9hjiILVaKnS4A/yRGiqhX2xKR6IerJ4icYr47s1MBp5+3PkhE/7T10D8KB3GGKSmF0m2QIRzks0KB4u0x9xU6P0al+g/NEDNBT4OtJUhwjOZ7ayOx6F9HyWgzAftiVUlmmXtSmATY3TtIq2NIOZ0d9G86+jhDYwSamGb4Vl7qXBJMq6KLc2Wb+J9pjx3rcyqYukkQmEYNzMjjsh6h0sg/LHMvPlFmYmaehfLgd2yjW3GaFxm2LuUZeFglqXu+NCXEZbQ7Rtc+84ETeTrGvAr07MwxH0uaDLKBNb9juixNBXvi1a/rEZGfkp2e3AB+TjoiHZZTtMzEBxj7WAVYDuwEV4XucMwUiXGGsr3+IX28mLk7mf065qbo2k3i8VEJhiljSN0A=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

You are receiving this message because you are an InCommon Site Administrator
(or are otherwise subscribed to this mailing list). Your prompt action may be
required. Please read this message carefully.

The Internet service provider Cloudflare has reported an incident that caused
random information from one Cloudflare-backed site to leak across other
Cloudflare-backed sites over a five-month period. It is thought that leaked
information included email messages, personally identifying information, and
possibly even user passwords. For more information about the incident, visit:

https://blog.cloudflare.com/incident-report-on-memory-leak-caused-by-cloudflare-parser-bug/

The InCommon Federation Manager (FM) has never used the Cloudflare service.
However, if you use your FM password to log into other sites, and one of
those sites uses the Cloudflare service, your FM password may have been
leaked. In that case, you should change your FM password immediately.

If you used the Cloudflare service any time since September 2016 AND you
reuse passwords across sites, you should probably change your FM password. If
you use your FM password to log into ANY other site (except the FM), you
should change your FM password immediately.

Password Reset for Site Administrators https://spaces.internet2.edu/x/4hP5AQ

If you have any difficulty using the automated password reset service, please
contact us immediately at


-----
Tom Scavo
For InCommon Operations

  • [InCommon NOTICE] Cloudbleed incident (IMPORTANT), Thomas Scavo, 02/27/2017

Archive powered by MHonArc 2.6.19.

Top of Page